Investment of digital certificates
By sending executable certificate data to the field device, the terminal device automatically installs the digital certificate, solving the complex installation problem in the prior art and realizing simplified certificate installation and secure communication.
Patent Information
- Application Number
- CN202510759418.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-06-12
- Filing Date
- 2025-06-09
- Publication Date
- 2025-12-12
AI Technical Summary
In existing technologies, the installation of digital certificates for field devices on terminal devices is complex and usually requires manual operation by professional technicians, resulting in a poor user experience.
By sending executable certificate data to the field device, the terminal device receives and executes this data, thereby automatically installing the digital certificate, adapting it to the terminal device's operating system, and performing communication verification under the HTTPS protocol.
It simplifies the installation process of digital certificates on terminal devices, improves the user experience, and enables ordinary users to easily complete the installation and verification of certificates, ensuring communication security.
Smart Images

Figure CN121125106A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a method for commissioning a digital certificate of a field device on a terminal device. According to a further aspect of the present application, a field device is proposed which can be used when executing the method. A computer-implemented method for execution on the field device is also proposed. BACKGROUND
[0002] In process automation technology, field devices are typically used to acquire and / or influence process variables. Examples of such field devices include fill level measuring devices, limit level measuring devices and pressure measuring devices, which have sensors for acquiring a corresponding process variable such as a fill level, a limit level or a pressure. Typical application scenarios for such field devices include areas such as flood forecasting, inventory management or other decentralized measurement tasks. Known field devices of the type described above can transmit measurement values so that a superior unit triggers a predetermined action depending on the determined measurement values. For example, an inlet can be closed or an outlet can be opened depending on the measurement values of a fill level measuring device if a limit value is exceeded.
[0003] In order to enable remote operation, configuration or checking, the field device can provide access via a network connection. For example, a web server application can be implemented in the field device. The web server application can provide a user interface which is accessible via the HTTP protocol. The abbreviation HTTP stands for HyperText Transfer Protocol. Thus, a user can use a web browser to perform device settings or acquire measurement values remotely. The user can connect to the field device via a terminal device, for example a personal computer.
[0004] For security reasons, encrypted communication between the field device and the terminal device is preferred. The use of digital certificates is also typically provided. The terminal device can use the digital certificate to verify that a remote device with which it communicates is indeed a field device. For this purpose, methods known from public key cryptography can be used. For example, secure communication using the HTTPS protocol can be established. The abbreviation HTTPS stands for HyperText Transfer Protocol Secure.
[0005] However, communication using the HTTPS protocol requires that the terminal device is able to check the digital certificate of the field device. For example, if the digital certificate is pre-stored on the terminal device, a corresponding comparison can be made before communication with the field device. This requires professional installation of the digital certificate on the terminal device. If a user wants to access the field device via his own terminal device, he must first install the digital certificate. For this purpose, for example, the user can download the digital certificate from the field device via an unsecured connection and install the digital certificate on the terminal device. Subsequent communication between the terminal device and the field device can take place via the HTTPS protocol. However, the installation of the digital certificate is comparatively complex and can only be done by a technical expert. Summary of the Invention
[0006] Therefore, an object of the present invention is to provide a simplified method for deploying digital certificates of field devices on a terminal device. Another object of the present invention is to provide a field device that can be used in conjunction with this method. Yet another object of the present invention is to provide a computer-implemented method for execution on such a field device.
[0007] This objective is achieved by the method according to claim 1, the field device according to claim 14, and the computer-implemented method according to claim 15. The dependent claims relate to alternative embodiments of the invention. It should be noted that the features listed in the independent and dependent claims can be combined in any way, provided such combination is technically feasible. This also applies across boundaries between claim classes, even if one claim does not refer to another. The invention is further described and illustrated in particular with reference to the accompanying drawings. Features included in the specification can also be freely combined, provided it is technically feasible.
