field device

Field devices employ dual-factor authentication to enhance cybersecurity, reducing cyber attack risks and ensuring secure data communication in industrial control systems.

DE102024200341A1Pending Publication Date: 2025-07-17VEGA GRIESHABER GMBH & CO

Patent Information

Application Number
DE102024200341
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-15
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Modern industrial control systems face increased susceptibility to cyber attacks due to the need for higher data rates and greater networking, which can lead to production failures and economic damage, necessitating secure communication channels with enhanced cybersecurity.

Method used

Field devices are equipped with a sensor arrangement and communication arrangement that authenticate data communication using at least two different security factors, ensuring only authorized access devices can communicate securely.

Benefits of technology

The dual-factor authentication significantly reduces the risk of cyber attacks, ensuring the integrity, availability, and confidentiality of production processes by allowing secure data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The disclosure relates to a field device (10) for detecting a process measurement variable, which is designed in particular as a level measuring device for detecting a level of a medium, wherein the field device (10) comprises: - a sensor arrangement (11) which is arranged to detect a measurement signal correlating with the process measurement variable, and - a communication arrangement (12) which is set up for data communication (1) with an access device (20), wherein the field device (10) is set up to receive authentication data (2) based on at least two security factors, and wherein the field device (10) is set up to authenticate the data communication (1) between the field device (10) and the access device (20) for evaluating at least a part of the authentication data (2) which is based on at least one of the at least two security factors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical FieldThe present disclosure relates to a field device for detecting a process measured variable, an access device for data communication with a field device, an authentication device, a system with a field device and an access device and / or authentication device, a method for authenticating data communication between a field device and an access device, and a computer program product.BackgroundIn industrial metrology, in particular in the field of process automation and process control, field devices are regularly used for detecting one or more process variables or, in other words, process measured variables. Field devices include, for example, flow, flow rate, pressure, differential pressure, temperature and fill level measurement devices. By means of a corresponding measurement system, the field devices generally record a measurement signal which correlates with one or more process measurement variables. A measured value for the respective process measured variable can then be determined via a computing arrangement of the respective field device on the basis of the measurement signal and / or on the basis of an evaluation of the measurement signal.Such field devices are often part of a larger industrial control system. However, controlling and monitoring processes in such a control system requires an ever greater number of information about the process for an increasing degree of automation. This makes it necessary to measure and process more process parameters. This results in a significantly higher amount of data which must pass from field devices to the control systems. This in turn creates the need for more and more recent communication channels.Current communication systems for constructing industrial fieldbuses such as HART quickly meet limits with the increased amount of data, which is why new developments are based on wireless or Ethernet-based protocols. The goal of higher data rates and greater networking can thus be achieved.The inventors have recognized that, against the background of such increasingly highly networked systems, there may be a higher susceptibility to cyber attacks. Cyber attacks can lead to malfunctions in production processes, which can lead to failures, production losses and thus to enormous economic damage.A challenge of the development of modern field devices of the type mentioned at the beginning is thus that of increasingly supporting new communication channels as well and at the same time ensuring a high degree of safety of these channels. Cybersecurity in field devices of the process industry is decisive in order to ensure the integrity, availability and confidentiality of the production processes and of the products produced.SummaryIt is an object of the present disclosure to enable a secure use of field devices.This object is achieved by the subject matters of the independent claims. Further developments of the present disclosure are evident from the dependent claims and the following description of embodiments.A first aspect of the present disclosure relates to a field device for detecting a process measured variable, which field device can be designed in particular as a fill level measuring device for detecting a fill level of a medium, wherein the field device has:a sensor arrangement which is configured for detecting a measurement signal correlating with the process measurement variable, anda communication arrangement which is set up for data communication with an access device,wherein the field device is configured to receive authentication data based on at least two, in particular different, security factors, and wherein the field device is configured to authenticate the data communication between the field device and the access device to evaluate at least a part of the authentication data based on at least one of the at least two security factors.Advantageously, a field device is thus provided, the data