Method and system for documenting logbook data by one or more first field devices

EP4619836A1Pending Publication Date: 2025-09-24ENDRESS HAUSER PROCESS SOLUTIONS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023793822
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-17
Filing Date
2023-10-20
Publication Date
2025-09-24

AI Technical Summary

Technical Problem

Resource-poor field devices in industrial systems face challenges in securely archiving logbook data due to limited storage capacity and slow communication interfaces, making it difficult to transmit and store safety-relevant data over extended periods without risking manipulation or exceeding device resources.

Method used

A method where logbook data from resource-constrained first field devices is continuously transmitted to a second field device with greater resources, which aggregates, secures, and stores the data, using authenticated and encrypted communication, and provides additional protection through checksums and secure key management, enabling secure archiving and analysis.

Benefits of technology

This solution ensures secure, tamper-proof storage and transmission of logbook data, overcoming storage and bandwidth limitations in resource-poor devices, while ensuring long-term security and integrity of safety-critical information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a method for documenting logbook data (LD1, LD1') by one or more first field devices (FG1, FG1'), wherein each of the first field devices (FG1, FG1') has a first resource power, wherein a second field device (FG2) is provided with a second resource power, wherein the second resource power is greater than each of the first resource powers, wherein each of the first field devices (FG1, FG1') continuously generates corresponding logbook data (LD1, LD1'), wherein the logbook data (LD1, LD1') contain safety-relevant data and / or data relating to the operation of the corresponding first field device (FG1, FG1'), said method comprising: - establishing a secure communication link between one or more of the first field devices (FG1, FG1') and the second field device (FG2); - transmitting the current logbook data (LD1, LD1') from the first field device (FG1, FG1') or each of the first field devices at intended times via the communication link; - accumulating the current logbook data (LD1, LD1') by the second field device (FG2) and storing the accumulated logbook data (LD1, LD1') in a memory unit (SE2) of the second field device (FG2), and a corresponding system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method and system for documenting logbook data from one or more first field devices

[0002] The invention relates to a method for documenting logbook data from one or more first field devices, wherein each of the first field devices has a first resource capacity, wherein a second field device is provided with a second resource capacity, wherein the second resource capacity is greater than each of the first resource capacities, wherein each of the first field devices continuously generates corresponding logbook data, wherein the logbook data contains, in particular, safety-relevant data and / or data relating to the operation of the respective first field device. Furthermore, the invention relates to a system comprising one or more first field devices of automation technology and a second field device of automation technology.

[0003] Field devices used in industrial plants are already known from the state of the art. Field devices are widely used in process automation technology as well as in manufacturing automation technology. Field devices essentially refer to all devices used close to the process and that provide or process-relevant information. Field devices are used to record and / or influence process variables. Measuring devices or sensors are used to record process variables. These are used, for example, for pressure and temperature measurement, conductivity measurement, flow measurement, pH measurement, level measurement, etc. and record the corresponding process variables such as pressure, temperature, conductivity, pH value, level, flow, etc. Actuators are used to influence process variables.These include, for example, pumps or valves that can influence the flow of a fluid in a pipe or the fill level in a container. In addition to the previously mentioned measuring devices and actuators, field devices also include remote I / Os, wireless adapters, and generally devices located at the field level.

[0004] Many applications in which the field devices described above are used are characterized by increased safety requirements. Examples include the pharmaceutical industry or critical infrastructure, such as nuclear power plants or drinking water supplies. One of the key tasks in these areas is the reliable verification and documentation of the plant's condition, a so-called "audit trail," which can be used, for example, to subsequently trace the plant's condition and changes in operating settings during the production of a drug batch. A large number of such field devices are manufactured and distributed by the Endress+Hauser Group.

