An access control system that controls a user's access to the operating functions of technical facilities
By dynamically supplementing access authorized data in the receiving device and verifying that it matches the expected state in the access control device, the hardware cost and complexity of the radio access control system is solved, and flexible and high-security operational function control is achieved.
Patent Information
- Application Number
- CN202010229655.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-03-28
- Filing Date
- 2020-03-27
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-03-27
AI Technical Summary
Prior arts use radio solutions for access control, and it is difficult to achieve high security and flexibility without increasing hardware costs and complexity, especially multi-level authorization control on machine devices.
The access authorization data is read from the mobile data carrier by the receiving device and supplementing the dynamic part during the dynamic process. The access control device is used to verify the data to ensure that it matches the expected state and the operation function is unlocked, avoiding additional hardware consumption.
It realizes flexible and efficient control of user access to the operational function of technical facilities without increasing hardware costs, meets the requirements of high security categories, and is compatible with existing systems.
Smart Images

Figure CN111753285B_ABST
Abstract
Description
Field of the Invention
[0001] The present invention relates to an access control system, an access control device, and a corresponding access control method for controlling a user's access to one or more operating functions of a technical facility, in particular for enabling a secure working mode selection on the technical facility. Background Art
[0002] Access control of technical facilities, such as machine tools, by means of one or more key switches is known from the prior art. By means of these key switches, various operating modes of the machine in the sense of European regulations and standards can be activated in a targeted manner.
[0003] DE 10 2007 041 768 A1, for example, discloses a machine tool in which data for access control is provided by a mobile data carrier. The machine tool has a reader for reading out the data of the mobile data carrier via a radio interface (for example, based on RFID technology). Compared to simple key switches, in this way, more extensive data can also be provided for access control, so that more complex access control can also be achieved, such as having multiple different authorization levels. Thereby, it can be accurately specified which user is allowed to perform which operating function on which machine tool. In addition, the use of radio technology in access control offers the advantages of better operation and simpler key management. Similarly, radio solutions are less susceptible to mechanical interference and contamination, such as may occur in an industrial environment.
[0004] Regardless of the type of access control, it must be ensured in key switches and radio solutions that the authorization transmitted once is timely and effective, that is, it must be confirmed whether the key has been "inserted" as expected. This can be easily achieved by mechanical means in the case of key switches, while special measures must be taken for radio solutions.
[0005] One possibility is to perform an antenna test in which the antenna of the reading device is temporarily disconnected and at the same time an attempt is made to read out the key or the mobile data carrier. If the attempt fails, it is assumed that it is operating as expected. However, the problem here is that additional hardware costs are required to be able to disconnect the antenna. Similarly, an increase in costs is to be expected in the case of achieving safe use, because the antenna test must be integrated into safe use and is not allowed to affect safe use itself.
[0006] Another possibility is to design the reading device as a security device for reading out mobile data carriers. For this purpose, security devices can be integrated into the reader, which can faultlessly check the presence of the key or the mobile data carrier. For example, redundant, mutually checking processing units may be added to the reader, which perform tests in order to faultlessly verify the presence of the key or the mobile data carrier. Alternatively, such processing units may also check in other ways whether the timeliness and validity of the read access authorization data are ensured. The corresponding measures (forming a security device from the reading device) are known from security technology and are fixed in the corresponding standards. However, in the sense of these standards, the design of the reading device as a complete security device is associated with significant costs, because special hardware equipment is required and corresponding expenses must be incurred in order to be able to authenticate the reading device independently. In addition, other requirements result for the integration of the security device into the remaining security technology, for example due to the necessity of dual-channel data transmission. Summary of the Invention
[0007] Against this background, the object of the present invention is to provide an improved control of access to a technical facility, which has the advantage of using a mobile and contactless acting data carrier as a key, but which can be implemented faultlessly and cost-effectively, so that overall the requirements of a higher security class of the relevant standards are also taken into account.
