Device for protecting access to segments in distributed systems

DE502020011929D1Active Publication Date: 2025-10-02VEGA GRIESHABER GMBH & CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502020011929
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-11-13
Publication Date
2025-10-02
Estimated Expiration
2040-11-13

AI Technical Summary

Technical Problem

Existing systems require individual access codes for each field device in distributed systems, leading to security hurdles and inefficient access management.

Method used

A device and method for verifying access data across multiple field devices within a segment, allowing secure and easy access by checking the access data of all devices in the segment, with the option for temporary access and centralized verification using a security server.

Benefits of technology

Enables secure and efficient access to multiple field devices within a segment by verifying access data collectively, reducing the need for individual code entry and enhancing security and ease of access management.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Field of the invention

[0001] The invention relates to a device for protecting access to segments in distributed systems according to claim 1.

[0002] Furthermore, the present invention relates to a method according to claim 10 for protecting access for a segment in distributed systems as well as a corresponding program element and a corresponding computer-readable storage medium. background

[0003] Central user administration in distributed systems can be achieved, for example, using the so-called Lightweight Directory Access Protocol, a protocol standard for querying and modifying information from a directory service, also known as Active Directory.

[0004] US 2016 / 119284 A1 describes systems and techniques for granting network access for a new network device.

[0005] In particular, various techniques and systems are provided for connecting a new network device to a network and limiting access of the network device while the new network device is authenticated. Example embodiments include a computer-implemented method. The method includes receiving, at a gateway in a network, a communication containing a request for a new network device to join the network; establishing a connection between the new network device and the gateway.

[0006] Document US 2016 063 785 A1 describes a method for authenticating a first unit, in particular a mobile device, on a second unit, in particular a field device, in a process automation system. Document US 2020 228 981 A1 relates to the field of communications technology, in particular to a method and device for authentication.

[0007] Document US 2009 060 192 A1 relates to communication networks, in particular to a method and a device for providing security in wireless communication networks.

[0008] According to the current state of the art, each field device is equipped with an individual access code and an individual code for locking the parameterization.

[0009] If a large number of sensors are used in a process plant, the valid access code must be entered for each individual sensor. Although this ensures a high level of security, it represents a certain hurdle in application. Summary of the invention

[0010] It is an object of the present invention to provide an improved apparatus for protecting access for segments in distributed systems.

[0011] The present invention makes it possible to provide verification of access data by all field devices grouped in a segment.

[0012] This object is achieved by the features of the independent patent claims. Further developments of the invention emerge from the subclaims and the following description of embodiments.

[0013] A first aspect of the invention relates to a device for protecting access for a segment in distributed systems, the device comprising: an input device which is designed to capture access data for a first field device.

[0014] Furthermore, the device according to the invention comprises a verification device which is designed to verify the acquired access data from a second field device, wherein the first field device and the second field device are coupled to the segment.

[0015] The present invention advantageously enables the connection to a segment having a plurality of field devices to be established to each field device in this segment even if the access code to a field device of the segment is known.

[0016] To do this, when establishing a connection to a field device, the required access data of all field devices linked to a segment is checked for correctness. If a field device in the segment confirms that the access data is correct, access to the desired field device is granted.

[0017] The present invention advantageously enables secure yet easy access to a field device.

[0018] According to one embodiment of the invention, it is provided that the verification device is designed to enable access to the first field device and / or the second field device using the access data.

[0019] According to one embodiment of the invention, the verification device is designed to temporarily enable access using the access data.

[0020] According to one embodiment of the invention, the verification device is designed to use the access data to temporarily enable access for a predetermined period of time and / or for a predetermined process sequence. The process sequence can include a sequence of program steps for providing access to a field device.

[0021] According to one embodiment of the invention, the verification device is designed to verify the acquired access data for access to the first field device of the segment by all field devices of the segment.

[0022] According to one embodiment of the invention, the device is designed as a security server.

[0023] Another aspect of the invention relates to a method for protecting access to a segment in distributed systems.

[0024] As a first step in the process for protecting access to a segment in distributed systems, access data for a first field device is collected.

[0025] As a second step of the method for protecting access for a segment in distributed systems, the acquired access data is verified by a second field device, wherein the first field device and the second field device are coupled to the segment.

[0026] At this point, it should be noted that according to a further aspect of the invention, the features described above and below with regard to the field device or the device can also be implemented as method steps.

[0027] Likewise, the method steps described above and below can be carried out by certain embodiments of the field device or apparatus.

[0028] According to a further aspect of the invention, a program element is specified which, when executed on a processor of the field device or device, instructs the field device or device comprising the device according to the invention for protecting access for a segment to carry out the steps described above and below.

[0029] According to a further embodiment of the invention, a computer-readable medium is provided on which a program element described above is stored.

[0030] The program element can be part of a software program stored on a processor. Furthermore, this embodiment of the invention comprises a program element that corresponds to the method or individual method steps described above and below.

[0031] According to a further embodiment of the invention, the distributed system comprising the inventive device for protecting access for a segment can be implemented as a distributed computer environment.

[0032] According to a further embodiment of the invention, the distributed system comprising the device according to the invention for protecting access for a segment can be implemented as a networked client-server system with a smartphone as a client having access to field devices or level measuring devices and to storage or processing resources in a computer cloud.