[0008] According to a first aspect of the invention, a method is provided for deploying a digital certificate of a field device on a terminal device, wherein the digital certificate is assigned to the field device and used to verify the identity of the field device during communication with the field device via a secure data transmission protocol. The method includes the terminal device sending a request (Anfrage) to the field device for transmitting the digital certificate, and the field device receiving the request for transmitting the digital certificate. In response to receiving the request for transmitting the digital certificate, the field device sends executable certificate data to the terminal device, wherein the executable certificate data includes executable instructions and the digital certificate. Furthermore, the terminal device receives the executable certificate data. Subsequently, the terminal device executes the executable certificate data, thereby installing the digital certificate on the terminal device. Thus, the digital certificate is deployed on the terminal device.
[0009] A digital certificate is installed on a terminal device by executing executable certificate data. This makes it easier for users of the terminal device to install the digital certificate. Within the scope of the method according to the invention, the terminal device first makes a request for the transmission of the digital certificate. For example, this request may include a request to download the digital certificate. According to the invention, the download can be performed through a website provided by the field device. According to the invention, a web server application can be run on the field device, which allows for the configuration of the field device. According to the invention, the web server application can be adapted to provide data via HTTP and HTTPS protocols. More generally, the web server application can be adapted to provide data via both insecure and secure data transmission protocols.
[0010] According to the present invention, the terminal device can make a request for transmitting a digital certificate without using the HTTP protocol. For example, it is conceivable that the request can be transmitted via the FTP protocol, and therefore the request can be an FTP request. Subsequently, the field device sends the executable certificate data to the terminal device. For example, this can be achieved through a download process via the FTP protocol, in which the FTP application of the field device preferably sends the executable certificate data to the terminal device.
[0011] Executable certificate data is executed on the terminal device. By executing the executable certificate data, the digital certificate is installed on the terminal device. The installation process performed in this context can have very different characteristics, depending specifically on the terminal device's operating system. According to the present invention, the certificate can be copied to a specific folder on the terminal device, specific registry settings can be made on the terminal device, specific program and / or system settings can be made on the terminal device, and / or other steps required to activate or install the digital certificate on the terminal device can be performed.
[0012] In some embodiments, the installation process may require interaction with the user of the terminal device. For example, the user of the terminal device may need to confirm the installation process or a portion thereof by performing input on the terminal device. Furthermore, the user may need to enter specific data required for the installation of the digital certificate. Even if the described user interaction is necessary, the installation of the digital certificate using executable certificate data is superior to manual installation of the digital certificate, as it significantly simplifies the installation process in this case. After installation, the certificate can preferably be used immediately, allowing it to be directly used by a web browser application on the terminal device. However, according to conceivable variations of the invention, the user may subsequently need to make one or more adjustments to the terminal device to ultimately enable the digital certificate to be used by the terminal device. For example, the terminal device may be a personal computer, laptop, tablet, smartphone, or other computer.
[0013] Preferably, when performing the method, at least one piece of information related to the terminal device's operating system is sent from the terminal device to the field device, and the field device receives the at least one piece of information related to the terminal device's operating system, wherein the executable certificate data sent from the field device to the terminal device is adapted to the terminal device's operating system. Depending on the operating system on the terminal device, various steps may be required to install the digital certificate on the terminal device. In particular, executable instructions that can be executed on a first operating system may not necessarily be executable on a second operating system. Executable certificate data adapted to the terminal device's operating system should be advantageously understood as executable certificate data that can be executed on the terminal device, wherein such execution results in the installation of the digital certificate on the terminal device.
[0014] Furthermore, differences may exist between different operating system versions, thus requiring different versions of executable certificate data depending on the operating system version used. For example, operating system-related information can be transmitted to the field device via a selection made through the field device's user interface. For instance, the terminal device's operating system and / or operating system version can be selected via a drop-down list displayed in the user interface provided by the field device. According to the invention, the field device can also extract at least one piece of information related to the operating system from data fields transmitted by the terminal device's web browser during communication with the field device's web server. For example, a so-called user-agent field can be evaluated, wherein, according to the HTTP protocol, the terminal device transmits information related to the web browser used and information related to the operating system used to the field device.