communication of which to or with an access device is authenticated by means of two security factors. Because two security factors are necessary to authenticate the data communication, the security is increased that only authorized users or authorized access devices are given access. The increased security thereby ensures a strong reduction of the susceptibility of the field device to a cyber attack and the chances of success of a cyber attack.The field device can be, for example, a flow rate, flow rate, pressure, differential pressure, temperature, fill level and / or limit level measuring device. Depending on the embodiment, it can be used in different installations and / or environments. For example, a fill level and / or limit level measuring device can be used in a measuring container in order to monitor its fill level and / or to detect a limit level. According to the embodiment of the field device, various sensor arrangements or sensors of the sensor arrangement can be used, such as a flow sensor, flow rate sensor, pressure sensor, temperature sensor, and / or radar sensor, etc.In addition to the sensor arrangement and the communication arrangement, the field device can also have a computing arrangement which can comprise a computer, processor and / or microcontroller, for example. The computing arrangement can be configured to acquire or compute the process measurement variable from the acquired measurement signals. Additionally or alternatively, in particular the computing arrangement can be configured to authenticate the data communication between the field device and the access device for evaluating at least the part of the authentication data.The communication arrangement may comprise one or more communication units. The communication arrangement or the various communication units can be configured for a wireless and / or wired connection. Accordingly, a wireless and / or wired data communication can take place between the field device and the access device. The communication technology may be any. Examples of possible communication technologies are HART, Ethernet, Bluetooth, WiFi, 4G, LTE, Lora, NB loT, etc.The terms authentication data and security factor are to be interpreted broadly. The authentication data can be any type of information, data or signal that can be read and evaluated by the field device. The authentication data may be based on one or more security factors. This includes the possibility that the authentication data include data, information or signals with respect to the security factors. For example, no part of the authentication data based on one of the security factors includes the security factor or information related thereto, for example, a password, a code generated once, information about a fingerprint, or the like. A security factor is understood here in particular as a factor which can be evaluated for ensuring the security of the field device in order to authenticate the data communication. The security factor may take various forms and include or be based on various information or data such as password, code, fingerprint, etc. The safety factor may be based on an input and / or output, as will be explained in more detail below.Receiving the authentication data by the field device may be provided by various arrangements, with the communication arrangement being just one example. Alternatively or additionally, it is possible to receive the authentication data by means of an input on an input arrangement which can be part of the field device, in particular can be fastened thereto or can be an integral part thereof. Of course, the access device or an authentication device explained in more detail below can also have an input arrangement in order to carry out authentication. In this case, however, the field device will typically receive the authentication data on the basis of the input at the input arrangement of the access and / or authentication device by means of a data communication with the access and / or authentication device. In particular, it is possible for the field device to be configured to receive different parts of the authentication data, which can be based on different security factors, from different arrangements or devices. For example, a portion of the authentication data based on one of the security factors can be received by means of the input arrangement on the field device, while another portion of the authentication data based on another of the security factors can be received by means of the data communication from the access device or the authentication device.The evaluation of at least a part of the authentication data by the field device, in particular by its computing arrangement, comprises that both or not both security factors have to be authenticated by the field device. For example, it can be provided that a first security factor of a part of the authentication data has already been authenticated by the access device and / or the authentication device in order to generate the remaining part of the authentication data on the basis of a second security factor. This remaining part of the authentication data can then be evaluated by the field device in order to authenticate the data communication. The authentication data are nevertheless based on the two security factors, because the second security factor cannot have been generated without the first security factor, so that the increased security is achieved. It is not necessary, although possible, for the field device to also evaluate the other part of the authentication data with respect to the other security factor. It is namely possible instead or alternatively in particular that a registration with respect to a safety factor has already taken place once. Thus, for example, an access device and / or authentication device may have been initially coupled to the field device, in particular using a special key or password, for example in the case of an initial installation, and / or by the manufacturer of the field device, for example