[0008] According to one aspect of the present invention, this object is achieved by an access control system for controlling a user's access to one or more operating functions of a technical facility, the access control system comprising: a receiving device for reading access authorization data from a mobile data carrier; and an access control device adapted to receive the access authorization data from the receiving device and to verify it, wherein the receiving device is further adapted to continuously supplement the access authorization data with a dynamic part and to send the dynamized access authorization data to the access control device, and wherein the access control device is adapted to: when the dynamized access authorization data corresponds to a defined expected state, generate an unlocking of the operating functions for which the access authorization data is verified as valid.
[0009] According to another aspect of the present invention, this object is also achieved by an access control device for controlling a user's access to one or more operating functions of a technical facility, the access control device comprising: an interface for receiving access authorization data from a receiving device, the receiving device reading the access authorization data from a mobile data carrier and continuously supplementing the access authorization data with a dynamic part; a processing unit adapted to verify the access authorization data, wherein the access control device is adapted to: when the dynamic access authorization data corresponds to a defined expected state, generate an unlocking of the operating functions for which the access authorization data is verified valid.
[0010] According to another aspect of the present invention, this object is also achieved by an access control method for controlling a user's access to one or more operating functions of a technical facility, the access control method having the following steps:
[0011] - Receiving access authorization data from a receiving device, the receiving device reading the access authorization data from a mobile data carrier and continuously supplementing the access authorization data with a dynamic part;
[0012] - Verifying the access authorization data by a processing unit; and
[0013] - When the dynamic access authorization data corresponds to a defined expected state, generating an unlocking of the operating functions for which the access authorization data is verified valid.
[0014] Thus, the idea of the present invention is to accumulate a "dynamic part" to the access authorization data read from the mobile data carrier. The dynamic part herein refers to the part of the access authorization data that continuously changes over time. The dynamic part can for example be the current value of a continuously increasing or decreasing count. The dynamic part is transmitted to the access control device together with the access authorization data, which analyzes the access authorization data and allows the user to use the operating functions that the user should perform according to the access authorization data. This permission to use is achieved under the condition that the dynamic access authorization data corresponds to a specific expected state.
[0015] Therefore, the access control device can compare the dynamic part with the expected state and thus check the timeliness of the access authorization data. Only when the dynamic part corresponds to the defined expected state does the access control device generate an unlocking of the access operating functions. When the expected state is not met, the data is discarded. Thereby, the fault response time can be reflected, monitored and adhered to.
[0016] The access control device generates an unlocking, generally in the form of an unlocking signal, which depends on dynamic access authorization data, i.e., based on the verified access authorization data and the continuously changing information transmitted by means of the access authorization data. "Accumulating" these information to the access authorization data to obtain dynamic access authorization data can be carried out by the receiving device without additional hardware cost. And the receiving device can be a simple and non-fault-proof device, in which, in order to achieve the corresponding confidence level (Safety-Level), the possible solutions of the design scheme related to the dynamic part are tracked.
[0017] In this regard, "non-fault-proof" means that the receiving device itself does not meet the requirements of the relevant standards for fail-safe aspects, that is, the receiving device does not have a supplementary safety device in the sense of safety technology. This has the following advantages: favorable receiving devices can be used or there is the possibility of reusing existing non-fault-proof reading devices of technical facilities. Here, the simple possibility of reading out software may be sufficient to dynamicize the access authorization data in the sense of the present invention.
[0018] Another advantage is that safety technology and control technology can be clearly separated from each other. This enables: the facility manufacturer or the machine manufacturer can implement access control by the user substantially independently of the safety technology required by the machine. Thus, the facility manufacturer or the machine manufacturer can independently and flexibly purchase and retrofit safety technology, thereby advantageously increasing their design freedom.
[0019] In addition, by supplementing the dynamic part at the beginning of the access control process, the entire process chain can be checked based on this. Thus, the proposed access control can efficiently cover the entire process chain.
[0020] Generally, the access control system according to the present invention discloses cost-effectively and flexibly controlling the access of users to one or more operating functions of technical facilities. Thus, the purpose stated at the beginning is fully achieved.