[0015] Specifically, the at least one piece of information may include the operating system type (e.g., Windows, macOS, or GNU / Linux). Optionally, this at least one piece of information may include a subtype of the operating system, the version number of the operating system, or other data characterizing the operating system. Based on this at least one piece of information, the field device sends executable certificate data suitable for the terminal device or its operating system to the terminal device. Therefore, this method can be implemented using different types or versions of operating systems.
[0016] Advantageously, in response to receiving at least one piece of information relating to the operating system of the terminal device, the field device selects executable certificate data to be distributed to the terminal device from its data storage based on the at least one piece of information. For example, the field device may store multiple variations of the executable certificate data. For example, based on the operating system type and / or operating system version, a suitable variation of the executable certificate data (i.e., preferably a variation matching the terminal device) is selected and downloaded from the data storage and sent to the terminal device.
[0017] According to the present invention, a field device can receive and store executable certificate data from a remote station. The field device can store the received executable certificate data in, for example, its internal data storage. Therefore, the executable certificate data can be available at a later point in time. Preferably, the field device receives and stores multiple variations of the executable certificate data. In principle, the remote station can be any device capable of communicating with the field device using its network interface. The remote station is preferably an update server, such as one provided by the field device's manufacturer. However, it can also be other servers, computers, etc. Preferably, the executable certificate data is transmitted from the remote station to the field device in encrypted form, and particularly preferably, the field device pre-authenticates the remote station to ensure a sufficient level of security.
[0018] Preferably, in response to receiving at least one piece of information relating to the operating system of the terminal device, the field device generates executable certificate data such that it is suitable for installing the digital certificate on the operating system of the terminal device. According to this variation of the invention, the field device does not access stored executable certificate data, but generates the data as necessary. Specifically, generation can be understood as combining the digital certificate with executable instructions in an appropriate manner. According to this variation of the invention, executable instructions can be generated or adapted such that they are suitable for installing the digital certificate on the operating system of the terminal device. This proves particularly useful when operating system variants have a large number of different characteristics, because not all required executable certificate data variants can exist in the field device's data storage. In this case, the field device can generate executable certificate data according to the operating system of the terminal device. According to the invention, the field device can store the generated executable certificate data for later use. Executable certificate data is also generated if (e.g., by changing the stored installation path or adjusting the version number or identifier, etc.) only the existing program pattern of the executable certificate data is modified.
[0019] In executing this method, the field device preferably receives a digital certificate from a remote station, generates executable certificate data, and stores the executable certificate data. According to this embodiment, the field device only receives the digital certificate from the remote station. Therefore, the field device needs to generate executable certificate data. According to the invention, this can be achieved by combining the digital certificate with executable instructions.
[0020] According to an advantageous embodiment of the invention, the executable certificate data is contained within the executable file. Therefore, a single executable file can be provided to the user, who only needs to run it. In this case, the user does not need to process multiple files, or even download multiple files separately (e.g., from a field device). Alternatively, the executable instructions and digital certificate may not be stored in the executable file, but rather in other types of files. Therefore, according to the invention, data can be stored in a container file, particularly in a compressed container file (e.g., a ZIP compressed file forming the executable certificate data).
[0021] According to one possible variation of the invention, the file is an executable binary file. For example, an executable EXE or MSI file could be provided for the Windows operating system. Other examples of executable binaries are ELF format files for GNU / Linux operating systems or Mach-O format files for macOS operating systems. The binary file may contain both executable instructions and a digital certificate.
[0022] Alternatively, the file can contain script files. Script files are characterized by being executed by an interpreter. For example, script files include PowerShell scripts for Windows or shell scripts for Linux and macOS. Typically, script files can be called as easily as binary files, so they generally have no disadvantages in terms of user-friendliness. However, the advantage of script files is that they can be created or modified relatively easily because it usually does not require generating or modifying binary code. Therefore, they are particularly suitable for generation by field devices. Script files can contain executable instructions (preferably executable script lines) and digital certificates (preferably embedded in the form of text data accessible to the executable instructions).