[0005] In modern industrial plants, field devices are typically connected to higher-level units via communication networks such as fieldbuses (Profibus®, Foundation® Fieldbus, HART®, etc.). Interfaces with inherent network capability, e.g., based on Internet protocols, are used only in exceptional cases. Recently, field devices have also increasingly been equipped with short-range wireless systems, such as Bluetooth or the IEEE 802.15.4 standard. For the purposes of this disclosure, a distinction is made between network-capable Wide Area Network (WAN) communication interfaces (e.g., based on Internet protocols) and local communication interfaces (e.g., short-range wireless or traditional fieldbus systems without network data transmission).

[0006] Typically, the higher-level units are control systems (DCS) or control units, such as a PLC (programmable logic controller), which generally do not allow a WAN data connection to field devices. These higher-level units are used, among other things, for process control, process visualization, process monitoring, and commissioning of field devices. The interfaces and interface protocols are generally not necessarily network-capable. For security reasons, security-relevant networks, in particular, are deliberately separated from wide-area networks such as the Internet to prevent external attacks.

[0007] The measured values ​​recorded by the field devices, especially sensors, are transmitted via the respective bus system to one (or possibly several) higher-level units. In addition, data transmission from the higher-level unit to the field devices via the bus system is also required, particularly for configuring and parameterizing field devices and controlling actuators.

[0008] There is a growing need for field devices to be protected against tampering, in addition to the need for "safety." A key component of this is the secure and tamper-proof storage of device information in logbooks.

[0009] With regard to the data to be securely archived, the following aspects are important: tamper-proof storage, which, for example, prevents subsequent manipulation of crucial information in the event of a malfunction; the required readout time for data transmission, or the transmission speed available on a communication interface; and the size of a persistent memory required for archiving.

[0010] In the run-up to an attack, it is unclear which information needs to be monitored for later analysis and at what point in time relevant data will be needed at a later point in time. Therefore, it is desirable to continuously, comprehensively, and permanently monitor the device status. However, this can result in very large amounts of data being generated over operating periods of up to several years. These data volumes can become problematic in that the storage capacity exceeds the resources of a device. On the other hand, even with a large amount of memory available in a device, the transmission speed on the interfaces can become a limiting factor if, for example, the transmission of log contents takes several hours.

[0011] These aspects pose technical challenges for many field devices, especially small, low-cost ones, because they, for example, only have low-speed communication interfaces and / or small memory sizes. With regard to long-term tamper resistance, the risk of compromise of the cryptographic keys used to secure logbook contents must also be considered, especially if the field device does not have special security chipsets (so-called "secure elements") that allow, for example, keys for secure checksums / signatures to be stored in a read-proof manner and cryptographic calculations to be performed with side-channel protection. Without such specialized security chipsets, it may not be possible to ensure that the risk of compromised keys can be controlled even when using keys with long validity periods (English: "long-term keys").

[0012] Server solutions for archiving data, e.g., on a PC in a server rack in a data center, are known in the state of the art. However, these solutions are often not suitable for industrial use because WAN network connections to field devices are not permitted due to a so-called "wire gap" to prevent external attacks, or because the fieldbus interfaces do not support external network connections to a logbook archiving server in a data center.

[0013] Key-based checksum methods for securing data are also known. Based on the keys used, a distinction can be made between symmetric checksums (e.g., HMAC-SHA256, so-called "keyed hashes," or message authentication codes) and asymmetric checksums or signatures (e.g., ECDSA, EdDSA). Symmetric checksums are both generated and verified with the same symmetric key, while asymmetric checksums use a private key of a key pair for generation and a public key for verification.

[0014] For the purposes of this disclosure, it is relevant that the computing power required to generate an asymmetric checksum (signature) may exceed the computing resources of a small field device. This applies in particular to so-called "post-quantum" algorithms, which cannot be broken cryptoanalytically even with the help of quantum computers that may become available in the future. New security standards are currently being developed for this purpose. These meet increased requirements but have increased computing power and memory requirements compared to previous methods (particularly those based on the RSA method or elliptic curves). Examples of such post-quantum algorithms are hash-based signatures, code-based methods such as McElice, isogeny methods on elliptic curves, and methods based on discrete lattices. Competitions for this are currently underway at, among others, the American NIST standards authority.