[0021] In another design, the receiving device can be adapted to supplement a defined template as the dynamic part to the access authorization data each time the access authorization data is read out from the mobile data carrier.
[0022] Thus, the dynamic part can be associated with the read-out access authorization data, so that another data group is generated only when the access authorization data has not changed during each read-out. In this way, dynamicization can be achieved particularly efficiently. By generating the template at the beginning of the processing chain of access control, the entire processing chain can be tested through the template and its analysis.
[0023] The template can in particular include an authorization, a serial number, a count, a current session key, one or more previous session keys, a key ID, an absolute time value and / or a relative time value, and can in particular be a defined combination of one or more of the aforementioned elements.
[0024] Thus, the template can be formed in different ways, wherein at least one continuously changing data value is included in the template. For example, the dynamic part can include a value corresponding to the time point at which the access authorization data has been read out by the receiving device. Such a time stamp can be an actual moment or a count value relative to a defined start time point. The advantage of having a time stamp as the dynamic part is that this can be implemented particularly simply and efficiently, whereby the implementation of the dynamicization is further simplified and can also be retrofitted in simple readers. However, in addition to the time stamp, other continuously changing values can also be used, which are in principle available at the receiving device. By combining different values into a complex template, the desired confidence level can be achieved through a likelihood conclusion.
[0025] In another design, the receiving device can be adapted such that the dynamic part is generated only when the access authorization data has been read out completely and / or effectively.
[0026] In other words, the dynamic part is added to the access authorization data and is associated therewith. If the access authorization data cannot be read out, then the dynamic part is not supplemented either, and thus even if the remaining access authorization data is valid for verification, the access control does not generate an unlocking.
[0027] In another design, the receiving device can send the dynamic access authorization data to the access control device in a single-channel manner. By using a likelihood scheme based on the dynamic part for access control, there is no need to additionally determine the transmission path and thus the transmission path can be designed in a single-channel manner. This has the advantage that a simple wiring between the receiver and the access control device is sufficient, whereby additional costs can be saved. It is also possible to dispense with the use of security protocols (PROFIsafe, FSoE, CIP Safety,), which makes encoding / decoding redundant.
[0028] In another design, the receiving device can have a reading device for reading out the mobile data carrier via a radio interface.
[0029] Thus, the mobile data carrier is a contactless acting data carrier. In addition, the communication between the receiving device and the mobile data carrier is preferably based on RFID technology. Then, a passive transponder can be used on the side of the mobile data carrier, which can be read out wirelessly without its own energy source.
[0030] In another design, the access control system further includes a selection device for the user to select one or more operating functions, wherein the access control device is further adapted to configure the selection device to only allow the user to access the unlocked operating functions.
[0031] Thereby, the access control device can act directly on the selection device (such as an operation panel) and limit access to only the unlocked functions.
[0032] In another design, the access control device can be adapted to: when the dynamic part does not change over a defined time period, disable the selection device.
[0033] Thereby, the operation of the selection device can also directly depend on the dynamic part and its analysis. Preferably, the access control device further has safety devices that can ensure a fail-safe operation of the selection device. This has the advantage that safety functions can be directly implemented by the access control device based on access control.
[0034] In another design, the access control system can further have a fail-safe control unit, which is adapted to ensure a fail-safe operation of the technical facility and to implement safety functions, wherein the access control device is adapted to: transmit the unlocking to the fail-safe control unit, such that the fail-safe control unit controls the technical facility depending on the unlocking, in particular when no unlocking is sent, the technical facility switches to a safe state.
[0035] Thereby, the inherent control of the technical facility can (as commonly) be implemented by a safety controller, which disables access to the machine or the operating functions of the machine taking into account the unlocking. As a last resort, if there should no longer be authorization, the fail-safe control unit as well as the machine can be switched to a safe state.
[0036] In another design, the access control device can have an integral component, assembly and / or module (in particular a software module), and the component is a fail-safe control unit.
