Method for detecting unauthorized data manipulation on a field device in an industrial automation system

DE102024201458A1Inactive Publication Date: 2025-08-21SIEMENS AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102024201458
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-16
Publication Date
2025-08-21
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method (100) for detecting unauthorized data manipulation (15) on a field device (10) in an industrial automation system (60). In a first step (110), a data set (12) is transmitted between the control unit (30) and the field device (10) via a wired connection (20), and the transmitted data set (12) is stored as a transmission duplicate (13). In a second step (120), the data set (12) sent to the field device (10) or the control unit (30) is duplicated as a reception duplicate (18). The reception duplicate (18) is sent to a comparison unit (50) via a radio connection (25). The method (100) also comprises a third step (130) in which a comparison (56) of the dispatch duplicate (18) with the reception duplicate (13) of the data record (12) is carried out and an unauthorized data manipulation (15) is detected if the dispatch duplicate (13) and the reception duplicate (18) differ from one another.In a fourth step (140), a warning (55) is output to a user and / or a data interface (54). Furthermore, the invention relates to a correspondingly suitable computer program product (35). Likewise, the invention relates to a security module (40) suitable for the method (100) and a suitable comparison unit (50). Furthermore, the invention relates to a correspondingly equipped industrial automation system (60).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for detecting unauthorized data manipulation on a field device and a corresponding computer program product. Furthermore, the invention relates to a comparison unit and a security module with which such a method can be implemented. The invention also relates to an industrial automation system equipped accordingly.

[0002] Patent application US 2023 / 0179610 A1 discloses a cybersecurity monitoring device that is designed to covertly receive the physical layer of a field device's communication at the bit level. Unique device-related attributes are stored in a memory that serve as fingerprints of the participating field devices. If a unique device-related attribute changes at the physical layer, an attempted attack is detected.

[0003] US Pat. No. 8,184,562 B2 discloses a distributed control system with a plurality of field devices. One of the field devices is connected to a control unit via a wired connection and a redundant wireless connection.

[0004] Industrial automation systems are increasingly interconnected, both internally and externally. Furthermore, physical access to industrial automation systems is becoming increasingly easier to facilitate maintenance work. Accordingly, industrial automation systems are increasingly exposed to threats from unauthorized actors. At the same time, there is a need for robust fieldbus communication. This creates the challenge of providing a way to detect unauthorized data manipulation while simultaneously providing communication suitable for industrial automation systems. Furthermore, there is a need for a way to easily implement this capability on existing industrial automation systems.

[0005] The task is solved by a method described below for detecting unauthorized data manipulation on a field device. The field device can be, for example, a sensor or an actuator. Unauthorized data manipulation is understood to mean a change to a transmitted data set containing, for example, measurement data, parameters, configuration information, and / or commands that is sent or received by the field device. The data set can include analog data, i.e., measurement data, parameters, configuration information, and / or commands encoded as analog signals. The unauthorized data manipulation is carried out by an unauthorized actor and / or an unauthorized device. The field device is used in an industrial automation system and is directly or indirectly connected to a control unit.The connection to the control unit is designed as a wired connection, or wire connection for short. The method comprises a first step in which a data set is transmitted between the control unit and the field device via the wired connection. The data set can thus be sent from the field device to the control unit or vice versa. The sent data set is stored at least temporarily as a sent duplicate on the control unit or field device. In a second step, the data set sent to the field device or control unit is duplicated on the receiver side and stored at least temporarily as a received duplicate. In the second step, the received duplicate is then sent to a comparison unit. The received duplicate can be sent from the field device to the comparison unit via a radio connection. Alternatively, the received duplicate can be sent to the comparison unit via a return channel connection.The radio connection is separate from the wired connection. A third step of the described method follows, in which the sent duplicate is compared with the received duplicate. For this purpose, the sent duplicate can be sent from the control unit to the comparison unit via the return channel connection. Alternatively, the sent duplicate can be sent to the comparison unit via a radio connection when the data set is transferred from the field device to the control unit. Furthermore, unauthorized data manipulation is detected if the sent duplicate and the received duplicate differ from one another. In a fourth step, a warning is issued to a user and / or a data interface if unauthorized data manipulation is detected.