[0015] Often, particularly critical system components are intentionally installed in completely separate subnets that, for example, do not allow a direct network data connection to a server room due to the lack of a physical cable connection. Locally within the subnet, communication may only be possible between field devices and each other, but not with external server components. In the case of field devices with short-range radio (such as Bluetooth), this may enable a data connection between field devices installed locally in a system component, for example, from one field device to a neighboring field device. However, due to the distance, direct radio communication with a system control center in the server room is not possible.

[0016] Fieldbus and wireless data connections that provide local networking over short distances generally also differ from conventional WAN networks in terms of quality characteristics, such as availability and maximum downtimes during maintenance or software updates, as are increasingly being prepared using long-distance wireless connections via mobile networks (e.g., according to the so-called 4G and 5G standards). It is important to note that local data communication from one field device to a neighboring field device can generally be considered more reliable than a connection to servers, which requires the use of WAN networks.

[0017] Many plant operators today define security policies (e.g., designed as a zone concept) in which field devices are not permitted direct access outside the automation system or subsystem (or its assigned zone). However, low-performance devices must still store their security-relevant data (e.g., information about user logins, change histories, etc.) and / or intellectual property information (e.g., process-related sensor measurement data, sensor sample data, sensor curves, etc.) in a secure, auditable and traceable storage. One possible security concept for connecting a local network to a WAN network involves the use of a so-called data diode, which allows information to be sent only unidirectionally from the local network to the WAN, but cannot receive data from the WAN network.

[0018] It should also be taken into account that, for cost reasons, only limited resources can be reserved for simple sensors (e.g. a cost-optimized temperature sensor reduced to basic functionality).

[0019] Based on this problem, the invention is based on the object of presenting a method which enables secure archiving of logbook data in systems, even involving field devices with low resource requirements.

[0020] The object is achieved by a method for documenting logbook data from one or more first field devices, each of the first field devices having a first resource capacity, a second field device being provided with a second resource capacity, the second resource capacity being greater than each of the first resource capacities, each of the first field devices continuously generating corresponding logbook data, the logbook data containing safety-relevant data and / or data relating to the operation of the respective first field device, comprising:

[0021] Establishing a secure, i.e. authenticated, integrity-checked and, if applicable, encrypted communication connection between one or more of the first field devices and the second field device;

[0022] Transmitting the current logbook data from the first field device or the respective first field devices continuously or at scheduled times via the communication connection;

[0023] Accumulating the current logbook data by the second field device and storing the accumulated logbook data in a storage unit of the second field device.

[0024] According to the invention, the logbook data of lower-resource first field devices is continuously transmitted during operation to a higher-resource second field device. This second field device continuously aggregates and collects the logbook data in its, in particular persistent, memory and makes it available to a user for analysis as needed. In this case, the first field devices have, in particular, communication interfaces that enable significantly slower data communication compared to the communication interfaces of the second field device.However, since the amount of logbook data to be transmitted from the first field devices is relatively small, for example approximately 1 kByte per minute, the communication interfaces usually present in the first field devices are sufficient to transmit the logbook data to the second field device - however, the amount of data of 500 megabytes that accumulates in this case over the course of, for example, one year could neither be stored in the first field devices nor read out via their slower communication interfaces.

[0025] Examples of field devices mentioned in connection with the method according to the invention have been listed in the introductory part of the description.

[0026] The term “safety” in the context of this invention includes both the dimension of operational safety in the sense of the English term “safety” and security with regard to accidental or intentional manipulation (English “security”).

[0027] For the purposes of this application, the term “resource performance” is understood to mean the summary of the characteristics of a limited capacity of a persistent data storage device (e.g. EEPROM or flash memory module) and / or the limited capacity of the available communication interfaces and / or the available computing power and / or the ability to store cryptographic key information in a read-safe manner over a longer period of time.