by remote access to the field device, so that the access device and / or authentication device (for the field device) is considered to be known or trusted. By securing the access device and / or authentication device with a first security factor for access thereto, for example by a password, one of the two security factors can thus be evaluated and fulfilled. For example, it is possible that the second security factor comprises a code which is generated by the field device or another device or server, is sent to the trusted device or is received by the latter, and then sends a message or a code back to the field device or generates it for the input at the field device, which is evaluated by the field device for authentication. Moreover, it is not necessary, although possible, for the authentication data evaluated by the access device to contain data with respect to both security factors.Alternatively, it is possible and can be provided that the field device is set up for evaluating the authentication data. The field device can evaluate both safety factors. This can be the case, for example, if the field device receives the authentication data with respect to both security factors by means of an input arrangement or receives parts of the authentication data based on one of the security factors in each case from different arrangements and / or devices, for example from the input arrangement and the access device, the input arrangement and the authentication device, or the access device and the authentication device.The authentication data can be evaluated by comparing information or data contained therein, in particular with respect to one or both security factors or one or both security factors, with expected information or data. In a particularly simple case, one of the two security factors can be, for example, a password query. In this case, a password input by means of the input arrangement of the field device or received by means of the data communication or the communication arrangement can be matched with an expected or predetermined password, which can be stored in a data memory of the field device. If the received password matches the expected password, a security factor may be confirmed, fulfilled, or, in other words, authenticated. If a further security factor is now also confirmed or authenticated whether it is authenticated by the field device itself or on another device as described above, the data communication can be authenticated.The two safety factors may be different types of safety factors or same types of safety factors. For example, both security factors can be a type password and / or type fingerprint. It is possible for security factors of different types or the same types to be distributed on different devices, for example on field device, access device and / or authentication device. This comprises an input, output and / or an evaluation of the safety factor on the various devices.The field device can be configured to allow read access and / or write access of the access device to the field device in the case of authenticated data communication. Data communication between the access device and the field device can also be provided and permitted here already before the authentication of the data communication. This can allow, for example, the field device to receive the authentication data from the access device. However, functions or access options on the part of the access device to the field device can be blocked if the data communication or, in other words, the data connection is not authenticated. Thus, by means of the authenticated data communication between the field device and the access device, partial or complete read and / or write access to the field device can be granted. Here, the reading and writing relates in particular to data which are stored on the field device, for example with respect to a parameterization of the sensor arrangement which can be read and written, in particular also overwritten.The field device can be configured to allow one of at least two different access permissions of the access device to the field device depending on the at least one part of the evaluated authentication data. The different access permissions may relate, for example, to different data and / or the reading and / or writing. Thus, for example, an access authorisation can only allow reading and / or writing for a part of data on the field device, for example for parameterizing the sensor arrangement, and another, in particular more comprehensive, access authorisation can allow reading and writing for more or all data on the field device, so that more comprehensive programming of the sensor arrangement or of the field device is possible. Thus, depending on the authentication data, access authorisation can be communicated and evaluated at the same time in a simple manner. This is suitable, for example, for assigning different access permissions to different users, such as a user of the field device, and a service technician.The field device can be configured to allow parameterization of the sensor arrangement by the access device in the case of authenticated data communication. Thus, the field device can be used for a specific application and / or environment. In particular, different field devices can be used for different applications and / or exposed to different environments. In order to determine precise process measured variables, the field device, in particular its sensor arrangement with one or more sensors, can be configured to be parameterizable for the different applications and / or environments. By means of parameterization, it is possible to allow a high measurement precision. The parameterization can be understood in particular as a characterization of the field device by parameters which influence the detection of the process measured variable. The parameterization can in this case comprise at least parameters of the field device itself, that is to say in particular settings of the field device, for