[0006] The transmission duplicate provides the comparison unit with the desired content of the transmitted data set. The reception duplicate, in turn, represents the actual content of the transmitted data set, which is compared with the transmission duplicate, i.e., the desired content. This makes it possible to check whether unauthorized data manipulation has occurred on the wired connection. Because the wired connection and the wireless connection are separate and independent of each other, they are diverse from each other. This provides a simple, fast, and reliable way to detect unauthorized data manipulation. The described method can be easily retrofitted as part of a retrofit of the underlying industrial automation system. The described method can be retrofitted, in particular, by adding additional devices without interrupting operation in the industrial automation system.

[0007] In one embodiment of the described method, at least the second step is carried out by a safety module that is connected to the field device. In particular, the third and / or fourth step can also be carried out by the safety module. The safety module can be connected to the field device via the wire connection and thus arranged along the wire connection between the field device and the control unit. The safety module can be arranged physically adjacent to the field device, attached directly to the field device or in the field device, i.e. integrated into the field device itself. For this purpose, the safety module can be accommodated in the housing of the field device, for example. The at least physically adjacent arrangement of the field device makes it more difficult to tamper with a connection between the field device and the safety module.This reduces the potential for unauthorized data manipulation and increases the security of the described process. Alternatively, the security module can also be designed as a component of the field device and located within the field device. This further increases the security of the described process.

[0008] Furthermore, in the described method, the security module can be digitally merged with the field device. This means a mutual coupling of the field device and the security module, whereby they can only function as intended when individually paired. Digital merging can, for example, be achieved using strong encryption, the key of which is based on device-specific data, such as a MAC address, an IMEI number, or a serial number combined with a type designation. The digital merging can be essentially irreversible or at least only be difficult to remove. Digital merging can be carried out quickly and easily. Digital merging prevents successful unauthorized data manipulation based on the unnoticed replacement of the security module with a compromised security module.In the fused state, the field device and the security module can be configured to communicate with each other in an encrypted manner. This also further increases the level of security achievable with the described method.

[0009] Furthermore, in the described method, the wired connection can be unencrypted and the wireless connection encrypted. Unencrypted wired connections offer increased robustness and speed, allowing highly available operation of the industrial automation system. Furthermore, unencrypted wired connections can be easily intercepted and diagnosed during maintenance work. Different types of encryption for wireless connections are readily available. Furthermore, many wireless connections include an encryption option. Encryption for wireless connections is also being further developed in other technical fields, such as mobile communications, Bluetooth, or WLAN technology. This makes the described method transferable to a wide range of existing and future types of wireless connections. Encrypted wireless connections offer increased protection against tampering.In particular, by combining an unencrypted wired connection with an encrypted wireless connection, the described method achieves reliable detection of unauthorized data manipulation. At the same time, the robustness and speed of the unencrypted wired connection remain unaffected. Since the wired connection and the wireless connection are designed separately, they can use different communication standards. In particular, the type of encryption for the wireless connection can be selected independently of the type of wired connection. The wireless connection can be of a different type than other wireless connections already present in the automation system. This allows for greater utilization of the frequency spectrum available in the industrial automation system.

[0010] The wired connection can be implemented, for example, as a HART connection, an IO-Link connection, a ModBus connection, an ASi connection, a Foundation Fieldbus connection, a CAN bus connection, a 4..20 mA connection, a ProfiBus connection, and / or a combination thereof. Such wired connections offer increased communication speed and signal robustness. The described method is therefore applicable to a wide range of existing industrial automation systems.

[0011] Furthermore, the radio connection can be implemented as a Bluetooth connection, a WiFi connection, a LoRa connection, a LoRaWAN connection, a Zigbee connection, an NbloT connection, a CAT-M1 connection, a point-to-point radio connection, a GSM connection, in particular a 3G, 4G, 5G, or 6G connection, and / or a combination thereof. Such radio connections have sufficient range and bandwidth to reliably connect the field device in the industrial automation system. The greater the range and bandwidth of the radio connection, the more field devices can be connected to a single comparison unit. Accordingly, the fewer comparison units are required for the described method, which allows the described method to be implemented cost-effectively.