[0028] The first field devices are resource-limited field devices, which are, for example, temperature transmitters, which are equipped with a HART fieldbus (nominal communication bandwidth in the order of approximately 50 bytes per second transmission speed) or a Bluetooth Low Energy interface (possibly in the order of approximately 200 bytes per second transmission speed), which are typically operated by a 12 volt power supply at 3.5 mA current.

[0029] Compared to the first field devices, the second field device is a more resource-efficient field device, particularly one with larger memory capacity, faster communication interfaces, and / or a more powerful power supply. The second field device is particularly suitable for the integration of secure chipsets (so-called "Secure Elements", SE). Examples of such second field devices include "recorder" devices or larger flowmeters, which, for example, are powered by a 230 V or 24 V power supply with a power of, for example, 20 W and, in addition to slower Bluetooth Low Energy or HART communication interfaces, may also have fast WLAN or Ethernet interfaces. Advantageously, the following further steps are provided:

[0030] Additional protection of the accumulated logbook data using the means of the second field device (e.g. additional checksums generated by the second field device);

[0031] Secure provision of the accumulated logbook data by the second field device to an authorized evaluation unit or to a user; and checking the logbook data (e.g., against manipulation).

[0032] One embodiment of the method provides for the secure communication connection to be implemented using a key. A symmetric key pair is used to establish a secure communication connection between the first and second field devices, with this key being located on both field devices.

[0033] Alternatively, an asymmetric key pair consisting of a private key and a public key is used to establish a secure communication connection, whereby the private key of the respective symmetric key pair is located on the corresponding field device and the public key of the symmetric key pair is located on the communication partner.

[0034] It may be intended to establish the basis of trust for establishing the communication connection (i.e. which public keys are trustworthy) by using a public key infrastructure.

[0035] Various methods for establishing a secure connection are known from the state of the art (for example, according to the TLS standard), whereby the security usually initially comprises a one- or two-sided authenticity check of the communication partners on the basis of the above-mentioned symmetric or asymmetric key information, and subsequently, if successful, the negotiation of a session key.

[0036] In an advantageous embodiment of the method, each of the first field devices provides its current logbook data with a checksum before transmitting it to the second field device. This checksum is calculated from the current logbook data and optionally an additional key. Advantageously, however, the second field device only aggregates the received current logbook data from the corresponding first field devices if the checksum can be successfully verified. In an advantageous embodiment of the method, the logbook data then also located in the memory unit of the second field device is provided with an additional second checksum by the second field device.The advantage of this second checksum is that the second field device can use better protected keys (for example when using a "secure element" chipset) or better protected, more computationally intensive methods, which may not be possible due to the limited resources of the first field device.

[0037] In an advantageous embodiment of the method, it is provided that the logbook data located in the memory unit of the second field device is output to a user by the second field device or retrieved by a user from the second field device. In particular, the logbook data located in the memory unit of the second field device can only be output to the user or retrieved by the user if the user has successfully authenticated themselves to the second field device and / or if the user has a correct user role. The output can be carried out, for example, using storage media (e.g., a USB stick or similar) or using communication interfaces of the second field device.

[0038] The term “user” refers to both a human user and an electronic entity, such as a plant control center.

[0039] In an advantageous embodiment, the second field device, which is temporarily or permanently connected to a WAN network and, when a WAN connection is available, transmits the accumulated logbook data securely (i.e., after authentication and / or integrity-checked and encrypted) to a server application, for example, upon request or in a preconfigured time frame. This communication advantageously takes place via a unidirectional telegram in order to also be able to work with WAN connections with a "data diode" provided for security reasons. This can be achieved, for example, by the logbook data being cryptographically signed by the transmitted field device and the receiver implementing a signature verification. Such a method also enables alternative unidirectional data connections, for example, using USB sticks or SD cards as data storage devices.