example a measurement sensitivity. Alternatively or additionally, the parameterization can also comprise external parameters, such as measurement conditions, for example density of a medium to be measured, volume of a measurement container in which the medium is contained, etc., as well as or alternatively ambient parameters, such as ambient temperature, ambient pressure, etc.It is possible that the communication arrangement is configured to receive at least a part of the authentication data, which is based on at least one of the at least two security factors, from the access device and / or an authentication device. Accordingly, at least a portion of the authentication data is provided by a further device which, as explained above, can be classified as trusted, in particular by earlier coupling to the field device, so that the security is further increased. Alternatively or additionally, it is possible to receive all or part of the authentication data by an input arrangement in the form of an input on the field device.It is possible that the field device is set up at least one output arrangement for outputting at least one signal for generating at least part of the authentication data which are based on at least one of the at least two security factors. The output arrangement can comprise one, two or more output units. The signal can again be recognized and / or read out by another device, in particular the access device and / or the authentication device, in order to generate at least the part of the authentication data, in particular with respect to one of the at least two security factors. The authentication data generated in this way can be transmitted to the field device for authentication. The combination of the output signal by the field device and generated authentication data by another device provides increased security that an authorized access device receives access to the field device.The output arrangement can have at least one of a display, a radio signal transmitter and a light generator. Any combination of individual or several of the aforementioned output units is also possible.In this case, the signal can be embodied as at least one of a machine-readable code, a radio signal and a light code. Accordingly, for example, a display can output a machine-readable code, for example in the form of a barcode or QR code. This can be scanned and read by the separate device in order to generate the authentication data. Alternatively or additionally, a radio signal can be generated and transmitted by a radio signal transmitter. This radio signal can be received, for example, by the access device and / or the authentication device, which thereupon generates and emits a counter-radio signal. This can be received by the radio signal transmitter or a radio signal receiver of the field device, whereupon the authentication data can be generated. Finally, it is possible that a light code is generated. The light code can be generated, for example, by illuminating one or more light sources, for example an LED or a display. The light can be encoded by different and / or alternating luminous colors, i.e. form the light code. Alternatively, or additionally, the light code can be formed by a frequency of switching the light on and off and / or an intensity of the light. The light code can be read out, for example, by the access device and / or authentication device, for example, by means of a camera, whereupon the authentication data are generated.Furthermore, it is possible that the field device is equipped with an input arrangement for inputting at least a part of the authentication data, which is based on at least one of the at least two security factors. In this respect, at least a part of the authentication data or the complete authentication data can be received directly via such an input arrangement instead of via the communication arrangement.For example, it is possible that the input arrangement comprises at least one of a display, a keyboard, a fingerprint sensor, a camera, a radio signal receiver and a microphone.For example, it is possible that the input is formed as at least one of a password, a fingerprint, an image or video of at least a part of a user, a radio signal and a voice. The password can be entered, for example, via the display, in particular a touch display, and / or a keyboard. The fingerprint can be input, for example, via the fingerprint sensor. The image or video of at least a part of the user can comprise, for example, the face of the user, the eyes, in particular iris, of the user, a gait cycle of the user or the like, such that in each case a specific or unique optical characteristic of the user is used, which is usable for authentication. The image or video can be recorded via the camera. The radio signal receiver can receive the above-explained counter radio signal. And finally, the microphone may record a voice of the user, for example, when speaking a password or an instruction.A second aspect of the present disclosure relates to an access device for data communication with a field device according to the first aspect of the present disclosure, wherein the access device is configured to generate and transmit at least a part of the authentication data, which are based on at least one of the at least two security factors, to the field device.A third aspect of the present disclosure relates to an authentication device configured to generate at least a part of the authentication data that can be evaluated by the field device according to the first aspect of the present disclosure, wherein the part of the authentication data is based on at least one of the at least two security factors.A fourth aspect of the present disclosure relates to a system including a field device according to the first aspect of the present disclosure and at least one of the access device according to the second aspect of the present disclosure and the authentication device according to the third aspect of the present disclosure.A fifth aspect of