[0037] Thereby, the access control device can be an independent unit or can be integrated into the fail-safe control unit. The latter has the advantage of cost-effective implementation, because the safety devices in the fail-safe control unit can be used for the access control device. In addition, secure communication between the access control device and the fail-safe control unit can be ensured in this way.
[0038] Obviously, the features described above and those to be described below can be used not only in the respective indicated combinations, but also in other combinations or individually, without departing from the scope of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Embodiments of the invention are shown in the drawings and are described in more detail in the following description. In the drawings:
[0040] Figure 1 A simplified schematic diagram showing one embodiment of an access control system,
[0041] Figure 2a shows an example of dynamic access authorization data with an incremented count,
[0042] Figure 2b An example of dynamic access authorization data with a timestamp is shown,
[0043] Figure 3 A simplified schematic diagram of one embodiment of an access control device, and
[0044] Figure 4 A flow chart illustrating an embodiment of an access control method for controlling user access to one or more operating functions of a technical facility. DETAILED DESCRIPTION
[0045] Figure 1 An embodiment of an access control system 10 for controlling user access to one or more operating functions of a technical installation 12 is shown in a simplified schematic diagram.
[0046] In this exemplary embodiment, a robot 14 with its drive 16 is indicated as the technical installation 12 by way of example. However, it should be understood that the access control system 10 is not limited to this embodiment, but any other technical installation can be associated with the access control system 10 .
[0047] In this preferred embodiment, the access control system 10 includes: a selection device (18) for a user to select one or more operating functions; a fail-safe control unit 20 (FS controller), which can ensure the fail-safe operation of the technical facilities; a receiving device 22, which is adapted to read out access authorization data 26 from a mobile data carrier 24; and an access control device 28.
[0048] The access control device 28 receives the access authorization data 26 from the receiving device 22 and verifies it, i.e. the access control device 28 determines for which operating functions the owner of the mobile data carrier has authorization with the aid of the access authorization data 26. This authorization can be derived directly from the access authorization data 26 or can be obtained by the access control device 28 with the aid of the access authorization data 26.
[0049] The selection device 18 can for example be an operating console which is arranged at the technical facility 12. The operating console can include keys 30a - 30d and the associated indicating elements 32a - 32d. The user of the technical facility can select one or more operating functions by means of the keys 30a - 30d. Preferably, each key is associated with exactly one operating function of the technical facility 12. The indicating elements 32a - 32d can indicate the selected operating function depending on the selection.
[0050] The receiving device 22 is adapted to read data from the mobile data carrier 24 as access authorization data 26. Preferably, the data is read by means of a reading device 34 which has a radio interface 36. For example, the communication between the reading device 34 and the mobile data carrier 24 can be implemented by means of RFID technology. In this case, the mobile data carrier 24 can be a passive transponder (for example a simple token) which does not have its own energy source and communicates only by being excited by the reading device 34. The reading device 34 can be a commercially available RFID reader and in particular includes logic for performing authorization.
[0051] The access authorization data 26 is transmitted from the receiving device 22 to the access control device 28. The transmission can be carried out wirelessly, in particular via a simple single - channel data transmission path 38. The data transmission can be carried out without redundancy or a dedicated protocol. More precisely, the transmission can be safeguarded by suitable signal processing based on the dynamic access authorization data.
[0052] The encoding of the authorization can be chosen arbitrarily. Preferably, the binary representation of the authorization is chosen such that the Hamming distance between individual representations is as large as possible in order to ensure high robustness during the transmission and storage of the authorization. For example, the authorization can be stored as a 32 - bit value and the Hamming distance can be preset to 9. Then, no other valid authorization can be generated by a change of up to 8 bits.
[0053] In a preferred embodiment, the access control device 28 can control the selection device 18 by means of the access authorization data 26 such that the user can only select the operating functions for which the user has authorization according to the access authorization data 26. The access control device 28 can for example activate or deactivate individual keys of the operating console such that a corresponding key only reacts when the user has the corresponding authorization according to the access authorization data 26 for the corresponding operating function associated with the key.