[0040] Advantageously, the signature can be generated and verified using a private / public key pair. The advantage of an asymmetric signature is that the receiving server and the field device both only require access to a common certificate-issuing certificate authority of a PKI, and otherwise, unidirectional communication from the field device to a central server is sufficient. Furthermore, the object is achieved by a system comprising one or more first field devices of automation technology and a second field device of automation technology, wherein each of the first field devices is integrated into an automation network via a corresponding first communication interface and is designed to acquire measured variables relating to a process and transmit them via the automation network and / or to receive control variables relating to the process.wherein each of the first field devices has a first resource capacity, wherein the second field device has a second resource capacity, wherein the second resource capacity is greater than each of the first resource capacities, wherein each of the first field devices is configured to continuously generate logbook data, wherein the logbook data contains safety-relevant data and / or data relating to the operation of the respective first field device, establishing a communication connection between one or more of the first field devices and the second field device, wherein each of the first field devices is configured to transmit its current logbook data to the second field device at predetermined times via a secure communication connection established via the first communication interface via the automation network or via a second communication interface of the respective first field devices via a further network,wherein the second field device is configured to accumulate the current logbook data and to store the accumulated logbook data in a storage unit, in particular a persistent memory, of the second field device.

[0041] In an advantageous embodiment of the system, it is provided that the second field device is designed to create its own logbook data, to accumulate it and to store it in the storage unit at regular intervals.

[0042] In an advantageous embodiment of the system, the second field device is also part of the automation network and is configured to acquire measured variables relating to a process and transmit them via the automation network and / or receive control variables relating to the process. In this case, the functionalities of receiving the current logbook data of the respective first field devices, accumulating the received current logbook data, and storing the received logbook data can be implemented by an additional module connected to the second field device.

[0043] In an alternative embodiment of the system, the second field device is a network device, in particular a gateway, switch, or edge device, a control unit, or a PC. An advantageous embodiment of the system additionally comprises a cloud-based platform, wherein the second field device is configured to transmit the accumulated logbook data contained in the storage unit to the cloud-based platform, in particular via the Internet. A cloud-based platform is a server or server system contactable via a WAN network, on which one or more applications can run, for example, allowing the storage and / or processing of the logbook data.

[0044] The invention is explained in more detail with reference to the following figure. It shows

[0045] Fig. 1 : an embodiment of the method according to the invention.

[0046] Fig. 1 shows an automation network AN. This automation network AN includes two first field devices FG1, FG1', and a second field device FG2. Of course, in addition to these field devices FG1, FG1', FG2, a variety of other field devices can be integrated into the automation network AN. The first field devices FG1, FG1' are, for example, measuring devices for recording process variables of a manufacturing process. The second field device FG2 is, for example, a data recorder, a network device, in particular a gateway, switch or edge device, a control unit, or a PC.

[0047] Each of the field devices FG1, FG1', FG2 has resources in the form of at least one electronic unit EE1, EE1', EE2, at least one communication interface KS1, KS1', KS2 and at least one memory unit SE1, SE1', SE2.

[0048] The resource performance of the second field device FG2 is higher than that of the first field devices FG1, FG1'. This means that at least one of the resources of the second field device FG2 has a higher performance than the corresponding resource of the respective first field device FG1, FG1'. For example, in the case of a memory unit, higher performance means that more storage space is available. For example, in the case of an electronic unit, higher performance means that it has higher computing power. For example, in the case of a communication interface, higher performance means that it can receive and send a higher data rate. For example, in the case of a key memory, higher performance means that it has a higher degree of readout protection.