the present disclosure relates to a method for authenticating a data communication between a field device for detecting a process measured variable, which can be designed in particular as a fill level measuring device for detecting a fill level of a medium, and an access device, the method comprising:receiving authentication data based on at least two security factors, andevaluating at least a portion of the authentication data, which is based on at least one of the at least two security factors, for authenticating the data communication.The method can be executable, for example, on or by the field device according to the first aspect and / or can be executable on or by further devices, such as the access device and / or authentication device, in particular the system. Furthermore, the method may comprise further steps as explained herein with reference to the various devices.A sixth aspect of the present disclosure relates to a computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method according to the fifth aspect of the present disclosure.The computer program product can be a computer program as such or a product on which the computer program is stored. Such a product can be, for example, a storage medium which is readable in particular by a computer or processor of the computer. A computer can also be a microprocessor or comprise a microprocessor, for example. A computer can be present, for example, in the form of electronics of the field device or in the form of a control unit of the field device.The features of the individual aspects of this disclosure explained herein can be combined with one another as desired and independently of the respective aspects involved.In the following, further embodiments of the present disclosure are described with reference to the figures. If the same reference numerals are used in the following description of the figures, these denote the same or similar elements. The representations in the figures are schematic and not to scale.Brief Description of the FiguresFIGS. 1 ato 1 e show schematic views of systems with a field device with different authentication processes. FIGS. 2 ato 2 c show schematic views of different input and / or output orders of the field devices from FIGS. 1 ato 1 e. FIGS. 3a-3c show schematic views of different scenarios of a portion of an example authentication process. FIG. 4 schematically shows a method for authenticating a data communication.Detailed Description of EmbodimentsFIG. 1 ashows a schematic view of a system 100 with a field device 10 according to an exemplary embodiment. The field device 10 of this embodiment can be embodied, for example, as a fill level measuring device, for example, as a liquid limit switch. Alternatively, however, the field device 10 can also assume another embodiment, for example the form of a pressure measuring device or other field device 10.The field device 10 has a sensor arrangement 11 which can have at least one sensor (not shown), for example a vibration fork in the example of the fill level measuring device. As a result, the sensor arrangement 11 can acquire measurement signals correlating with a process measurement variable, here for example an oscillation frequency as a measurement signal, wherein the process measurement variable can be a fill level, here for example a limit fill level, which is determined by the position of the sensor. In a measuring container, for example, the oscillation frequency decreases when the liquid inside the measuring container gains fill level and reaches the sensor. The sensor arrangement 11 of the field device 10 can determine the frequency difference and thus record the limit fill level as a process measured variable. A pump can then be switched off, for example, in order to no longer fill the measuring container.Furthermore, the field device 10 comprises a communication arrangement 12 which can comprise, for example, one or more communication interfaces or channels, for example in the form of at least one antenna for wireless data communication 1 with another device, in the present case, for example, an access device 20 of the system 100.Furthermore, as is shown by way of example in FIG. 1 a, the field device 10 can comprise an output arrangement 13, an input arrangement 14, a computing arrangement 15 and / or a computer program product 16. The computing arrangement 15 can comprise a computer or processor, for example. By means of the computing arrangement 15, measurement values of the process measurement variable can be ascertained on the basis of the measurement signals, that is to say, for example, the liquid limit level is reached, and these measurement values can also be evaluated, for example, for shutting down the pump.The access device 20 may in turn also comprise a communication arrangement 21, a computing arrangement 22 and a computer program product 23, which may in principle have the same structure as described herein with reference to the field device 10.The field device 10 can now, as shown in the example of FIG. 1 a, set up a data communication 1 with the access device 20, for example a smartphone or another computer arrangement with a screen, input means and the like. The purpose of this may be, for example, to allow the access device 20 to read access and / or write access the field device 10, in order to allow, for example, parameterization of the sensor arrangement 11 by the access device 20.It can now be provided that the data communication 1 is authenticated by the field device 10. In other words, the field device 10 is intended to ensure that the access device 20 or its user has the necessary authorisation for the read access, write access and / or the parameterization. This can be done by the field device 10 receiving and evaluating authentication data 2. If the evaluation reveals that the access device 20 or its user is authorized, the data communication 1 is authenticated. Otherwise, the data communication 1 is not authenticated and the access device 20 or its user is not given