[0023] Preferably, during the execution of executable certificate data, the terminal device performs at least the following steps: if the terminal device is not in administrator mode, a user request is generated to switch the terminal device to administrator mode; and if user input is made on the terminal device in response to the user request, thereby enabling the switch to administrator mode, the terminal device is switched to administrator mode and the digital certificate is copied to the terminal device's certificate storage. If the device is already in administrator mode, only the digital certificate needs to be copied to the device's certificate storage.
[0024] Installing a digital certificate typically requires the operating system to be in administrator mode. Administrator mode grants broader privileges. Specifically, these privileges may include those necessary to modify system and / or operating system settings. Generally, a digital certificate cannot be installed without administrator privileges. If the operating system is not in administrator mode, it is preferable to first generate a user request to switch to administrator mode, following the steps described above. In this case, for example, the terminal device user is prompted to switch to administrator mode so that certificate data can be executed. For example, the user may be prompted to enter an administrator password.
[0025] After switching to administrator mode, the digital certificate is installed. Preferably, installation can be performed by copying the digital certificate to the operating system's certificate store. For example, the certificate store may involve a file path where the digital certificate for the operating system can be stored. Applications on the terminal device (e.g., web browsers) access this file path to read the digital certificate installed on the operating system. If the operating system is already in administrator mode, no user request for switching to administrator mode is required, and it is preferable to copy the digital certificate directly to the certificate store. Within the scope of the method according to the invention, the executable certificate data may also include additional instructions, for example, for outputting information to the user of the terminal device or for requesting additional information required to install the digital certificate on the terminal device.
[0026] Preferably, after installing the digital certificate on the terminal device, the following steps are performed: the terminal device sends a request to the field device to establish a connection via a secure data transmission protocol; the field device receives the request; the field device sends authentication data to the terminal device; the terminal device verifies the authentication data according to the digital certificate; if the verification is successful, the terminal device and the field device communicate via the secure data transmission protocol. Once the digital certificate is installed on the terminal device, communication between the terminal device and the field device via the secure data transmission protocol is possible.
[0027] To initiate the communication process, the terminal device sends a request to the field device to establish a secure connection. The field device then transmits authentication data to the terminal device. This authentication data can be, for example, a digital certificate, but it can also be other data used to authenticate the field device based on a digital certificate stored in the terminal device. Authentication can also be performed using encryption keys and / or cryptographic signatures.
[0028] According to an advantageous embodiment of the invention, the secure transmission protocol is the HTTPS protocol. HTTPS is an internet communication protocol that allows data to be transmitted in encrypted form and also allows authentication of communication participants. However, the secure transmission protocol can also be another data transmission protocol that allows encryption and authentication. The digital certificate is preferably a digital certificate conforming to the X.509 standard. The X.509 standard is an ITU-T standard for generating digital certificates. However, according to the invention, different digital certificates can also be used.
[0029] According to another aspect of the invention, a field device is provided, comprising a sensor for acquiring measurement values, a network interface, and a data processing device. The data processing device is configured to provide options for operating the field device via a secure data transmission protocol through the network interface. Furthermore, the data processing device is configured to receive a request for transmitting a digital certificate from a terminal device via the network interface. The digital certificate is assigned to the field device and used to verify the identity of the field device during communication with it via the secure data transmission protocol. Additionally, the data processing device is configured to, in response to receiving the request for transmitting the digital certificate, trigger an action to send executable certificate data to the terminal device via the network interface. The executable certificate data includes executable instructions and the digital certificate.
