Method for automatically logging on a user to a field device and automation system
Patent Information
- Application Number
- DE502019013646
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2019-09-27
- Publication Date
- 2025-08-07
- Estimated Expiration
- 2039-09-27
AI Technical Summary
Existing methods for logging into field devices, particularly in industrial systems, face challenges with simple access data security, manual entry of complex passwords, and integration into automated systems, especially in older devices.
A method involving a security device that provides user information to a mobile device, which generates device-specific login information for seamless access to field devices, using cryptographic methods and local communication to ensure secure, automated login without manual entry.
Enhances security and efficiency by eliminating manual password entry errors and enabling secure, automated access to field devices without internet connectivity, suitable for safety-critical systems.
Description
[0001] The present invention relates to a method for automatically logging on a user to a field device and an automation system.
[0002] For a user to manage a field device, it is usually necessary for the user to log in to the field device using a combination of user name and password. The field device can, for example, have different user accounts, with different management operations being possible depending on the user account. Particularly in industrial systems such as automation systems that require regular maintenance by the manufacturer's service technicians, the problem here is that the access data used is often very simple to avoid complications during the login process. Using unique and complex passwords for different field devices would increase security, but is difficult to implement in practice. Manually entering long and complex passwords, for example, is time-consuming and error-prone.
[0003] Another problem is how the access data used can be stored and made available. Depending on the requirements of the operator of a field device or automation system, centralized, decentralized, or even local systems are possible. Especially with older field devices, it is often not possible or not easy to change passwords or integrate them into a corresponding automated access system.
[0004] A document US 2015 / 0215321A1 discloses a method and system for authorizing a user on a field device through a mobile communication device.
[0005] Against this background, it is an object of the present invention to propose an improved method for automatically logging on a user to a field device.
[0006] According to a first aspect, a method for automatically logging a user into a field device for managing the field device is proposed. In a step a), user information is provided by a security device depending on an identity of the user and an identity of the field device. In a step b), the provided user information is transmitted to a mobile device of the user. In a step c), the mobile device generates field device-specific login information depending on the transmitted user information. In a step d), the user is logged into the field device using the generated login information.
[0007] This method has the particular advantage that a highly secure infrastructure can be used to manage access information for field devices without causing problems during the login process. In particular, manual entry of complex and long passwords often leads to input errors, which is avoided here by providing a seamless chain from the security device to the login on the field device.
[0008] In this context, a field device is understood to mean any "smart" device that, for example, has sensors and / or data processing. Such field devices can be configured to adapt their behavior and / or functions to the respective desired application. For this purpose, the field device has an input option that is particularly protected, for example, by a password. To manage the field device, the password must therefore first be entered. In particular, the field device has control software, such as an operating system, by means of which the field device can be managed.
[0009] Examples of field devices include smart home devices such as intelligent light switches, door locks, ventilation and / or heating systems, and the like, as well as ATMs, ticket machines, medical devices such as X-ray machines or CT scanners, and even industrial production facilities. In particular, a plurality of field devices can form an automation system. Field devices that form an automation system can, in particular, be jointly managed by a control computer.
[0010] Managing a field device preferably refers to any operation on the field device that changes a configuration or setting on the field device. Managing particularly includes service operations, such as updating software or firmware, or other functional tests. Normal operation of the field device therefore does not constitute managing the field device. Setting the settings of an X-ray device and starting an X-ray image by an operator, such as a physician, preferably does not constitute managing the field device.
[0011] Depending on the type and configuration of the field device, a central management access, such as administrator access, can be provided, or different user groups can be provided, with each user group having assigned rights. An individual user account can also be provided for each user, with each user account being assigned individual rights for managing the field device.
[0012] In particular, these field devices are not connected to the internet or at least do not have internet-accessible access that would allow them to be managed. This is often the case with safety-critical field devices, for example. This ensures that a hacker cannot gain management access to the field device via the internet. Logging into the field device to manage it, for example, by a service technician, can only be done locally with such field devices, meaning the service technician requires physical access to the field device.