access.In the example of FIG. 1 a, the authentication data 2 is received by the field device 10 by a transmission of the authentication data 2 via the data communication 1 between the field device 10 and the access device 20. At least a portion of the authentication data 2, which is based on one of the two security factors, is evaluated by the field device 10 in order to authenticate the data communication 1.In the example of FIG. 1 a, it can be provided, for example, that the access device 20 or an application thereon, which is set up for the read access, write access and / or the parameterization of the field device 10, is protected with a password or via another security check, for example a fingerprint or a face scan or other scan of an optical characteristic of a user of the access device 20. This can form one of the two safety factors. A second security factor can be, for example, a PLN, TAN, password or the like generated for a single access to the access device 20, which is generated, for example, by a remote server, for example of the manufacturer, and is sent to the access device 20, in particular a separate application. In this case, the access device 20 can have been initially coupled, in particular using a particular key or password, for example in the case of an initial installation, or by the manufacturer of the field device 10, for example by remote access to the field device 10, such that the access device 20 is considered to be known or trusted. Accordingly, the access device 20 can receive the PIN, TAN or password generated for the one-time access and then transmit authentication data 2 to the field device 10, which is based on both the password for access to the application and the PIN, TAN or password generated once, i.e. is based on two security factors. For example, the authentication data 2 can contain the PIN, TAN or the password. In this case, for example, the PIN, TAN or the password can also have been received by the remote server from the field device 10. The evaluation by the field device 10 can accordingly be carried out, for example, by matching the two PINs, TANs or password, that is to say, on the one hand, that received from the server and, on the other hand, that received from the access device 20. If both coincide with one another, the data communication 1 can be authenticated accordingly by the field device 10, so that, for example, parameterization of the sensor arrangement 11 by means of the access device 20 is permitted. Such an authentication method can be executed when the computer program product 16 is executed by the computing arrangement 15.FIG. 1 bshows a system 100 which uses an authentication device 30 in addition to the field device 10 and access device 20. Here, a part of the authentication data 2 or all of the authentication data 2 is provided by the authentication device 30 and transmitted from the access device 20 to the field device 10, for example. In this example, the authentication device 30 itself does not communicate directly with the field device 10, but only indirectly via the access device 20.The authentication device 30 can in turn also comprise a communication arrangement 31, a computing arrangement 32 and a computer program product 33, which can in principle have the same structure as described herein with reference to the field device 10 or the access device 20.Alternatively, FIG. 1 cshows a system 100 which likewise uses an authentication device 30, but in which the access device 20 and the authentication device 30 each transmit separate parts of the authentication data 2, in each case based on one of the two security factors, to the field device 10. Only when the field device 10 receives both parts of the authentication data 2 and evaluates them for authenticating the data communication 1 does the access device 20 gain access to the field device 10.A further alternative is shown in FIG. 1 d, in which the complete authentication data 2 is received directly from the authentication device 30 at the field device 10 or a part of the authentication data 2 based on one of the two security factors is received from the authentication device 30 at the field device 10, while another part of the authentication data 2 can be received directly at the field device 10, namely by means of the input arrangement 14.An example of an embodiment of the field device 10 for the variant of FIG. 1 dis shown, for example, in FIG. 2 b. The input arrangement 14 is realized here as a password input by way of example. A security factor can thus be checked by checking a specified password as input 4 of the user on the field device 10. Accordingly, a first part of the authentication data 2 relating to the password is received as a security factor at the field device 10 and evaluated by matching with the known password, for example, as indicated in the form of a 4-digit PIN. A further part of the authentication data 2 is provided in FIG. 2 b by the authentication device 30. In this case, the field device 10 here has, by way of example, an output arrangement 13 in the form of a light generator which outputs a light code as a signal 3. This signal 3 can be read out by the authentication device 30, which can be designed as a special reading device for the signal 3. The authentication device 30 can thereby generate at least a part of the authentication data 2. This can in turn transmit it directly, as shown in FIG. 1 d, or indirectly, as shown in FIG. 1 b, via the access device 20 to the field device 10, where the authentication data 2 are evaluated based on the security factor with respect to the signal 3. If, for example, the part of the authentication data 2 with respect to the signal 3 corresponds to an authentication data 2 expected by the field device 10 on the basis of the output signal 3, for example a code, and the password of the input 4 also corresponds to the expected password, then the data communication 1 can be authenticated.FIG. 2 ashows an alternative with a machine-readable code as signal 3 of the