[0030] Therefore, the field device according to the invention can be used in conjunction with the methods described above. The field device can have all the features previously described regarding the field device. According to the invention, the field device can be suitable for measuring fill level, limit level, pressure, or other measured values. The network interface can be, for example, an Ethernet interface or a WLAN interface. However, it can also be other network interfaces, such as a two-wire interface. The operational options for operating the field device via the network interface are preferably implemented by a web server application installed on the field device. This web server application preferably provides options for configuring the field device and / or acquiring data from the field device. For this purpose, according to the invention, a user interface for the field device can be provided, which can be accessed via a web browser. According to the invention, the data processing device can be a microcontroller, an embedded computer, or other computer or other computer unit of the field device. The data processing device is preferably connected to the network interface of the sensor and / or the field device. According to the invention, the field device can also have a data storage device, which is preferably also connected to the data processing device.
[0031] According to an advantageous embodiment of the invention, the field device can receive at least one piece of information related to the operating system of the terminal device via the field device's network interface. According to an advantageous embodiment, the data processing apparatus can be configured to cause the field device to send executable certificate data adapted to the terminal device's operating system to the terminal device via the network interface.
[0032] According to an advantageous embodiment, the field device is configured to, in response to receiving at least one piece of information relating to the operating system of the terminal device, select executable certificate data from the field device's data memory for distribution to the terminal device, based on the at least one piece of information, for distribution. According to the invention, this can be accomplished by a data processing apparatus.
[0033] Furthermore, the field devices can be configured to receive executable certificate data from a remote station via a network interface. Specifically, the data processing unit can be configured to store the executable certificate data received from the remote station in the field device's data storage. Further advantageously, the field devices are configured to generate executable certificate data in response to receiving at least one piece of information relating to the operating system of the terminal device, making them suitable for installing digital certificates on the terminal device's operating system. Advantageously, the certificate data is generated by the data processing unit of the field device.
[0034] Advantageously, the field device can be configured to receive digital certificates via a network interface, specifically to generate executable certificate data through the field device's data processing apparatus, and to store the executable certificate data in the field device's data storage. It should be understood that the executable certificate data can be included in an executable file according to the invention, wherein the file can be an executable binary file or a script file according to embodiments of the invention.
[0035] The field device can also be configured to receive requests to establish a connection via a secure data transmission protocol. Receiving is preferably accomplished via the field device's network interface. The field device can be configured to send authentication data to the terminal device in response to receiving a request. Subsequently, if the terminal device successfully verifies the authentication data, communication can occur between the terminal device and the field device via the secure data transmission protocol. According to the invention, the secure data transmission protocol can be the HTTPS protocol. According to the invention, the digital certificate can be an X.509 certificate.
[0036] According to another aspect of the present invention, a computer-implemented method executed on a field device having a network interface is provided. This computer-implemented method includes at least the following steps: the network interface receives a request from a terminal device for transmitting a digital certificate, wherein the digital certificate is assigned to the field device and used to verify the identity of the field device in a device communicating with the field device via a secure data transmission protocol; and, in response to receiving the request for transmitting the digital certificate, triggers an action of sending executable certificate data to the terminal device through the network interface, wherein the executable certificate data includes executable instructions and the digital certificate. This method is preferably executed by the data processing apparatus of the aforementioned field device. According to the present invention, the computer-implemented method can be executed with any desired modifications to achieve the functionality of the aforementioned field device. Attached Figure Description
[0037] The invention will be described by way of example with reference to the accompanying drawings.
[0038] Figure 1 A schematic diagram of the field equipment and terminal equipment is shown.
[0039] Figure 2 This diagram illustrates the sequence of deploying digital certificates from field devices on terminal devices.
[0040] Figure 3 This diagram illustrates executable certificate data. Detailed Implementation
[0041] Figure 1A schematic diagram of field device 1 and terminal device 2 is shown. Field device 1 has a sensor 3 for measuring pressure. Sensor 3 is connected to a data processing unit 4, which can store and evaluate the measurements acquired by sensor 3. Data processing unit 4 is a powerful microcontroller on which a web server application runs. Data processing unit 4 is also connected to a network interface 5 of field device 1. The web server application provides a user interface for field device 1. Terminal device 2 can access the user interface via network connection 6 to configure field device 1. Field device 1 is also equipped with a data storage device 7, which is connected to the data processing unit 4 of field device 1.