[0013] The security device is designed, for example, as a password safe. The security device can be accessible, for example, via the Internet or an internal intranet. Preferably, the security device is configured for the cryptographic storage of user information for one or more field devices. User information can be separate information for each individual user and for each field device. However, it can also be provided that several users form a user group whose user information is then identical. Preferably, the user information is different for at least each of a number of field devices.In this case, the fact that the user information is provided depending on the identity of the user and the identity of the field device means that exactly the user information assigned to the respective user for the respective field device is provided.
[0014] Providing user information means, for example, that the security device reads it from an internal memory and outputs it, for example to a communication unit of the security device, such as a modem.
[0015] The user information is then transmitted to the user's mobile device. The mobile device is, in particular, a smartphone or notebook belonging to the user. The mobile device establishes a communication connection with the security device, via which the user information is transmitted. The communication connection can, for example, comprise a LAN connection, a WLAN connection, a mobile phone connection, a Bluetooth connection, and the like. The communication connection is, in particular, secured by encryption. The user information can be transmitted directly before logging on or significantly before logging on to the field device. For example, the user information can be transmitted while the user is still in the office before driving to the field device. However, the transmission can also take place immediately before logging on.
[0016] Once the mobile device has received the user information, it generates a login credential based on this user information. This specifically means that the mobile device decrypts, for example, encrypted transmitted user information and thus generates the login credential. Additional security factors may be used, such as a chip card reader or the entry of a password or biometric information, such as a fingerprint or an iris scan.
[0017] In some embodiments, generating the login information can also mean that the mobile device leaves the received user information unchanged in terms of content and converts it into a data format readable by the field device and / or packages it into a data packet that can be transmitted according to a specific protocol. The mobile device then functions, for example, as a wireless modem. In this respect, "generating" does not necessarily mean manipulating the user information or generating new data; rather, the login information can also be identical to the user information.
[0018] The generated credential is suitable for logging the user into the field device. The credential can be transmitted to the field device in various ways. This is preferably done automatically, using a scanner, a microphone, a data connection, or even an acceleration sensor. For example, the mobile device generates a modulated tone sequence containing the credential. The tone sequence is captured by a microphone, and the credential is determined from it by demodulation.
[0019] This may require the user to first enter a user name or access name. However, this information is preferably already included in the login information, so the user does not need to enter it manually.
[0020] Advantageously, the method also allows the user to log in to the field device without the user knowing the login information. Security is thus further increased.
[0021] When multiple field devices are deployed, the login credentials are preferably different for each field device, preventing a user from logging in to multiple field devices using a single credential. This contributes to increased security.
[0022] According to one embodiment of the method, the safety device is arranged locally at the field device.
[0023] Local means that the safety device is located in the same room as the field device, preferably no more than 3 meters away from the field device. For large devices, such as a rolling mill or a printing press, the local arrangement refers in particular to a central control computer, if one is available.
[0024] Physical access to the safety device is therefore only possible if physical access to the field device is also available. This makes tampering with the safety device more difficult. The safety device is preferably designed as a mini-PC that can be powered, for example, via a USB port.
[0025] According to a further embodiment of the method, the provided user information is transmitted by means of a local communication connection between the mobile device and the security device.
[0026] A local communication connection is understood, in particular, to be a short-range communication connection. Reliable communication is only possible at a short distance, for example, less than 10 meters, preferably less than 5 meters, more preferably less than 3 meters, and preferably less than 1 meter, between the mobile device and the security device. This can apply to both wired and wireless communication connections. Examples of such a communication connection are Bluetooth or NFC (Near Field Communication).
[0027] In particular, in this embodiment, the security device is preferably not connected to the Internet or an intranet, making remote manipulation of the security device impossible. This embodiment significantly increases security.
[0028] According to a further embodiment of the method, the security device is configured for cryptographically secured storage of access data for at least one user group of a plurality of user groups of the field device.
[0029] In addition, the method provides a receiving device that can be coupled to the field device, which registers with the field device as an interface device and receives the registration information from the mobile device via a communication connection to the mobile device and registers the user with the field device.