[0012] The described method can further comprise a fifth step in which an artificial intelligence is trained based on a data exchange between the field device and the control unit. The data exchange involves the multiple sending and receiving of different data sets by the field device or the control unit. The data exchange takes place during normal operation of the industrial automation system, ensuring that no unauthorized data manipulation occurs. The artificial intelligence is thus suitable for precisely detecting normal operation of the industrial automation system. In a sixth step, at least one data set is recorded and evaluated, which is then transmitted between the control unit and the field device. The data set can be sent from the control unit to the field device or vice versa.The artificial intelligence evaluates the recorded data set and checks whether an anomaly exists. An anomaly is defined as a state that deviates from the intended operation trained by the artificial intelligence to such an extent that the state cannot be interpolated as an intermediate state within the intended operation. An anomaly can also exist if the recorded state cannot be extrapolated from the intended operation. Alternatively, in the fifth step, a training data set created on at least one third-party industrial automation system can be supplied, and the artificial intelligence can be trained based on this. Based on this, anomalies can be detected in a similar way.A third-party industrial automation system is defined as any other industrial automation system in which communication is sufficiently similar in terms of scope and frequency. Such anomalies represent at least an indication of unauthorized data manipulation. If an anomaly in the acquired data set, and thus unauthorized data manipulation, is detected, a warning can be issued to the user and / or the data interface. The described method can therefore be additionally supported by artificial intelligence. Monitoring data exchange on the wired connection using artificial intelligence is diverse from the mechanisms outlined above in the described method. This further increases the achievable security.

[0013] In the described method, the security module can be provided with at least one sensor designed to detect unauthorized physical manipulation of the security module and / or the field device. Such a sensor can be designed, for example, as an acceleration sensor, by which a forced opening of the security module or the field device can be detected. Alternatively or additionally, the sensor can be designed as a switch, which can be indicated by an opening of the field device and / or the security module. Further alternatively or additionally, the sensor can be designed as a geoposition sensor, by which it can be detected whether the security module and / or the field device is located in a designated geographical position. Such a sensor can be designed as a GPS receiver and / or as a mobile radio receiver suitable for evaluating identifiers of transmission towers.This makes it detectable when the security module is removed from its intended installation location. The described procedure also provides protection against unauthorized physical manipulation, which could be used to prepare for unauthorized data manipulation.

[0014] Furthermore, the radio connection can be established intermittently in the described method. The radio connection can, for example, be established and then terminated according to a schedule. The schedule can have a fixed pattern or a random pattern. The radio connection is therefore not permanently in operation. Furthermore, the safety module can be provided with a memory in which data for comparisons between sent duplicates and received duplicates or for detected deviations between them is stored at least temporarily. Likewise, data for changes in the operating mode of the field device can also be stored at least temporarily in the memory. In numerous industrial automation systems, many field devices send a constant signal over long periods of time, for example a constant process variable or a negative acknowledgment regarding the presence of operationally relevant messages, such as warnings.The longer the radio connection is active with an unchanged signal, the more vulnerable it is to unauthorized reception and evaluation, leading to unauthorized decryption. Interrupted establishment and termination of the radio connection further increases the security of the described method. Furthermore, the radio connection can also be established in an event-driven manner, for example, when unauthorized data manipulation is detected. Furthermore, the control unit used to establish the radio connection can be operated for an extended period using a battery. In addition to conserving battery power, data traffic over the radio connection can also be reduced, allowing for cost-effective operation.