[0033] The term "computer cloud" refers to an IT infrastructure that is made available, for example, via the Internet.

[0034] According to a further embodiment of the invention, the distributed system comprising the device according to the invention for protecting access for a segment can be designed as a networked heterogeneous or homogeneous computer network with at least two devices according to the first aspect and / or a plurality of field devices or level measuring devices that interact via the computer network or, for example, as an ad hoc network or are networked via the Internet.

[0035] According to a further embodiment of the invention, the computer network comprising the device according to the invention for protecting access can be divided into computer network segments.

[0036] Further embodiments of the invention are described below with reference to the figures. Where the same reference numerals are used in the following description of the figures, they denote identical or similar elements. The representations in the figures are schematic and not to scale. Short description of the characters

[0037] Fig. 1 shows an apparatus for protecting access for a segment in distributed systems according to an embodiment of the invention. Fig. 2 shows an apparatus for protecting access for a segment in distributed systems according to an embodiment of the invention. Fig. 3 shows a flowchart of a method for protecting access for a segment in distributed systems according to an embodiment of the invention. Detailed description of embodiments Description of implementation examples

[0038] The representations in the figures are schematic and not to scale.

[0039] Where the same reference symbols are used in different figures in the following description, they refer to identical or similar elements. Identical or similar elements may also be designated by different reference symbols.

[0040] Fig. 1 shows an apparatus for protecting access for a segment in distributed systems according to an embodiment of the invention.

[0041] According to one embodiment of the invention, it is provided that a check of the access data for access to a field device of a segment is carried out by all or at least by a predetermined proportion of the field devices of the segment, for example more than half or one third.

[0042] According to one embodiment of the invention, if the access data matches the access data stored in a field device, access is enabled.

[0043] According to one embodiment of the invention, in the case of integration of a security server into the segment of field devices, this security server can centrally enable access to the sensors in the segment.

[0044] According to one embodiment of the invention, it is provided that a temporary release is carried out, e.g. for a service technician for all field devices of the segment in which a time-limited access code is set up on one of the field devices or on the security server.

[0045] According to one embodiment of the invention, each field device can be contained in multiple segments. This makes it possible to control which access data can affect which field devices.

[0046] For a field device A, for example, the access data from a field device in segment A must be known, whereas for a field device B the access data from segment A and segment B can be used if field device A is only part of segment A, while field device B is part of segments A and B.

[0047] According to one embodiment of the invention, the field devices are designed as field devices for process automation, in particular for determining a process variable such as fill level or pressure.

[0048] Fig. 2 shows an apparatus for protecting access for a segment in distributed systems according to an embodiment of the invention.

[0049] The device for protecting access to a segment in distributed systems comprises an input device 10 and a verification device 20.

[0050] The input device 10 is designed to capture access data for a first field device.

[0051] The verification device 20 is designed to verify the acquired access data from a second field device, wherein the first field device and the second field device are coupled to the segment.

[0052] Fig. 3 a flowchart of a method for protecting access for a segment in distributed systems according to an embodiment of the invention.

[0053] As a first step of the method for protecting access for a segment in distributed systems, access data for a first field device is collected S1.

[0054] As a second step of the method for protecting access for a segment in distributed systems, verification S2 of the acquired access data is carried out by a second field device, wherein the first field device and the second field device are coupled to the segment.

[0055] According to one embodiment of the invention, it is provided that the access data enables access to the first field device and / or to the second field device.

[0056] According to one embodiment of the invention, it is provided that access is temporarily enabled with the access data.

[0057] It should also be noted that "comprising" and "having" do not exclude other elements or steps, and the indefinite articles "a" or "an" do not exclude a plurality.

[0058] Reference signs in the claims are not to be considered as limitations.

Claims

1. A device for protecting an access for a segment in distributed systems, the device comprising: an input device (10) configured to capture access data for a first field device; and a verification device (20) configured to verify the acquired access data from a second field device, wherein the first field device and the second field device are coupled to the segment.

2. The device according to claim 1, wherein the verification device (20) is configured to enable access to the first field device and / or to the second field device with the captured access data.

3. The device according to claim 2, wherein the verification device (20) is configured to temporarily enable access with the captured access data.

4. The device according to claim 3, wherein the verification device (20) is configured to temporarily enable access for a predetermined period of time and / or for a predetermined process sequence using the acquired access data.

5. The device according to one of the preceding claims, wherein the verification device (20) is configured to verify the acquired access data for access to the first field device of the segment by all field devices of the segment.

6. The device according to one of the preceding claims, wherein the device is designed as a security server.

7. A field device comprising a device according to any one of the preceding claims.

8. A computer network segment comprising at least two devices according to any one of the preceding claims 1 to 6.

9. A computer network segment according to claim 8, wherein a first device of the at least two devices is implemented in the first field device and a second device of the at least two devices is implemented in the second field device.

10. A method for protecting an access for a segment in distributed systems, the method comprising the following method steps: acquiring (S1) access data for a first field device; and verifying (S2) the acquired access data from a second field device, wherein the first field device and the second field device are coupled to the segment.

11. The method according to claim 10, wherein the captured access data is used to enable access to the first field device and / or to the second field device.

12. The method of claim 11, wherein access is temporarily enabled with the captured access data.

13. A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to perform the steps of the method according to any one of claims 10 to 12.

14. A computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 10 to 12.