Method of confirming or verifying field devices

By setting encrypted signatures on field devices and utilizing the encrypted signature method of asymmetric cryptography, the problem of integrity verification of field devices in automation systems is solved, enabling fast and convenient confirmation of device authenticity and integrity, and ensuring system security.

CN114402565BActive Publication Date: 2025-10-28ENDRESS HAUSER PROCESS SOLUTIONS AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080064764.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-20
Filing Date
2020-08-20
Publication Date
2025-10-28
Estimated Expiration
2040-08-20

AI Technical Summary

Technical Problem

In automated systems, existing technologies struggle to quickly and reliably verify the integrity of field equipment and prevent unauthorized manipulation, especially in systems with hundreds or even thousands of devices, leading to production failures and safety hazards.

Method used

An asymmetric cryptographic signature method is used to ensure the authenticity and integrity of the hardware and software modules of the field device by setting first and second cryptographic signatures on the manufacturer's and customer's sides respectively, and to automate the verification process using private keys and public verification keys.

Benefits of technology

It enables quick and easy verification of the authenticity and integrity of field equipment, prevents unauthorized alterations, and ensures the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114402565B_ABST
    Figure CN114402565B_ABST
Patent Text Reader

Abstract

This invention relates to a method for verifying or authenticating a field device in an automation technology that identifies or monitors physical, chemical, or biological process variables of a process medium, wherein: the field device (FG) comprises multiple hardware and software modules; the field device has a first encrypted signature (S1) on the manufacturer's side (HS); the first encrypted signature (S1) explicitly identifies the device manufacturer and / or original delivery status of the field device (FG), defined by authentic hardware and software / firmware and authentic configuration settings; the origin and integrity of the field device (FG) are verified on the customer's side (KS) by means of... A first cryptographic signature (S1) is used for confirmation / verification; once the field device (FG) is adapted to the defined machine, a second cryptographic signature (S2) is set on the client side (KS) for the field device (FG); the second cryptographic signature (S2) explicitly identifies the adaptation of the field device (FG) on the client side (KS) as the machine-specific expected state of the field device (FG); and during the period when the field device (FG) is installed in the defined machine, at least one confirmation or verification of the field device (FG) is performed on the client side (KS) by means of the second cryptographic signature (S2).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for identifying or verifying field devices that determine or monitor physical, chemical, or biological process variables of process media in automation technologies. Background Technology

[0002] In automation systems, especially process automation systems, field devices are frequently used to detect and / or influence process variables of a medium. The medium itself can be a liquid, gas, or even a solid. Sensors are used to detect these process variables; the sensors used are, for example, integrated into level gauges, flow meters, pressure gauges, thermometers, pH redox potentiometers, conductivity meters, etc. These sensors detect corresponding process variables such as level, flow rate, pressure, temperature, pH value, or conductivity. Actuators, such as valves or pumps, are used to influence these process variables, via which the flow rate of fluid in a pipe section or the level of a medium in a container can be changed. In conjunction with this invention, all devices used in relation to a process and providing or processing process-related information are referred to as field devices. The term "field device" is also understood to refer to remote I / O, radio adapters, and other components located at the field level in the process. Endress+Hauser manufactures and sells a variety of such field devices.

[0003] Field devices are typically connected to fieldbuses. Communication between field devices and / or with higher-level units is conducted via at least one fieldbus protocol commonly used in automation technology. However, increasingly, communication is also conducted via Internet Protocol (IP).

[0004] If unauthorized intervention is performed on one of the field devices—leading to manipulation of that device—it can have significant adverse effects on the operator of the automation system. In the worst-case scenario, manipulation can cause production disruptions in the corresponding plant and / or potentially result in personal injury and property damage. Furthermore, it is important to determine whether manipulation is performed on calibrable field devices.

[0005] To ensure that the configuration of field devices is not manipulated, a complex comparison process is used to examine the current inventory list and configuration parameters. This process determines whether the automation system is still in the expected and defined state as desired by the operator. Considering that hundreds or even thousands of field devices can be used in an automation system, proving through the aforementioned comparison process that additional and / or manipulated field devices is extremely difficult. Due to this very time-consuming verification method, it is often not performed at all.