[0015] Furthermore, in the described method, at least one field device in the industrial automation system can be locked or deactivated if unauthorized data manipulation is detected. The field device in which the unauthorized data manipulation is detected and / or another field device belonging to the industrial automation system can be locked or deactivated. The corresponding field device can be placed in a state in which it refuses to accept commands, in particular parameterization and configuration commands, and / or automatically resets its parameterization or configuration to a setting last classified as uncompromised. The field device can be reset to the setting last classified as uncompromised, for example, by the security module.Such a setting classified as uncompromised can be a setting specified for the described process when the industrial automation system is set up. The described process is therefore designed to automatically react to detected unauthorized data manipulation and initiate targeted countermeasures. In particular, the reaction to detected unauthorized data manipulation can be specified type-dependently and its scope can be adjusted. For example, blocking or deactivation can be limited only to field devices identified as being affected by unauthorized data manipulation. This accelerates the resumption of normal operation after the source of danger has been eliminated. The described process offers a higher degree of cost-effectiveness due to its targeted nature.

[0016] The problem outlined above is also solved by the computer program product described below. The computer program product comprises machine-readable program code stored on a non-volatile memory and executable by a processor. The computer program product is designed to at least partially implement a method for detecting unauthorized data manipulation on a field device according to one of the embodiments outlined above. The computer program product can, in particular, be designed to perform at least the described steps. The computer program product can be monolithic, i.e., executable on a single hardware platform.Alternatively, the computer program product can be modular, i.e., comprise multiple subprograms that can be executed on different hardware platforms and that interact via a communicative data connection to provide the corresponding functionality. For example, the first step can be executed with a subprogram on the control unit, the second step with another subprogram on the security module, and the third and fourth steps with yet another subprogram on the comparison unit. The features and advantages of the described method also apply analogously to the described computer program product and can be transferred to it individually or in combination. The described method can be easily implemented using the corresponding computer program.

[0017] The above-described problem is also solved by a comparison unit described below. The comparison unit is designed to receive and process a sent duplicate and a received duplicate. The sent duplicate and the received duplicate can be sent to the comparison unit by a control unit connected to the comparison unit or a security module connected to the comparison unit. The received duplicate and the sent duplicate belong to a data set that is transmitted between the control unit and the field device. The described comparison unit is equipped with a computer program product according to at least one of the embodiments outlined above and is thus suitable for implementing the method described above.The features and advantages of the described computer program product and the described method also apply analogously to the described comparison unit and are transferable to it accordingly.

[0018] Likewise, the problem outlined above is solved by a safety module described below. The safety module can be connected to a wired connection that exists between a field device and a control unit in an industrial automation system. The safety module is configured to perform at least the second step in a method according to at least one of the embodiments described above. The features and advantages of the described method accordingly apply analogously to the described safety module and can be transferred to it individually or in combination. The safety module is suitable for being integrated into an existing industrial automation system as part of a retrofit, thus implementing the described method therein.

[0019] Furthermore, the problem outlined above is solved by an industrial automation system described below. The industrial automation system comprises at least one field device connected to a control unit and a security module via a wired connection. Furthermore, the industrial automation system comprises a comparison unit connected to the security module via a radio connection. The industrial automation system is designed to implement a method according to at least one of the embodiments described above. The features and advantages of the described method are thus analogously transferable to the described industrial automation system, individually or in combination. The described industrial automation system has an increased level of security against unauthorized data manipulation and can therefore be operated reliably and economically.The industrial automation system can, for example, be designed as a production line, a chemical plant, in particular a petrochemical plant, or a conveyor system.

[0020] The invention is explained in more detail below using individual embodiments in the figures. The figures are to be read as complementary to one another in that identical reference numerals in different figures have the same technical meaning. The features of the individual figures can also be combined with one another. Furthermore, the embodiments shown in the figures can be combined with the features outlined above. They show in detail: Fig. 1 schematically shows a first embodiment of the described method carried out on a described industrial automation system; Fig. 2 schematically shows a structure of another embodiment of the claimed industrial automation system.