[0049] Each of the field devices FG1, FG1', FG2 continuously collects logbook data LD1, LD1', LD2. This logbook data LD1, LD1', LD2 contains, among other things, safety-relevant data (e.g. configuration or user information) and / or data relating to the operation of the respective field device FG1, FG1', FG2, for example operating hours or similar. The logbook data is saved in the corresponding memory units SE1, SE1', SE2 of the respective field devices FG1, FG1', FG2. Although the memory requirement for each generated logbook data LD1, LD1', LD2 is not too large (e.g. 10 kilobytes), the continuous generation (e.g. every minute) results in a volume of data that cannot be stored on the memory units SE1, SE1' of the first field devices FG1, FG1'. Reading this amount of data from the first field devices FG1, FG1' is only possible with restrictions due to their slow communication interfaces KS1, KS1'.

[0050] The first field devices FG1, FG1' are therefore designed such that the logbook data LD1, LD1' is continuously transmitted to the second field device FG2. For this purpose, a secure communication connection is established between the respective first field devices FG1, FG1' and the second field device FG2 via the automation network AN. If the first field devices FG1, FG1' have additional communication interfaces (e.g., wired or wireless) in addition to the communication interface used for connecting to the automation network AN, it is also possible to establish the communication connection for the logbook data via these interfaces (and not using the automation network AN).

[0051] For a secure communication connection, the communication connection is authenticated and, if necessary, encrypted using a key-based trust relationship between the second field device FG2 and the corresponding first field device FG1, FG1'. The trust relationship can be based on a symmetric key known to both sides. Alternatively, the trust relationship can be based on two asymmetric key pairs, with each communication partner being given the public key as well as their own private key. A checksum can also be appended to the log data LD1, LD1', whereby the second field device FG2 only accepts the received log data LD1, LD1' if the checksum is plausible.

[0052] The advantage of using asymmetric keys is that the administrative effort can be reduced by using a so-called public key infrastructure, in which a certificate issuing authority confirms the trustworthiness of communication partners with a public key PKa via an associated certificate signed by the certificate issuing authority. When using such a PKI, the trust between the communication partners can be traced back to a certificate issuing authority that is jointly recognized as trustworthy. The volume of logbook data LD1, LD1' to be transmitted is so small that this task can be easily performed by the communication interfaces KS1, KS1' of the corresponding first field devices FG1, FG1'. The second field device FG2 receives the corresponding logbook data LD1, LD1', aggregates it, and stores it in its storage unit SE2.The second field device FG2 can also generate its own logbook data LD2, which is then additionally stored in the storage unit SE2. The storage unit SE2 of the second field device FG2 is so large that the logbook data LD1, LD1' can be stored for an extended period of time. Furthermore, the field device FG2 can provide the logbook data LD1, LD1' with a checksum based on the key information stored in the FG2. The advantage of this is that the field device FG2 can better protect the keys used for this purpose against readout (using special secure element chipsets) or can use more computationally intensive but better protected methods (e.g., post-quantum algorithms).

[0053] For the secure communication connection for the exchange of logbook data LD1 , LD1 ' between field device FG1 , FG1 ' and FG2, various procedures can be used:

[0054] In a first embodiment, the exchange occurs by establishing a secure connection in the sense of a cryptographically secured end-to-end connection (for example, using the TLS protocol) between FG1, FG1', and FG2, in which the logbook data LD1, LD1' is subsequently transmitted. In this embodiment, the data integrity check by the field device FG2 is based on the protection provided by the end-to-end connection, the key negotiated for this connection, and the integrity check of the transmitted payload data integrated into the end-to-end connection.

[0055] In an alternative embodiment, the field device FG1, FG1 ', first adds a first checksum to the log data, for example, based on a symmetric key stored there (e.g., the secret-key algorithm HMAC-SHA256 according to RFC4688), and transmits this to the field device FG2, possibly without using end-to-end encryption and without additional protection. In this case, the integrity check is performed by the field device FG2 by checking the first checksum.

[0056] It is important that the field device FG2 only aggregates data in its storage unit SE2 if the test is completed successfully.