[0006] Furthermore, customers lack the opportunity to easily and readily determine whether only original manufacturer components are installed in field equipment; this applies not only to initial deliveries but also to repair instances where the field equipment enters the service provider's range for repair purposes. In the context of this invention, original components are understood to refer to hardware components, software components such as firmware and applications, and the parameters or configuration settings of the field equipment.

[0007] To ensure the firmware of field devices is not manipulated, it is known to associate a CRC32 (CRC: Cyclic Redundancy Check)-based checksum with the firmware. This is code capable of detecting data changes. Firmware is understood as software embedded in an electronic device. It is typically stored in flash memory, EPROM, EEPROM, or ROM, and cannot be replaced by the user or can only be replaced by special means or functions. The term originates from the fact that firmware is functionally permanently linked to the hardware. Without firmware, the hardware cannot be used meaningfully. Firmware serves as an intermediate position between hardware and application software, representing a potentially interchangeable program for the field device. Incidentally, known authenticity protection is preferably used in calibrable field devices. Solutions for providing general operational protection for field devices are not yet known. Summary of the Invention

[0008] The purpose of this invention is to provide a simple method for checking the integrity of field devices. Within the meaning of this invention, a field device is considered intact when all its components correspond to the original manufacturer's condition at the time of delivery to the user.

[0009] This objective is achieved through a method for verifying or authenticating a field device used in an automation technology to identify or monitor physical, chemical, or biological process variables of a process medium, wherein the field device comprises multiple hardware and software modules. On the manufacturer's side, the field device is provided with a first cryptographic signature, which explicitly identifies the device manufacturer and / or original delivery state of the field device, defined by authentic hardware and software / firmware and authentic configuration settings. On the customer's side, the origin and / or integrity of the field device are verified / authenticated using the first cryptographic signature. After the field device has been adapted to a defined application, a second cryptographic signature is provided to the field device on the customer's side, which explicitly identifies the adaptation of the field device on the customer's side as the application-specific intended state of the field device. During the duration of the field device's installation in the defined application, the customer can perform verification or authentication of the field device at any time using the second cryptographic signature.

[0010] Field devices, typically designed in a modular fashion, are preferably assigned a first cryptographic signature at the end of the manufacturing process. Field devices consist of hardware components (e.g., electronic components) and software components (such as firmware, applications, and configuration parameters). This first cryptographic signature explicitly identifies the manufacturer and / or the original delivery state, thereby confirming the integrity of the corresponding field device.

[0011] Upon delivery, this encrypted signature from the manufacturer or supplier is used to enable the customer / user to verify the origin and integrity of the field equipment.

[0012] If the customer has already installed field devices in, for example, an automation system, these field devices are typically adapted to the corresponding use case or application on the customer's side. The field devices are configured / parameterized, where, where applicable, configuration data preset by the manufacturer is changed. A second encrypted signature is then set for the field device on the customer's side. This signature is, for example, customer-specific, system-specific, device-specific, etc. Using this second signature, the customer / authorized user can thus identify the expected state of the field device according to their expectations.

[0013] Based on this further signature, customers can check the integrity of the field equipment at any time. In particular, they can easily check and determine whether changes have been made to electronic components, firmware, software, and / or configuration data of the field equipment.

[0014] Therefore, field device verification or validation can be used to check whether the actual state of the field device corresponds to the expected state authorized and / or defined by the customer / user, and whether the field device is intact. Furthermore, if unauthorized changes to the hardware and / or software modules of the field device have been attempted or performed, this can be easily determined via signature comparison.

[0015] According to one embodiment of the method of the present invention, the first cryptographic signature and / or the second cryptographic signature are created by an asymmetric cryptosystem consisting of a private key and a public verification key, and a public key.

[0016] The term "asymmetric cryptography" is a general term used for public-key encryption methods, public-key authentication, and digital signatures. An asymmetric cryptography system, or public-key cryptography system, is an encryption method in which, unlike symmetric cryptography, communicating parties do not need to know a shared secret key. Each user generates their own key pair consisting of a secret part (private key) and a non-secret part (public key). The public key allows anyone to encrypt data for the private key owner, check their digital signatures, or authenticate them. The private key enables its owner to decrypt data encrypted using the public key to generate or verify digital signatures.