[0021] In Fig. 1 schematically shows a first embodiment of the described method 100, which is carried out on a described industrial automation system 60. The industrial automation system 60 comprises at least one field device 10, which is designed as a sensor 11. The field device 10 is connected directly to a control unit 30 via a wired connection 20, which is designed to enable a bidirectional data exchange 16 between the field device 10 and the control unit 30. The wired connection 20 is unencrypted and offers an increased degree of robustness. The industrial automation system 60 also includes a security module 40, which is positioned adjacent to the field device 10. The security module 40 is coupled to the wired connection 20 and connected between the control unit 30 and the field device 10. The data exchange 16 between the field device 10 and the control unit 30 is looped through the security module 40.Furthermore, the security module 40 is connected to a comparison unit 50 via an antenna 42 via a radio link 25. The radio link 25 is established in sections via a main antenna 27 and a computer cloud 26, so that the transmission 17 in the second step 120 takes place in stages. The radio link 25 is encrypted so that manipulation of the received duplicate 18 can be ruled out. Likewise, the control unit 30 is connected to the comparison unit 50 via a return channel connection 24. The return channel connection 24 can be wired, wireless, or a combination thereof. Furthermore, the return channel connection 24 is secure against unauthorized data manipulation. The comparison unit 50, in turn, is designed as a computer.

[0022] In the described method 100, a first step 110 takes place in which a data set 12 is sent from the control unit 30 to the field device 10 via the wired connection 20. The data set 12 can, for example, comprise commands and / or parameters for the field device 10. In the embodiment according to Fig. 1, there is unauthorized data manipulation 15 at the wire connection 20, which alters the transmitted data set 12 and which can be detected by the method 100. Due to the unauthorized data manipulation 15, the data set 12 has at least one manipulated section 14. The data set 12 transmitted by the control unit 30 is duplicated by the control unit 30 in the first step 110. Duplication 19 generates a transmission duplicate 13, which is at least temporarily stored on the control unit 30. The transmission duplicate 13 is sent to the comparison unit 50 via the return channel connection 24 during the method 100.

[0023] In a second step 120 of the described method 100, the data set 12, which has been altered by the unauthorized data manipulation 15, is received by the field device 20 and the security module 40. The security module 40 is configured to duplicate 19 the received data set 12. In the second step 120, the data set 12 also received by the field device 10 is duplicated, thus generating a received duplicate 18. In the second step 120, the received duplicate 18 is sent to the comparison unit 50 via the radio connection 25. A third step 130 of the described method 100 is performed with the comparison unit 50. In this step, the sent duplicate 13 is compared with the received duplicate 18. The received duplicate 18 has the manipulated section 14, so that in the third step 130 a discrepancy is detected between the received duplicate 18 and the sent duplicate 13.If at least one such deviation is detected by the comparison 56 in the third step 130, this is classified as unauthorized data manipulation 15 on the field device 10. Because the sent duplicate 13 can reliably not be affected by unauthorized data manipulation, it represents a target content for the data set 12 sent in the first step 110, while the received duplicate 18 represents an actual content of the data set 12 sent in the first step 110. The sent duplicate 13 and the received duplicate 18 can be compared using a variety of algorithms, for example, using a checksum or bitwise.

[0024] In the fourth step 140 of the described method 100, a warning 55 is issued if the unauthorized data manipulation 15 is detected in the third step 130. The warning 55 is issued via a display device 52 to a user and / or via a data interface 54. The data interface 54 allows, for example, a connection to the control unit 30 via the return channel connection 24. In addition, in the described method 100, the control unit 30 sends a command by which the field device 10 is locked or deactivated. The deactivation 57 renders the field device 10 inoperative, so that the attack manifested in the unauthorized data manipulation 15 is ineffective. Alternatively, the locking 59 sets the field device 10 to the last setting known to be uncompromised. Alternatively or additionally, the transmission of measured values ​​from the field device 10 to the control unit 30 is prevented.

[0025] The described method 100 is implemented by means of a computer program product 35, which has a plurality of subprograms that run on the control unit 30, the security module 40, and the comparison unit 50. Through the interaction of the subprograms, the function of the described computer program product 35 is implemented and the described method 100 is implemented. The described method 100 is bidirectional, so that unauthorized data manipulation 15 can also be detected analogously in a data set 12 that is transmitted from the field device 10 to the control unit 30.