[0030] This embodiment is particularly advantageous because a field device can be used for automatic registration without requiring any modification to the field device itself. The receiving device is coupled, in particular, via an interface already present on the field device, preferably via a wired connection. In particular, a corresponding receiving device can be configured for any known interface.
[0031] An interface device is understood to be, for example, an input device such as a keyboard, a computer mouse, and / or a joystick. The coupled receiving device is preferably not actually designed as an interface device, but merely registers with the field device as such. One can also say that the receiving device simulates a real interface device. This enables the receiving device to transmit inputs typical of an interface device to the field device. For example, a USB dongle can register with the field device as a keyboard configured for entering character strings according to known standards.
[0032] In preferred embodiments, the receiving device is designed as a USB dongle and coupled to the field device via a USB interface. This embodiment has the advantage that any field device with a USB interface can be used for the method. The USB dongle registers with the field device as a keyboard. The USB dongle, for example, has a Bluetooth modem and can establish a Bluetooth connection to the mobile device.
[0033] The communication connection to the receiving device is, in particular, a local communication connection. The communication connection is, in particular, secured by encryption.
[0034] Furthermore, part of the method is that in addition to the login information and after the user has logged in to the field device, the mobile device sends a management input for managing the field device to the receiving device.
[0035] An administrative input can be any command that can be entered via the interface device simulating the receiving device. For example, a mouse click on specific coordinates can be "simulated," or a command line window can be opened, a command can be entered, and a command can be confirmed.
[0036] For example, updates can be performed virtually invisibly, without requiring manual user intervention. This can further increase security, especially for security-critical administrative operations.
[0037] In some embodiments, entire scripts can also be created and / or executed on the field device.
[0038] According to a further embodiment of the field device, the mobile device generates the login information by means of a cryptographic method depending on the user information.
[0039] A cryptographic method refers, in particular, to the application of an encryption and / or authentication method. Examples include PKI (Public Key Infrastructure) or OTP (One-Time-Pad).
[0040] According to a further embodiment of the method, step a) comprises authenticating the user on the mobile device and / or on the security device.
[0041] For example, the user authenticates on the mobile device with their fingerprint, after which the mobile device authenticates itself to the security device as the user's mobile device. This ensures that user information is only transmitted to the mobile device that actually belongs to the user who wishes to log in to the field device.
[0042] To increase security, two-factor user authentication can also be provided. For example, the user must first authenticate themselves to the mobile device so that the device can receive the user credentials from the security device. The user credentials can, for example, include a user-specific second factor for authentication, which the user must provide before the field device-specific credentials can be generated. The second factor can be a password, an object such as a chip card, or even a biometric characteristic of the user.
[0043] According to a second aspect, an automation system with a number of field devices and at least one safety device is proposed. Each field device of the number of field devices can be managed by at least one user, wherein in order to manage a respective one of the field devices, registration with the respective field device using field device-specific login information is required. A mobile device of the at least one user is configured to retrieve user information from the safety device depending on an identity of the at least one user and an identity of the respective field device. The mobile device is further configured to generate the field device-specific login information depending on the retrieved user information and to output the generated login information.
[0044] This automation system can comprise one or more field devices. In particular, the automation system is an industrial production facility with a large number of field devices, all or part of which can be managed via a central control computer. Logging on to the control computer thus corresponds to logging on to all field devices that can be managed via it. In this respect, the control computer can be considered a single field device.
[0045] The at least one user is preferably logged on to one of the field devices according to the method of the first aspect. The embodiments and features described for the proposed method apply accordingly to the proposed automation system, whereby the aforementioned advantages also arise.
[0046] In this context, a field device is understood to mean any "smart" device that, for example, has sensors and / or data processing. Such field devices can be configured to adapt their behavior and / or functions to the respective desired application. For this purpose, the field device has an input option that is particularly protected, for example, by a password. To manage the field device, the password must therefore first be entered. In particular, the field device has control software, such as an operating system, by means of which the field device can be managed.