output arrangement 13 in the form of a display, for example. Here too, the authentication device 30 can be provided to read in the signal 3 and to generate at least the part of the authentication data 2. Alternatively or additionally, the access device 20 can also be configured to generate the part of the authentication data 2 on the basis of the signal 3.Alternatively, it is possible, for example, for the authentication data 2 to be evaluated on the field device 10 with respect to both security factors, i.e. completely. This is shown, for example, in FIG. 1 e, in which the field device 10 receives the authentication data 2 and authenticates the data communication 1 between the field device 10 and the access device 20 without the access device 20 itself participating in the authentication except for the data communication 1 with the field device 10 and associated confirmations, for example the interrogation as to whether the data communication 1 is to be authenticated with the access device 20. This is possible, for example, in the input arrangement 14 of the field device 10 of FIG. 2 c. The input arrangement 14 is realized here as a fingerprint sensor by way of example. A security factor can thus be checked by checking the fingerprint as input 4 of the user on the field device 10. Accordingly, a first part of the authentication data 2 relating to the fingerprint is received as a security factor at the field device 10 and evaluated by matching with a known or previously stored fingerprint. A further part of the authentication data 2 is schematically indicated in FIG. 2 c with respect to a password input as input 4, for example here with 4 points for a 4-digit PIN input. Accordingly, the second part of the authentication data 2 with respect to the PIN or password is also received as a security factor at the field device 10 and evaluated by matching with the stored PIN or password. If both safety factors are fulfilled, the data communication 1 is authenticated.Finally, FIGS. 3 ato 3 c show a further variant of an authentication of the data communication 1 of the field device 10 with the access device 20, in which an authentication device 30 according to one of FIGS. 1 b, 1 cand 1 dis used. In this case, in these examples, the field device 10 comprises an output arrangement 13 in the form of a radio signal transmitter for generating a radio signal as a signal 3, in particular within a specific range, which is indicated here by way of example by a circle around the field device 10. The field device 10 further comprises an input arrangement 14 in the form of a radio signal receiver for receiving a radio signal as input 4. the authentication device 30 is now designed, for example, as or with a radio beacon which can output the radio signal as input 4 when it receives the signal 3. The radio signal as input 4 can form part of the authentication data 2 with respect to a security factor, which can be received by the field device 10 from the authentication device 30 accordingly.For example, FIG. 3 a shows a user 5 within the range of the signal 3 but without the authentication device 30 here. accordingly, no authentication data 2 based on the security factor of the input 4 are received by the field device 10 in the form of the radio signal. The user 5 can accordingly not authenticate himself or not completely authenticate himself to the field device 10, lack the authentication device 30; in FIG. 3 b, the user 5 is within the range of the signal 3 and equipped with the authentication device 30, which correspondingly generates the radio signal as input 4 and transmits it as part of the authentication data 2 to the field device 10. In FIG. 3 c, although the user 5 is equipped with the authentication device 30, it is located outside the range of the signal 3, so that no authentication data 2 with respect to the input 4 are generated. If the user 5 has moved away from FIG. 3 bin FIG. 3 c, the data communication 1 can no longer be authenticated.FIG. 4 shows purely schematically a method 200 for authenticating the data communication 1 between the field device 10 and the access device 20.The method 200 comprises, in step 201, receiving the authentication data 2 based on two security factors. As explained, parts of the authentication data 2, wherein each part can be based on one of the two security factors, can be received from different devices and / or arrangements.In step 202 of method 200, at least a part of authentication data 2, which is based on at least one of the two security factors, is evaluated for authenticating data communication 1. If the evaluation is successful, for example the authentication data 2 or the part thereof agree with the expected information or data, the data communication 1 can be authenticated.Finally, with authenticated data communication 1, in step 203 of the method 200, the read and / or write access of the access device 20 to the field device 10 can be permitted.The terms used in the claims should be construed to obtain the broadest reasonable interpretation consistent with the above description. For example, the use of the article "a" or "the" in the insertion of an element should not be construed to exclude a plurality of elements. Likewise, the phrase "or" should be construed to include a plurality of elements, such that the phrase "A or B" does not exclude "A and B", unless it is clearly understood from the context or the foregoing description that only one of A and B is meant. Further, the phrase "at least one of A, B, and C" is to be understood as one or more elements from a group of elements consisting of A, B, and C, and is not to be construed as requiring at least one of each of the listed elements A, B, and C, whether A, B, and C are joined together as categories or otherwise. Moreover, the phrase "A, B, and / or C", or "at least one of A, B, or C" should be construed to include any individual entity of the listed items, e.g., A, any subset of the listed items, e.g., A and B, or the entire list of items A, B, and C.