[0026] A further embodiment of the described industrial automation system 60 is shown in Fig. 2 schematically shown. The industrial automation system 60 is designed to implement a method 100 for detecting unauthorized data manipulation 15, such as in Fig. 1. The industrial automation system 60 comprises at least one field device 10, which is connected to a control unit 30 via a wired connection 20. The field device 10 is designed as a sensor 11. A security module 40 is connected between the field device 10 and the control unit 30. The security module 40 has an antenna 42 via which it can establish a radio connection 25. The wired connection 20 is unencrypted and the radio connection 25 is encrypted. A data exchange 16 takes place via the wired connection 20, during which a data set 12 is sent from the control unit 30 to the field device 10. The security module 40 is coupled to the wired connection 20 adjacent to the field device 10.The security module 40 is connected to the field device 10 on a receiver side 21, so that a section of the wired connection 20 located between the field device 10 and the security module 40 essentially offers no point of attack for unauthorized data manipulation 15. Complementary to the receiver side 21, the wired connection 20 has a transmitter side 23. The field device 10 and the security module 40 are digitally merged, so that they only function as intended in combination.

[0027] The safety module 40 is coupled to the wired connection 20 in such a way that the data exchange 16 between the field device 10 and the control unit 30 is looped through the safety module 40. The safety module 40 comprises an energy recovery unit 41, with which electrical energy can be extracted from the wired connection 20, with which the safety module 40 can be at least partially operated. Partial operation here is understood to mean the provision of at least individual functions of the safety module 40.

[0028] The energy extraction unit 41 is coupled to an energy storage device 48, by means of which the security module 40 can also be operated at least partially independently of the wired connection 20. Furthermore, the security module 40 has a first communication unit 43, via which the data exchange 16 between the field device 10 and the control unit 30 can be evaluated. The first communication unit 43 can be a modem for a communication standard used in the wired connection 20. Furthermore, the security module 40 has a controller 44, which comprises a processor and is coupled to a memory 46. The memory 46 is designed as a non-volatile memory, on which a partial program of a computer program product 35 is stored, with which a method 100, such as in Fig. 1. The memory 46 is further configured to temporarily store the transmitted data set 12 in order to generate a received duplicate 18. The security module 40 further comprises a second communication unit 47, which interacts with the antenna 42 to establish the radio connection 25. The second communication unit 47 can, for example, be a modem for the communication standard used in the radio connection 25.

[0029] The Fig. The security module 40 shown in Figure 2 is configured to at least temporarily store the data exchange 16 between the control unit 30 and the field device 10 as training data and to provide it as input to an artificial intelligence 49. The artificial intelligence 49 is stored in the memory 46 and is suitable for training characteristics of a properly configured data exchange 16 using the training data from the data exchange 16. The training of the artificial intelligence 49 takes place in a fifth step 150 of the method 100. Furthermore, the artificial intelligence 49 is configured to detect an anomaly in the data exchange 16 between the field device 10 and the control unit 30 and, if necessary, to classify such an anomaly as unauthorized data manipulation 15. Such evaluation of a data set 12 and detection of an anomaly takes place in a sixth step 160 of the method 100.

[0030] Furthermore, the security module 40 is equipped with at least one sensor 45, which can be designed as an acceleration sensor, a switch and / or a geoposition sensor. As a result, any physical manipulation of the security module 40 can be detected during the described method 100. If physical manipulation is detected, a warning is also issued. The security module 40 is additionally designed to monitor at least one electrical variable at the wire connection 20 and to compare it with a predeterminable threshold value. This makes it possible, for example, to detect an increasing energy consumption of the field device 10. The security module 40 is designed to issue a warning if the electrical variable exceeds its associated adjustable threshold value. Overall, the security module 40 is designed according to Fig. 2 an increased level of security for the operation of the associated industrial automation system 60 is achieved. QUOTES CONTAINED IN THE DESCRIPTION