[0047] Examples of field devices include smart home devices such as intelligent light switches, door locks, ventilation and / or heating systems, and the like, as well as ATMs, ticket machines, medical devices such as X-ray machines or CT scanners, and even industrial production facilities. In particular, a plurality of field devices can form an automation system. Field devices that form an automation system can be managed jointly by a control computer.
[0048] Managing a field device preferably refers to any operation on the field device that changes a configuration or setting on the field device. Managing particularly includes service operations, such as updating software or firmware, or other functional tests. Normal operation of the field device therefore does not constitute managing the field device. Setting the settings of an X-ray device and starting an X-ray image by an operator, such as a physician, preferably does not constitute managing the field device.
[0049] Depending on the type and configuration of the field device, a central management access, such as administrator access, can be provided, or different user groups can be provided, with each user group having assigned rights. An individual user account can also be provided for each user, with each user account being assigned individual rights for managing the field device.
[0050] In particular, these field devices are not connected to the internet or at least do not have internet-accessible access that would allow them to be managed. This is often the case with safety-critical field devices, for example. This ensures that a hacker cannot gain management access to the field device via the internet. Logging into the field device to manage it, for example, by a service technician, can only be done locally with such field devices, meaning the service technician requires physical access to the field device.
[0051] The security device is designed, for example, as a password safe. The security device can be accessible, for example, via the Internet or an internal intranet. Preferably, the security device is configured for the cryptographic storage of user information for one or more of the field devices. User information can be separate information for each individual user and for each field device. However, it can also be provided that several users form a user group whose user information is then identical. Preferably, the user information is different for at least each of a number of field devices. The fact that the user information is retrieved depending on the identity of the user and the identity of the field device is understood here to mean that exactly the user information assigned to the respective user for the respective field device is retrieved.This is done in particular under the control of the safety device.
[0052] The mobile device retrieves the user information from the security device. For example, the security device provides the user information, which is then transmitted to the mobile device. For example, the security device reads the user information from internal memory and sends it to the mobile device via a communication unit of the security device, such as a modem.
[0053] The mobile device is, in particular, a smartphone or notebook belonging to the user. The mobile device establishes a communication connection with the security device, via which the user information is transmitted. The communication connection can, for example, comprise a LAN connection, a WLAN connection, a mobile phone connection, a Bluetooth connection, and the like. The communication connection is, in particular, secured by encryption. The transmission of the user information can, in particular, take place directly before logging in or significantly before logging in to the field device. For example, the user information can be transmitted while the user is still in the office before driving to the field device. However, the transmission can also take place immediately before logging in.
[0054] Once the mobile device has received the user information, it generates a login credential based on this user information. This specifically means that the mobile device decrypts, for example, encrypted transmitted user information and thus generates the login credential. Additional security factors may be used, such as a chip card reader or the entry of a password or biometric information, such as a fingerprint or an iris scan.
[0055] In some embodiments, generating the login information can also mean that the mobile device leaves the received user information unchanged in terms of content and converts it into a data format readable by the field device and / or packages it into a data packet that can be transmitted according to a specific protocol. The mobile device then functions, for example, as a wireless modem. In this respect, "generating" does not necessarily mean manipulating the user information or generating new data; rather, the login information can also be identical to the user information.
[0056] The generated login information is suitable for logging the user into the field device. For this purpose, the login information is output by the mobile device, in particular transmitted to the field device. The login information can be transmitted to the field device in various ways. This is preferably done automatically, whereby a scanner, a microphone, a data connection, or even an acceleration sensor can be used. For example, the mobile device generates a modulated tone sequence containing the login information. The tone sequence is captured by a microphone, and the login information is determined from it by demodulation.
[0057] This may require the user to first enter a user name or access name. However, this information is preferably already included in the login information, so the user does not need to enter it manually.
[0058] When multiple field devices are deployed, the login credentials are preferably different for each field device, preventing a user from logging in to multiple field devices using a single credential. This contributes to increased security.
[0059] According to one embodiment of the automation system, the number of field devices forms a local group, wherein the safety device is arranged locally in the group.