Claims

Field device (10) for detecting a process measurement variable, which is designed in particular as a fill level measuring device for detecting a fill level of a medium, wherein the field device (10) has: - a sensor arrangement (11), which is designed to detect a measurement signal correlated with the process measurement variable, and - a communication arrangement (12), which is designed to communicate data (1) with an access device (20), wherein the field device (10) is designed to receive authentication data (2) based on at least two security factors, and wherein the field device (10) is designed to authenticate the data communication (1) between the field device (10) and the access device (20) to evaluate at least a part of the authentication data (2) which is based on at least one of the at least two security factors.The field device (10) according to claim 1, wherein the field device (10) is configured to allow a read access and / or write access of the access device (20) to the field device (10) in the case of authenticated data communication (1).The field device (10) according to claim 1 or 2, wherein the field device (10) is configured to allow one of at least two different access permissions of the access device (20) to the field device (10) depending on the at least one part of the evaluated authentication data (2).Field device (10) according to one of the preceding claims, wherein the field device (10) is configured to allow parameterization of the sensor arrangement (11) by the access device (20) in the case of authenticated data communication (1).Field device (10) according to one of the preceding claims, wherein the communication arrangement (12) is configured to receive at least part of the authentication data (2) based on at least one of the at least two security factors from the access device (20) and / or an authentication device (30).Field device (10) according to one of the preceding claims, wherein the field device (10) is set up at least one output arrangement (13) for outputting at least one signal (3) for generating at least part of the authentication data (2) which are based on at least one of the at least two security factors.The field device (10) of claim 6, wherein the output arrangement (13) comprises at least one of a display, a radio signal transmitter and a light generator.Field device (10) according to claim 6 or 7, wherein the signal (3) is formed as at least one of a machine-readable code, a radio signal and a light code.Field device (10) according to one of the preceding claims, wherein the field device (10) is set up an input arrangement (14) for inputting (4) at least a part of the authentication data (2) which are based on at least one of the at least two security factors.The field device (10) of claim 9, wherein the input arrangement (14) comprises at least one of a display, a keyboard, a fingerprint sensor, a camera, a radio signal receiver, and a microphone.The field device (10) according to claim 10, wherein the input (4) is configured as at least one of a password, a fingerprint, an image or video of at least a part of a user, a radio signal and a voice.Access device (20) for data communication (1) with a field device (10) according to one of the preceding claims, wherein the access device (20) is configured to generate and transmit at least part of the authentication data (2) which are based on at least one of the at least two security factors to the field device (10).Authentication device (30), configured to generate at least a part of the authentication data (2) that can be evaluated by the field device (10) according to one of claims 1 to 11, wherein the part of the authentication data (2) is based on at least one of the at least two security factors.A system (100) comprising a field device (10) according to any preceding claim and at least one of the access device (20) according to claim 12 and the authentication device (30) according to claim 13.Method (200) for authenticating a data communication (1) between a field device (10) for detecting a process measured variable, which is designed in particular as a fill level measurement device for detecting a fill level of a medium, and an access device (20), wherein the method comprises: - receiving authentication data (2) based on at least two security factors, and - evaluating at least part of the authentication data (2) based on at least one of the at least two security factors for authenticating the data communication (1).A computer program product (16) comprising instructions which, when the program is executed by a computer (15), cause the computer to carry out the method (200) of claim 15.

Citation Information

Patent Citations

  • two-factor authentication for user interface devices in a process plant

    DE102017116161A1

  • Level measuring device with combined device display unit for displaying status information and outputting a verification code

    DE102018209374A1

Cited By

  • Field device

    WO2025153519A1