[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature

[0000] US 2023 / 0179610 A1

[0002] US 8,184,562 B2

[0003]

Claims

[1] Method (100) for detecting unauthorized data manipulation (15) on a field device (10) in an industrial automation system (60) connected to a control unit (30) via a wired connection (20), comprising the steps: a) transmitting a data set (12) between the control unit (30) and the field device (10) via the wire connection (20) and storing the transmitted data set (12) as a transmission duplicate (13) on the transmitting control unit (30) or the transmitting field device (10); b) duplicating (19) the data set (12) sent to the field device (10) or the control unit as a received duplicate (18) and sending the received duplicate (18) to a comparison unit (50); c) comparing (56) the dispatch duplicate (18) with the reception duplicate (13) of the data record (12) and detecting an unauthorized data manipulation (15) if the dispatch duplicate (13) and the reception duplicate (18) differ from each other; d) issuing a warning (55) to a user and / or a data interface (54). [2] Method (100) according to claim 1, characterized by that at least step b) of is carried out by a security module (40) which is connected to the field device (10). [3] Method (100) according to claim 1 or 2, characterized by that the safety module (40) is digitally fused with the field device (10). [4] Method (100) according to one of claims 1 to 3, characterized by that the wired connection (20) is unencrypted and / or the radio connection (25) is encrypted. [5] Method (100) according to one of claims 1 to 4, characterized by that the wire connection (20) is designed as a HART connection, as an IO-Link connection, as a ModBus connection, as an ASi connection, as a Foundation Fieldbus connection, as a CAN bus connection, as a 4..20mA connection, as a ProfiBus connection and / or as a combination thereof. [6] Method (100) according to one of claims 1 to 5, characterized by that the radio connection (25) is designed as a Bluetooth connection, as a WiFi connection, as a LoRa connection, as a LoRaWAN connection, as a Zigbee connection, as an NbloT connection, as a CAT-M1 connection, as a point-to-point radio connection, as a GSM connection and / or as a combination thereof. [7] Method (100) according to one of claims 1 to 6, characterized by that the method (100) further comprises the steps: e) training an artificial intelligence (49) based on a data exchange (16) between the control unit (30) and the field device (10); f) detecting and evaluating at least one data set (12) transmitted between the control unit (30) and the field device (10) by the artificial intelligence (49) and checking the detected data set (12) for the presence of an anomaly. [8] Method (100) according to one of claims 2 to 7, characterized bythat the security module (30) is provided with at least one sensor (45) which is designed to detect unauthorized physical manipulation of the security module (30) and / or the field device (10). [9] Method (100) according to one of claims 1 to 8, characterized by that the radio connection (25) is established without interruption. [10] Method (100) according to one of claims 1 to 9, characterized by that upon detection of unauthorized data manipulation (15), at least the associated field device (10) is blocked or deactivated. [11] A computer program product (35) comprising machine-readable program code stored on a non-volatile memory (46) and executable by a processor, characterized bythat the computer program product (35) is designed to at least partially carry out a method (100) for detecting unauthorized data manipulation (15) on a field device (10) according to one of claims 1 to 10. [12] Comparison unit (50) designed to receive and process a sending duplicate (13) and a receiving duplicate (18) of a data set (12) sent from a control unit (30) to a field device (10), characterized by that the comparison unit (50) is equipped with a computer program product (35) according to claim 11. [13] Security module (40) connectable to a wire connection (20) between a field device (10) and a control unit (30) in an industrial automation system (60), characterized by that the security module (40) is configured to carry out at least step b) in a method (100) according to one of claims 1 to 10. [14] Industrial automation system (60), comprising at least one field device (10) connected to a control unit (30) and a security module (40) via a wired connection (20), and a comparison unit (50) connected to the security module (40) via a radio connection (25), characterized by that the industrial automation system (60) is designed to carry out a method (100) according to one of claims 1 to 10.

Citation Information

Patent Citations

  • Passive physical layer distinct native attribute cyber security monitor

    US20230179610A1

  • Process control system having dual wireless communication links

    US8184562B2