[0060] A local group is understood, for example, to be a number of field devices arranged in close proximity to one another, with a distance of less than 10 meters, preferably less than 5 meters, more preferably less than 3 meters, and preferably less than 1 meter. In particular, individual field devices in the local group can also functionally cooperate and / or be interdependent.
[0061] A local arrangement is understood to be an arrangement with a small distance.
[0062] According to a further embodiment of the automation system, the mobile device is configured to retrieve the user information by means of a local communication connection to the security device.
[0063] A local communication connection is understood, in particular, to be a short-range communication connection. Reliable communication is only possible at a short distance, for example, less than 10 meters, preferably less than 5 meters, more preferably less than 3 meters, and preferably less than 1 meter, between the mobile device and the security device. This can apply to both wired and wireless communication connections. Examples of such a communication connection are Bluetooth or NFC (Near Field Communication).
[0064] According to a further embodiment of the automation system, at least one of the field devices of the number has a coupled receiving device that registers with the field device as an interface device, wherein the mobile device is configured to establish a communication connection with the receiving device, wherein the mobile device is configured to transmit the registration information to the receiving device via the communication connection and the receiving device is configured to register the user with the field device.
[0065] This embodiment is particularly advantageous because the field device can be used for automatic registration without requiring any modifications to the field device itself. The receiving device is coupled, in particular, via an interface already present on the field device, preferably wired. In particular, a corresponding receiving device can be configured for any known interface. This allows even field devices that are outdated in terms of the available interface to be used accordingly.
[0066] An interface device is understood to be, for example, an input device such as a keyboard, a computer mouse, and / or a joystick. The coupled receiving device is preferably not actually designed as an interface device, but merely registers with the field device as such. One can also say that the receiving device simulates a real interface device. This enables the receiving device to transmit inputs typical of an interface device to the field device. For example, a USB dongle can register with the field device as a keyboard configured for entering character strings according to known standards.
[0067] In preferred embodiments, the receiving device is designed as a USB dongle and coupled to the field device via a USB interface. This embodiment has the advantage that any field device with a USB interface can be used for the method. The USB dongle registers with the field device as a keyboard. The USB dongle, for example, has a Bluetooth modem and can establish a Bluetooth connection to the mobile device.
[0068] The communication connection to the receiving device is, in particular, a local communication connection. The communication connection is, in particular, secured by encryption.
[0069] According to a further embodiment of the automation system, the mobile device is configured to generate a management input for managing the field device and to transmit the management input to the receiving device after the user has logged on to the field device.
[0070] An administrative input can be an additional command that can be entered via the interface device simulating the receiving device. For example, a mouse click on specific coordinates can be "simulated," or a command line window can be opened, where a command can be entered and confirmed.
[0071] For example, updates can be performed virtually invisibly, without requiring manual user intervention. This can further increase security, especially for security-critical administrative operations.
[0072] In some embodiments, entire scripts can also be created and / or executed on the field device.
[0073] According to a further embodiment of the automation system, the mobile device is configured to retrieve the user information and / or to generate the login information by means of a cryptographic method.
[0074] A cryptographic method refers, in particular, to the application of an encryption and / or authentication method. Examples include PKI (Public Key Infrastructure) or OTP (One-Time-Pad).
[0075] According to a further embodiment of the automation system, a communication connection for retrieving the user information and / or a communication connection for transmitting the login information is a local communication connection.
[0076] Furthermore, a computer program product is proposed which causes the method as explained above to be carried out on a program-controlled device.
[0077] A computer program product, such as a computer program means, can be provided or delivered, for example, as a storage medium, such as a memory card, USB stick, CD-ROM, DVD, or in the form of a downloadable file from a server in a network. This can be done, for example, in a wireless communications network by transmitting a corresponding file with the computer program product or the computer program means.
[0078] According to a further aspect, an automation system with a number of field devices and at least one safety device arranged locally with one of the field devices of the number is proposed. Each field device of the number can be managed by users, wherein in order to manage one of the field devices, registration with the respective field device using field device-specific login information is required. A mobile device of the user is configured to retrieve user information from the safety device depending on an identity of the user and an identity of the field device via a local communication connection. The mobile device is further configured to generate the field device-specific login information depending on the retrieved user information and to output the generated login information.