[0042] Figure 2 This diagram illustrates the sequence for deploying the digital certificate of field device 1 on terminal device 2. In the first step, terminal device 2 sends a certificate request 8 for transmitting the digital certificate to field device 1 via a network connection. The certificate request 8 is triggered when the user of terminal device 2 clicks on the field device 1's user interface, which provides a field for downloading the certificate, through its network interface. In the user interface of field device 1, the user has pre-selected their operating system, so the certificate request 8 also includes information related to the operating system of terminal device 2.
[0043] Upon receiving certificate request 8 and information related to the operating system of terminal device 2, the data processing unit of field device 1 generates executable certificate data. The executable certificate data contains the digital certificate of terminal device 2 and executable instructions. Field device 1 generates executable instructions suitable for execution on terminal device 2. For this purpose, information related to the operating system of terminal device 2 is evaluated. To generate the executable certificate data, the digital certificate is pre-loaded from the data storage of field device 1. Field device 1 now initiates instruction dispatch 9, in which the executable certificate data is sent to terminal device 2. Certificate request 8 and instruction dispatch 9 are executed via the HTTP protocol.
[0044] Terminal device 2 receives executable certificate data. The user now triggers the execution of the executable certificate data on terminal device 2, thereby installing a digital certificate on device 2. During this process, the digital certificate is copied to the certificate storage on terminal device 2. An HTTPS connection can now be established between field device 1 and terminal device 2. To do this, terminal device 2 sends a connection request 10 to field device 1, thereby initiating the initialization of the HTTPS protocol. Upon receiving connection request 10, field device 1 triggers a certificate issuance 11 to terminal device 2, in which field device 1 transmits the digital certificate to terminal device 2. Terminal device 2 compares the digital certificate obtained in this manner with the digital certificate stored in its certificate storage to confirm the validity of the digital certificate. In this way, authentication of field device 1 is completed. Several further steps, not shown here, are required to complete the initialization of the HTTPS protocol. Subsequently, encrypted communication can be established between field device 1 and terminal device 2 via the HTTPS protocol.
[0045] Figure 3 A schematic diagram of executable certificate data 12 is shown. Executable certificate data 12 is formed from a script file containing a digital certificate 13. In addition to the digital certificate 13, the script file also contains executable instructions 14. When executable certificate data 12 is invoked on a terminal device, executable instructions 14 are executed. As a result, the digital certificate 13 is copied to the certificate storage of the terminal device.
[0046] List of reference numerals
[0047] 1. On-site equipment
[0048] 2. Terminal equipment
[0049] 3 Sensors
[0050] 4. Data processing device
[0051] 5. Network Interface
[0052] 6. Network connectivity
[0053] 7. Data Storage
[0054] 8 Certificate Request
[0055] 9. Command Dispatch
[0056] 10 Connection Request
[0057] 11. Certificate Issuance
[0058] 12 Executable Certificate Data
[0059] 13 Digital Certificates
[0060] 14 Executable instructions
Claims
1. A method for enabling the use of a digital certificate (13) of a field device (1) on a terminal device (2), wherein, The digital certificate (13) is assigned to the field device (1) and used to verify the identity of the field device (1) during communication with the field device (1) via a secure data transmission protocol, wherein the method includes: The terminal device (2) sends a request to the field device (1) for transmitting the digital certificate (13); The field device (1) receives the request for transmitting the digital certificate (13); In response to receiving the request for transmitting the digital certificate (13), the field device (1) sends executable certificate data (12) to the terminal device (2), wherein the executable certificate data (12) includes executable instructions (14) and the digital certificate (13); The terminal device (2) receives the executable certificate data (12); and After the terminal device (2) receives the executable certificate data (12), the terminal device (2) executes the executable certificate data (12) to install the digital certificate (13) on the terminal device (2).