[0017] Using this invention and its embodiments, it is possible to reliably determine whether a field device module is genuine and whether the field device is still in the expected state of customer expectation and authorization through simple, automated signature checks. Field devices without valid signatures can be automatically identified and selectively rejected. Detailed Implementation

[0018] use Figure 1 The method for identifying or verifying a field device (FG) according to the present invention is explained in more detail, which identifies or monitors physical, chemical, or biological process variables of a process medium in an automation technology. Figure 1 Multiple field devices (FGs) are shown located on the manufacturer's side (HS) and the customer's side (KS). Each field device (FG) consists of multiple hardware and software modules. On the manufacturer's side (HS), the field device (FG) is equipped with a first encrypted signature (S1) before delivery to the customer. The first encrypted signature (S1) explicitly identifies the device manufacturer and / or original delivery status of the field device (FG). The field device guarantees authentic hardware and software / firmware, as well as authentic configuration settings.

[0019] On the customer side KS, the origin and integrity of the field device FG are confirmed / verified by the service personnel S using the first encrypted signature S1.

[0020] Typically, a new configuration is performed on the customer side to optimally adapt the field device FG to the defined application in which it is installed. The field device FG is then set with a second encrypted signature S2 by service personnel S on the customer side KS. The second encrypted signature S2 explicitly identifies the adaptation of the field device FG performed on the customer side as the application-specific expected state of the field device FG. This allows the customer to choose to use the second encrypted signature S2 at any time—even while the field device FG is running in the defined application—to determine whether the field device is still in its verified and validated expected state. Because the verification / validation process can be automated, actual / expected checks can be performed without spending a significant amount of time, even during the operation of the field device FG.

Claims

1. A method for validating or authenticating a field device (FG) that identifies or monitors physical, chemical, or biological process variables of a process medium in an automation technology, wherein, The field device (FG) consists of multiple hardware modules and software modules, and the method includes the following steps: - On the manufacturer's side (HS), a first cryptographic signature (S1) is set for the field device (FG), wherein the first cryptographic signature (S1) explicitly identifies the device manufacturer and / or original delivery status of the field device (FG), the device manufacturer and / or original delivery status being defined by genuine hardware and software / firmware and genuine configuration settings, wherein the origin and integrity of the field device (FG) are confirmed / verified on the customer's side (KS) by means of the first cryptographic signature (S1); - After the field device (FG) is adapted to a defined application example, a second cryptographic signature (S2) of the field device (FG) is set on the client side (KS), wherein the second cryptographic signature (S2) is generated by the client and used only by the client, independent of the device manufacturer, and the second cryptographic signature (S2) explicitly identifies the adaptation of the field device (FG) performed on the client side (KS) as a client-authorized expected state specific to the defined application example of the field device (FG), wherein the expected state includes the expected hardware and software / firmware state and the expected configuration settings; and - At least one acknowledgment or verification of the field device (FG) is performed by the customer on the customer side (KS) using the second cryptographic signature (S2), wherein the acknowledgment or verification is performed by the customer during the installation process of the defined application example, or may be performed at any time after the second cryptographic signature (S2) is generated.

2. The method according to claim 1, in, System-specific and / or device-specific signatures are used as the second cryptographic signature (S2).

3. The method according to claim 1 or 2, in, Use the verification or validation of the field device (FG) to check whether the actual state of the field device (FG) matches the expected state and whether the field device (FG) is intact, or whether any unauthorized changes have been made to the hardware and / or software modules of the field device (FG).

4. The method according to claim 1 or 2, wherein, The first cryptographic signature (S1) and / or the second cryptographic signature (S2) are created via an asymmetric cryptographic system consisting of a private key and a public verification key, and a public key.

5. The method according to claim 1 or 2, wherein, Electronic components are identified as hardware modules.

6. The method according to claim 1 or 2, wherein, Recognize firmware or configuration parameters as software modules.

Citation Information

Patent Citations

  • Boot blocks for software

    US20030196110A1

  • Method for isolating special functionalities in field devices used in automation technology

    US20100153736A1