[0079] This can advantageously increase security for access to safety-critical field devices, since the physical presence of the user is required both to retrieve user information and to log in to the respective field device. The user is preferably authenticated using the mobile device, for example, using a biometric identifier. The embodiments and features of the automation system according to the second aspect apply accordingly to the proposed automation system.
[0080] To increase security, two-factor user authentication can also be provided. For example, the user must first authenticate themselves to the mobile device so that the device can receive the user credentials from the security device. The user credentials can, for example, include a user-specific second factor for authentication, which the user must provide before the field device-specific credentials can be generated. The second factor can be a password, an object such as a chip card, or even a biometric characteristic of the user.
[0081] Further possible implementations of the invention also include combinations of features or embodiments described above or below with respect to the exemplary embodiments that are not explicitly mentioned. In this case, the person skilled in the art will also add individual aspects as improvements or additions to the respective basic form of the invention.
[0082] Further advantageous embodiments and aspects of the invention are the subject of the dependent claims and the exemplary embodiments of the invention described below. The invention will be explained in more detail below using preferred embodiments with reference to the accompanying figures. Fig. 1 shows a schematic block diagram of a first embodiment of an automation system; Fig. 2 shows a schematic block diagram of a second embodiment of an automation system; Fig. 3 shows a schematic block diagram of a third embodiment of an automation system; and Fig. 4 shows a schematic block diagram of an embodiment of a method for automatically logging on a user to a field device.
[0083] In the figures, identical or functionally identical elements have been given the same reference numerals unless otherwise stated.
[0084] Fig. 1 shows a schematic block diagram of a first embodiment of an automation system 300, which is, for example, an industrial production plant. Without restricting its generality, the industrial production plant 300 has only one field device 100, which is, for example, a control computer of the industrial production plant 300. The control computer 100 can be used, for example, to control the production of the industrial production plant 300. If the industrial production plant 300 is expanded and / or modified by individual machines, this must be configured accordingly on the control computer 100. For this purpose, a suitably trained user, for example, a service technician, must log on to the control computer 100 to perform this configuration; this is also referred to as managing the control computer 100.
[0085] The user must have the appropriate rights to make changes to the configuration. For this purpose, for example, an administrator account is set up on the control computer 100. The administrator account is protected in particular with a strong password, which is, for example, 250 characters long and contains a random mix of upper and lower case letters, numbers, and special characters. Entering such a password manually would be very time-consuming and error-prone. Therefore, the user carries a mobile device 150, which is embodied here as a smartphone. As soon as the user is at the control computer 100, they initiate the login process, for example, via a special application on the smartphone 150. The smartphone 150 establishes a communication connection K1 to a security device 200, which is embodied here as a server.The server 200 has a cryptographic storage system in which access data for a plurality of users and / or a plurality of field devices 100 are stored. Upon request from the smartphone 150, the server 200 provides user information U1 depending on the identity of the user and the field device to which the user wishes to log in and transmits it to the smartphone 150.
[0086] Smartphone 150 receives user information U1 and generates login information U2 from it, which here includes, for example, an access name for administrator access and the associated password. In particular, smartphone 150 decrypts the received user information U1 for this purpose. It can also be provided that smartphone 150 forwards the received user information U1 unchanged as login information U2.
[0087] The smartphone 150 then transmits the login information U2 to the field device 100 via a transmission path K2 to log the user into the administrator account. The transmission path K2 is, for example, a wireless transmission connection; in particular, it can also be a signal transmission via optical, acoustic, and / or mechanical means. For example, the smartphone could display the login information U2 as a barcode or a QR code on a screen, and a camera (not shown) arranged on the control computer 100 captures the screen content of the smartphone 150.
[0088] This allows the user to easily log in as administrator to the control computer 100, which is protected with a very strong password.
[0089] The described method is preferably to be used when the field device 100 does not allow remote access, for example via the Internet.
[0090] Fig. 2 shows a schematic block diagram of a second embodiment of an automation system 300. The second embodiment has the same features as the first embodiment, with additional features being described below.