[0054] In a preferred embodiment, in addition to the selected operating functions, the indicating elements 32a - 32d can in particular also indicate operating functions that can be selected by the user with authorization. The indicating elements 32a - 32d can, for example, cause only the keys 30a - 30d to light up, the operating functions of which are permitted according to the access authorization data 26.
[0055] The access control device 28 can also include a confirmation device. The confirmation device 40 confirms, based on the access authorization data 26 received by the receiving device 22, which operating functions are permitted for the user to perform. Based on this confirmation, the access control device 28 accesses the technical facility in the manner described above, such that it only permits the user to access the selected operating functions that the user is authorized to perform.
[0056] To confirm the authorization, the confirmation device 40 can access a server via a communication interface 42, for example via a local data network 44. The server can provide the access control device 28 with the authorization for the authenticated user based on the user identity. Alternatively or additionally, the authorization can also be stored in the access control device 28 itself.
[0057] According to the invention, the receiving device 22 is also adapted to supplement the access authorization data 26 with a dynamic part 46 and send the dynamized access authorization data 48 to the access control device 28.
[0058] In particular, the receiving device 22 can dynamize the access authorization data 26 depending on the read - out process, that is, directly at the start of the access control process chain. For example, the receiving device 22 accumulates the dynamic part 46 for the access authorization data 26 in each read - out process. It is also conceivable that this dynamization is associated with the presence of the mobile data carrier within the effective range of the receiving device 22. In other words, the receiving device 22 can be adapted such that the access authorization data 26 is dynamized only when the mobile data carrier 24 is "inserted" and can act contactlessly, that is, the access authorization data 26 can be detected by the receiving device 22.
[0059] The dynamic part 46 can be a part of the access authorization data 26 that changes over time. Thus, the dynamized access authorization data 48 at a first point in time for a certain authorization is different from the dynamized access authorization data 48 at another point in time for the same authorization. When continuously reading out the access authorization data 26 from the mobile data carrier 24, the receiving device 22 can, for example, add a time stamp to or combine the read - out access authorization data 26 with a time stamp to produce the dynamized access authorization data 48.
[0060] The dynamic part can be in particular a defined template, which is combined with the access authorization data 26 read in by the mobile data carrier. The template can include, for example, an authorization, a sequence number, a count, a current session key, one or more previous session keys, an absolute time value and / or a relative time value. In the case of NFC, the session key can be, for example, the current NFC session key and / or one or more NFC session keys of a previous period. The template can in particular be a defined combination of a plurality of the aforementioned elements. The more complex the template, the higher the achievable confidence level based on the probability conclusion can be.
[0061] The dynamicized access authorization data 48 are transmitted to the access control device 28 and the contained access authorization data 26 are used for access control in the manner described above. The dynamic part 46 is used to check the timeliness of the access authorization data 48 and can be used to implement security functions. The dynamic part can be used to ensure, in particular, that access to the technical facility or certain operating functions of the technical facility is unlocked only when current access authorization data are present.
[0062] The dynamic part is analyzed by comparing with the expected state. In other words, the defined template must correspond to the expected template. For example, within the template, the count must be within a certain range based on the previous value. It is also possible to confirm the expected value determined based on the read-out time and the FS cycle time of itself, which defines the expected state of the dynamic part. This comparison can identify values that are too small, too large and / or remain equal over time. It can also be checked whether the session key changes beyond a certain time. It should be understood that the dynamic part is not limited to the aforementioned examples, but can include other continuously changing information.
[0063] Depending on the design of the dynamic part (in particular defined templates), different verification schemes can be combined so that the probability of failure can be reduced to a defined level. In particular, the probability of failure can be reduced to such an extent that it allows verification of the system according to a high safety category without the receiving device itself having to be designed as a fail-safe unit.