2. The method according to claim 1, characterized in that, The method further includes: Send at least one piece of information related to the operating system of the terminal device (2) to the field device (1); and The field device (1) receives at least one piece of information related to the operating system of the terminal device (2). The executable certificate data (12) sent by the field device (1) to the terminal device (2) is adapted to the operating system of the terminal device (2).
3. The method according to claim 2, characterized in that, In response to receiving at least one piece of information relating to the operating system of the terminal device (2), the field device (1) selects the executable certificate data (12) to be dispatched to the terminal device (2) from the data storage (7) of the field device (1) according to the at least one piece of information.
4. The method according to any one of the preceding claims, characterized in that, The method further includes: The field device (1) receives the executable certificate data (12) from the remote station; The field device (1) stores the executable certificate data (12).
5. The method according to claim 2, characterized in that, In response to receiving at least one piece of information relating to the operating system of the terminal device (2), the field device (1) generates the executable certificate data (12) such that the executable certificate data is suitable for installing the digital certificate (13) on the operating system of the terminal device (2).
6. The method according to any one of claims 1 or 2 or according to claim 5, characterized in that, The method further includes: The field device (1) receives the digital certificate (13) from the remote station; The field device (1) generates the executable certificate data (12); and The field device (1) stores the executable certificate data (12).
7. The method according to any one of the preceding claims, characterized in that, The executable certificate data (12) is contained in the executable file.
8. The method according to claim 7, characterized in that, The file is an executable binary file.
9. The method according to claim 7, characterized in that, The file in question is a script file.
10. The method according to any one of the preceding claims, characterized in that, During the execution of the executable certificate data (12), the terminal device (2) performs at least the following steps: If the terminal device (2) is not in administrator mode, a user request is generated to switch the terminal device (2) to administrator mode. If user input is made on the terminal device (2) in response to the user request, thereby enabling the switch to administrator mode, the terminal device (2) is switched to administrator mode, and the digital certificate (13) is copied to the certificate storage of the terminal device (2). If the terminal device (2) is already in the administrator mode, the digital certificate (13) is copied to the certificate storage of the terminal device (2).
11. The method according to any one of the preceding claims, characterized in that, The method further includes: After the digital certificate (13) has been installed on the terminal device (2), the terminal device (2) sends a request to the field device (1) to establish a connection via the secure data transmission protocol; The field device (1) receives the request to establish a connection via the secure data transmission protocol; The field device (1) transmits authentication data to the terminal device (2); The terminal device (2) verifies the authentication data according to the digital certificate (13); and If the verification is successful, the terminal device (2) and the field device (1) communicate via the secure data transmission protocol.
12. The method according to any one of the preceding claims, characterized in that, The secure data transmission protocol is HTTPS.
13. The method according to any one of the preceding claims, characterized in that, The digital certificate (13) is an X.509 certificate.
14. A field device (1) having a sensor (3) for acquiring measured values, a network interface (5), and a data processing device (4), wherein, The data processing device (4) is configured to provide options for operating the field device (1) via the network interface (5) through a secure data transmission protocol, and wherein the data processing device (4) is further configured to: A request for transmitting a digital certificate (13) is received from the terminal device (2) via the network interface (5), wherein the digital certificate (13) is assigned to the field device (1) and is used to verify the identity of the field device (1) during communication with the field device (1) via the secure data transmission protocol; and In response to receiving the request for transmitting the digital certificate (13), an action is triggered to send executable certificate data (12) to the terminal device (2) through the network interface (5), wherein the executable certificate data (12) includes executable instructions (14) and the digital certificate (13).
15. A computer-implemented method for execution on a field device (1) having a network interface (5), comprising: The network interface (5) receives a request from the terminal device (2) for transmitting a digital certificate (13), wherein the digital certificate (13) is assigned to the field device (1) and is used to verify the identity of the field device (1) during communication with the field device (1) via a secure data transmission protocol. In response to receiving the request for transmitting the digital certificate (13), an action is triggered to send executable certificate data (12) to the terminal device (2) through the network interface (5), wherein the executable certificate data (12) includes executable instructions (14) and the digital certificate (13).