[0091] For example, the field device 100 in this example is an outdated measuring device that operates with outdated and insecure control software. Therefore, the measuring device 100 has no internet access and can only be managed locally. Apart from relatively old interfaces, such as RS-232, PS / 2, or USB 1.0, the measuring device 100 also has no communication interfaces. To achieve automated user registration, the measuring device 100 was equipped with a receiving device 110, which is embodied here as a USB dongle that registers with the measuring device 100 as a keyboard. The USB dongle 110 is configured, in particular, to establish an NFC connection K2.
[0092] In order to log in to the measuring device 100, the user calls up a user information U1 (see Fig. 1 ). The smartphone 150 generates the login information U2 from this user information U1 (see Fig. 1 ). The user then brings the smartphone 150 close to the USB dongle 110, whereby the smartphone 150 establishes the NFC connection K2 to the USB dongle 110 and transmits the login information U2 via this connection K2.
[0093] The USB dongle 110 receives the login information U2 and outputs it to the measuring device 100, whereby the measuring device 100 receives the same signal via the USB port as if the user were entering the login information U2 via a physical keyboard.
[0094] Thus, the user is automatically logged in to the measuring device 100, which is why a strong password can be used to secure access without logging in being a problem.
[0095] Fig. 3 shows a schematic block diagram of a third exemplary embodiment of an automation system 300. The illustrated automation system 300 is, for example, a safety-critical system, such as a power plant. Here, too, only one field device 100 is illustrated, without restricting generality.
[0096] For security reasons, it is undesirable for the Kraftwerk 300 to have access data such as user information U1 (see Fig. 1 ) or credentials U2 (see Fig. 1 ) are stored outside the power plant 300 and / or centrally. Therefore, the safety device 200 is arranged locally at the field device 100. Furthermore, there is no external communication connection from either the safety device 200 or the field device 100.
[0097] The user must therefore be physically present to manage the field device 100. To do so, the user establishes a local communication connection K1 with the security device 200 using their mobile device 150, for example, an NFC connection. The security device 200 comprises an access data memory 210, which stores, for example, access data for a plurality of users. The user information U1 assigned to the user is read by the security device 200 from the access data memory 210 and transmitted to the mobile device 150 via the communication connection K1. The user information U1 is, in particular, cryptographically secured using OTP (One-Time-Pad), so that the user or the mobile device must first generate a corresponding cryptographic key with which it can be decrypted. In this way, the login information U2 is generated in a cryptographically secure manner.
[0098] The login information U2 is sent from the mobile device 150 via a local communication connection K2, for example Bluetooth, to the field device 100 or to a receiving device 110 (see Fig. 2 ). This automatically logs the user into the field device 100.
[0099] Subsequently, the user can transmit further management inputs to the field device 100 via the local communication connection K2, allowing management of the field device 100 using the mobile device 150. In particular, management can also be fully automated after the user has logged in, for example, by transmitting predetermined scripts and / or command sequences from the mobile device 150 to the field device 100.
[0100] Fig. 4 shows a schematic block diagram of an embodiment of a method for automatically logging on a user to a field device 100 (see Fig. 1 - 3 ).
[0101] In a first step S1, a user information U1 (see Fig. 1 ) depending on an identity of the user and an identity of the field device 100 by a security device 200 (see Fig. 1 - 3 ). In particular, the user information U1 is taken from a cryptographically secured memory, such as an access data memory 210 (see Fig. 3 ), read out. In this case, authentication of the user and / or the mobile device 150 (see Fig. 1 - 3 ) should be provided.
[0102] In a second step S2, the provided user information U1 is transmitted to the user's mobile device 150. The transmission can take place via a wired or wireless communication connection K1 (see Fig. 1 - 3 ). To increase security, the communication connection K1 can be a local connection that allows only a small distance between the mobile device 150 and the security device 200. The transmission is preferably cryptographically secured, i.e., in particular, encrypted.
[0103] In a third step S3, the mobile device 150 generates a field device-specific login information U2 (see Fig. 1 ) depending on the transmitted user information U1. For example, the mobile device 150 decrypts the encrypted transmitted user information U1.