[0064] If the dynamic part does not change over a defined period of time or does not correspond to a defined expected state, access to the technical installation or individual operating functions of the technical installation can be disabled and safety functions implemented, if appropriate, to transfer the machine to a safe state. The latter is, however, only a last resort. Advantageously, the technical installation continues to operate and only certain operating functions are disabled or restricted, so that the availability of the technical installation is necessarily limited by access control.
[0065] In one embodiment, the access control device 28 can also transfer the unlock obtained from the dynamic access authorization data 48 to the fail-safe control unit 20, which actually disables or unlocks the operating functions and can implement a safety function when appropriate, which reduces the risk based on the machine to an acceptable level. It is also conceivable that the fail-safe control unit 20 performs the template verification process completely or at least partially instead of the access control device 28.
[0066] Thereupon, the fail-safe control unit 20 can control the technical facility 12 in a manner known per se and is characterized by the presence of redundant processing units 50a, 50b and a safety output 52. The redundant processing units 50a, 50b can monitor each other and act on the safety output 52 independently of each other.
[0067] In one embodiment, the access control device 28 can be a unit integrated in the fail-safe control unit 20. Advantageously, however, the access control device 28 can also be implemented as a separate unit or a module of the fail-safe control unit 20, whereby access control can be implemented independently of the safety control. The technical facility monitored by the fail-safe control unit 20 can, for example, be supplemented with access control in a simple manner without having to change or replace the hardware on the technical facility side or having to adapt the fail-safe control unit 20. Thus, the access control system according to the present disclosure can be retrofitted and supplemented particularly simply even in the case of existing systems.
[0068] Figure 2a and 2b Two possibilities for adapting the dynamic part 46 are shown by way of example. It should be understood that other variants (as described previously) can be envisaged to dynamize the transmitted information.
[0069] Figure 2a A data stream is shown, where the dynamic part includes an incrementing count 46a. With each read access authorization data 26, the count is incremented by one, and the current value of the count is added to the access authorization data 26. The packet transmitting the access authorization data 26 can thereby be extended by an additional count range in which the current value of the count is stored. In this way, only when the access authorization data remains unchanged during the cycle are the individual data packets different from the previous data packets.
[0070] In Figure 2b instead of a count, a timestamp 46b is added as the dynamic part to the incoming data 16. The timestamp 46b can in particular mark the time point at which the associated access authorization data 26 of the mobile data carrier 24 has been completely read out. In this way, it is also possible to dynamize the access authorization data.
[0071] Adding the dynamic part 46 only creates the possibility of dynamizing the information to be transmitted. Alternatively, access authorization data 26 can also be combined with the dynamic part, for example by a corresponding coding that combines the access authorization data 26 with a dynamic element. Thus, in one embodiment, a key ID can be counted.
[0072] Periodic encryption is also conceivable, in which different encrypted data is generated from the same data in each period. However, in contrast, simply adding dynamic information has the advantage that the signal processing during the generation and separation of the dynamized access authorization data can be designed to be particularly simple.
[0073] Using a count and a timestamp as the value of the dynamic part (as shown in Figure 2a and Figure 2b should only be understood as exemplary. Preferably, a plurality of dynamic or non-dynamic data are combined and combined to produce a complex template that depends on as many parameters as possible, which are different or based on different dynamic behaviors, such as different change periods. The more complex the template, the higher the achievable confidence level can be.
[0074] Figure 3 An embodiment of the access control device 28 is shown in a simplified schematic diagram. The access control device 28 is designed as an independent module and is arranged in its own housing 54. In this design, the access control device 28 can be retrofitted particularly easily even in an existing system.
[0075] In this embodiment, the access control device 28 has a processing unit 56 and a plurality of interfaces 42, 58, 60, 62.
[0076] The processing unit 56 can receive access authorization data via a first interface 58, and these access authorization data are verified by the processing unit 56. Via a second interface 60, the access control device 28 can configure a selection device connected thereto based on the verified access authorization data. This configuration can include controlling the selection device so that the selection device only allows a user to access the operating functions for which the access authorization data verification of the technical facility is valid.