[0104] In a fourth step S4, the user is logged on to the field device 100 using the generated login information U2. The login occurs automatically, i.e., without the user having to enter the login information U2 themselves. For this purpose, a local communication connection K2 (see Fig. 1 - 3 ) from the mobile device 150 to the field device 100 or to a receiving device 110 coupled to the field device 100 (see Fig. 2 ). The transmission of the login information U2 over the communication link K2 is particularly encrypted. The login information can also be kept secret from the user, which further increases security.
Claims
1. Method for automatically registering a user on a field device (100) for the purpose of administering the field device (100), comprising a) providing (S1) user information (U1) on the basis of an identity of the user and an identity of the field device (100) by way of a security device (200), b) transmitting (S2) the provided user information (U1) to a mobile device (150) of the user, c) generating (S3) field-device-specific registration information (U2) on the basis of the transmitted user information (U1) by way of the mobile device (150), and d) registering (S4) the user on the field device (100) by means of the generated registration information (U2), characterized in that there is provision for a receiving apparatus (110), couplable to the field device (100), that registers on the field device (100) as an interface device and that uses a communication connection (K2) to the mobile device (150) to receive the registration information (U2) from the mobile device (150) and registers the user on the field device (100), and the mobile device (150) sends an administration input for administering the field device (100) to the receiving apparatus (110) in addition to the registration information (U2) and after the user has been registered on the field device (100).
2. Method according to Claim 1, characterized in that the security device (200) is arranged locally to the field device (100).
3. Method according to Claim 2, characterized in that the provided user information (U1) is transmitted between the mobile device (150) and the security device (200) by means of a local communication connection (K1).
4. Method according to one of Claims 1-3, characterized in that the security device (200) is configured for cryptographically secure storage of access data for at least one user group from a plurality of user groups of the field device (100).
5. Method according to one of Claims 1-4, characterized in that the mobile device (150) generates the registration information (U2) by means of a cryptographic method on the basis of the user information (U1).
6. Method according to one of Claims 1-5, characterized in that step a) comprises authentication of the user on the mobile device (150) and / or on the security device (200).
7. Automation system (300) having a number of field devices (100) and at least one security device (200), wherein each field device (100) from the number of field devices (100) is administrable by at least one user, wherein administering a respective instance of the field devices (100) requires registration with the respective field device (100) by means of field-device-specific registration information (U2), wherein a mobile device (150) of the at least one user is configured for retrieving user information (U1) from the security device (200) on the basis of an identity of the at least one user and an identity of the respective field device (100), and wherein the mobile device (150) is configured for generating the field-device-specific registration information (U2) on the basis of the retrieved user information (U1) and for outputting the generated registration information (U2), characterized in that - at least one of the field devices (100) from the number of field devices (100) has a coupled receiving apparatus (110) that is configured to register on the field device (100) as an interface device, wherein the mobile device (150) is configured for making a communication connection (K2) to the receiving apparatus (110), wherein the mobile device (150) is configured for transmitting the registration information (U2) to the receiving apparatus (110) via the communication connection (K2), and the receiving apparatus (110) is configured for registering the at least one user on the field device (100), and - the mobile device (150) is configured for generating an administration input for administering the field device (100) and for transmitting the administration input to the receiving apparatus (110) after the at least one user has been registered on the field device (100).
8. Automation system (300) according to Claim 7, characterized in that the number of field devices (100) forms a local group, wherein the security device (200) is arranged locally to the group.
9. Automation system (300) according to Claim 8, characterized in that the mobile device (150) is configured for retrieving the user information (U1) by means of a local communication connection (K1) to the security device (200).
10. Automation system (300) according to one of Claims 7-9, characterized in that the mobile device is configured for retrieving the user information (U1) and / or for generating the registration information (U2) by means of a cryptographic method.
11. Automation system (300) according to one of Claims 7-10, characterized in that the communication connection (K1) for retrieving the user information (U1) and / or the communication connection (K2) for transmitting the registration information (U2) is a local communication connection (K1, K2).