[0077] The processing unit 56 can have a confirmation device that extracts the corresponding authorization from the access authorization data 26 when the authorization is encoded in the access authorization data. Alternatively or additionally, the access authorization data can also contain reference specifications, such as a user identification code, by means of which the confirmation device 40 can obtain the corresponding authorization. For this purpose, the access control device 28 can have an additional interface 42, and the confirmation device is connected to a data memory via this additional interface. The confirmation device can be integrated in the processing unit 56 or implemented as a software module of the processing unit.
[0078] The access authorization data received by the access control device 28 via the first interface 58 (as described above) are also accumulated with a dynamic part 46, which can be extracted, analyzed and associated with a defined expected state by the processing unit 56. With the help of the dynamic part 46 of the access authorization data 26, the access control device 28 can draw possible conclusions therefrom: whether the access authorization data 26 have been read out from the receiving device as expected and are still current (the receiving device itself does not have to have a security device).
[0079] In contrast, the access control device 28 can advantageously be designed as a security device and for this purpose have a further processing unit 64 connected in parallel with the processing unit 56. The parallel processing units 56, 64 can be adapted such that they monitor each other in order to ensure fail-safe operation of the access control device 28.
[0080] In another embodiment, the access authorization device 28 can also be adapted to itself take over the fail-safe control of the technical installation via the additional safety output 66. This can have the advantage that the access control can be realized independently of the existing safety technology. Advantageously, however, the access authorization device 28 is configured to cooperate with an already existing fail-safe control unit 20 and, if appropriate, to completely or partially delegate the evaluation of the dynamicized data to this fail-safe control unit 20. This can have the advantage that the access authorization device 28 can be reduced to a minimum of required components, so that it can be realized particularly simply and cost-effectively.
[0081] at last, Figure 4 An embodiment of an access control method for controlling user access to one or more operating functions of a technical facility is exemplarily presented in a flow chart.
[0082] A first step S101 comprises receiving access authorization data from a receiving device which reads the access authorization data from the mobile data carrier and continuously supplements these access authorization data with dynamic parts.
[0083] The second step S102 comprises: verifying the access authorization data by a processing unit. The processing unit extracts information about which operating functions can be unlocked from the access authorization data. In one embodiment, the information can be derived directly from the access authorization data or obtained by an external unit.
[0084] The third step S103 includes: when the dynamically generated access authorization data corresponds to a predefined expected state, generating an unlocking of the following operating functions for which these access authorization data are verified as valid. Thus, the unlocking is associated with whether the dynamic part conveyed by the access authorization data corresponds to the predefined expected state. The dynamic part is chosen here (as previously described) such that it is possible to draw a probable conclusion as to whether the access authorization data has been read in and transmitted as expected.
[0085] The probability of the access authorization data being read in and transmitted as expected can be confirmed as follows by means of a complex template such that the requirements for a high security class are only overall met if the receiving device is not a secure device.
[0086] It should be understood that the method (as exemplarily shown here) can include other steps and is not limited to the order shown here. Other method steps can be obtained from the previously described design of the access control system.
[0087] Furthermore, the scope of protection of the present invention is determined by the following claims and is not limited to the features set forth in the description or shown in the drawings.
Claims
1. An access control system (10) for controlling a user's access to one or more operating functions of a technical facility (12), the access control system comprising: a receiving device (22) adapted to continuously read access authorization data (26) from a mobile data carrier (24); and an access control device (28) adapted to verify the access authorization data (26) received from the receiving device (22), wherein the receiving device (22) is further adapted to continuously supplement the access authorization data (26) with a dynamic part (46) to obtain dynamic access authorization data (48) and to send the dynamic access authorization data (48) to the access control device (28), and wherein the access control device (28) is adapted to: receive from the receiving device (22) the dynamic access authorization data (48) comprising the access authorization data (26) and the dynamic part (46), and generate an unlock signal that the access authorization data (26) is verified valid for the operating functions when the dynamic part (46) corresponds to a defined expected state.
2. The access control system according to claim 1, wherein the receiving device (22) is adapted to supplement the access authorization data (26) with a defined template as the dynamic part each time the access authorization data (26) is read from the mobile data carrier (24).
3. The access control system according to claim 2, wherein the template comprises an authorization, a serial number, a count, a current session key, one or more previous session keys, a key ID, an absolute time value, and / or a relative time value.
4. The access control system according to claim 3, wherein the template is a defined combination of one or more of an authorization, a serial number, a count, a current session key, one or more previous session keys, a key ID, an absolute time value, and a relative time value.
5. The access control system according to any one of claims 1 to 4, wherein the receiving device (22) is adapted to generate the dynamic part (46) only when the access authorization data (26) has been read out completely and / or effectively.
6. The access control system according to any one of claims 1 to 4, wherein the receiving device (22) sends the dynamic access authorization data (48) to the access control device (28) in a single-channel manner.
7. The access control system according to any one of claims 1 to 4, wherein the receiving device (22) has a reading device (34) for reading the mobile data carrier (24) via a radio interface (36).
8. The access control system according to any one of claims 1 to 4, further comprising a selection device (18) for the user to select one or more operating functions, wherein the access control device (28) is further adapted to configure the selection device (18) to allow the user to access only the unlocked operating functions.
9. The access control system according to claim 8, wherein the access control device (28) is adapted to: disable the selection device (18) when the dynamic part (46) does not change over a defined period of time and / or when the dynamic part (46) does not correspond to a defined expected state.
10. The access control system according to any one of claims 1 to 4, further comprising a fault-tolerant control unit (20), the fault-tolerant control unit being adapted to ensure the fault-tolerant operation of the technical facility (12) and to implement safety functions, wherein the access control device (28) is adapted to: transmit the unlocking signal to the fault-tolerant control unit (20) such that the fault-tolerant control unit (20) controls the technical facility (12) depending on the unlocking signal.
11. The access control system according to claim 10, wherein when no unlocking signal is sent, the fault-tolerant control unit (20) transitions the technical facility (12) to a safe state.
12. The access control system according to claim 11, wherein the access control device (28) is an integral part, component, and / or module of the fault-tolerant control unit (20).
13. The access control system according to claim 12, wherein, The access control device (28) is a software module of the fault-tolerant control unit (20).
14. An access control device (28) for controlling a user's access to one or more operating functions of a technical facility (12), the access control device comprising: an interface for receiving dynamic access authorization data (48) comprising access authorization data (26) read continuously from a mobile data carrier (24) and a continuously changing dynamic part (46); a processing unit adapted to verify the access authorization data (26), wherein the access control device (28) is adapted to: generate an unlocking signal that the access authorization data (26) are validly verified for the operating functions when the dynamic part (46) corresponds to a defined expected state.
15. An access control method (100) for controlling a user's access to one or more operating functions of a technical facility (12), the access control method having the following steps: - continuously reading access authorization data (26) from a mobile data carrier (24) by a receiving device (22) and continuously supplementing the access authorization data with a dynamic part (46); - verifying the access authorization data (26) by an access control device (28); and - generating an unlocking signal that the access authorization data (26) are validly verified for the operating functions when the dynamic access authorization data correspond to a defined expected state, Among them, the receiving device (22) continuously supplements the access authorization data (26) with the dynamic part (46) to obtain dynamic access authorization data (48) and sends the dynamic access authorization data (48) to the access control device (28), and Wherein, the access control device (28) receives, from the receiving device (22), the dynamic access authorization data (48) including access authorization data (26) and a dynamic part (46), and generates an unlock signal that is authentication-valid for these operation functions for these access authorization data (26) when the dynamic part (46) corresponds to a defined expected state.
16. A computer-readable storage medium having stored thereon a program including instructions that, when executed by a computer, cause the computer to perform the method according to claim 15.
Citation Information
Patent Citations
system for controlling access to a machine tool
DE102007041768A1
Method and system for activating at least one operating / parameterizing function of a field device in automation technology
DE102016120306A1