[0057] The logbook data LD1, LD1', LD2 stored in this way in the second field device can be retrieved by a user (e.g., via a control unit that communicates wirelessly or wired with the second field device FG2). It can also be provided that the second field device FG2 transmits the logbook data, at user initiative, at regular intervals and / or at predetermined times via the internet (or a similar suitable connection), to a cloud-based platform CP.

[0058] List of reference symbols

[0059] AN automation network

[0060] CP cloud-based platform EE1.EE1 1 , EE2 electronic units

[0061] FG1, FG1', FG2 field devices

[0062] KS1, KS1', KS2 communication interfaces

[0063] LD1, LD1', LD2 logbook data

[0064] SE1, SE1', SE2 storage units

Claims

Patent claims 1. A method for documenting logbook data (LD1, LD1') from one or more first field devices (FG1, FG1'), wherein each of the first field devices (FG1, FG1') has a first resource capacity, wherein a second field device (FG2) is provided with a second resource capacity, wherein the second resource capacity is greater than each of the first resource capacities, wherein each of the first field devices (FG1, FG1') continuously generates corresponding logbook data (LD1, LD1'), wherein the logbook data (LD1, LD1') contain in particular safety-relevant data and / or data relating to the operation of the respective first field device (FG1, FG1'), comprising: Establishing a secure communication connection between one or more of the first field devices (FG1, FG1') and the second field device (FG2); transmitting the current logbook data (LD1, LD1') from the first field device (FG1, FG1') or the respective first field devices continuously or at scheduled times via the communication connection; Accumulating the current logbook data (LD1, LD1') by the second field device (FG2) and storing the accumulated logbook data (LD1, LD1') in a storage unit (SE2) of the second field device (FG2).

2. The method according to claim 1, wherein the secure communication connection is implemented key-based.

3. The method according to claim 2, wherein a symmetric key pair is used for the secure communication connection for each first field device (FG1, FG1'), wherein one of the keys of the respective symmetric key pair is located on the corresponding first field device (FG1, FG1') and the other key of the symmetric key pair is located on the second field device (FG2).

4. The method according to claim 2, wherein for the secure communication connection, an asymmetric key pair consisting of a private key and a public key is used for each first field device (FG1, FG1'), wherein the private key of the respective symmetric key pair is located on the corresponding first field device (FG1, FG1') and the public key of the symmetric key pair is located on the second field device (FG2).

5. The method according to any one of claims 2 to 4, wherein the secure communication connection is established by using a public key infrastructure.

6. Method according to one or more of the preceding claims, wherein each of the first field devices (FG1, FG1') provides its current logbook data (LD1, LD1') with a checksum before transmitting it to the second field device (FG2), which checksum is calculated from the current logbook data (LD1, LD1').

7. The method according to claim 6, wherein the second field device (FG2) aggregates the received current logbook data (LD1, LD1') of the corresponding first field devices (FG1, FG1') only if the checksum can be successfully verified.

8. Method according to one or more of the preceding claims, wherein the logbook data (LD1, LD1', LD2) located in the memory unit (SE2) of the second field device (FG2) are output by the second field device (FG2) to a user or are retrieved by a user from the second field device (FG2).

9. The method according to claim 8, wherein the logbook data (LD1, LD1', LD2) located in the memory unit (SE2) of the second field device (FG2) can only be output to the user or retrieved by the user if the user successfully authenticates himself to the second field device (FG2) and / or if the user has a correct user role.

10. Method according to one or more of the preceding claims, wherein the logbook data (LD1, LD1', LD2) located in the memory unit of the second field device (FG2) are provided with an additional second checksum by the second field device (FG2).

11. Method according to one or more of the preceding claims, wherein the logbook data (LD1, LD1', LD2) located in the memory unit (SE2) of the second field device (FG2) are output from the second field device (FG2) to a cloud-based platform (CP), wherein the field device FG2 and the cloud-based platform (CP) mutually authenticate each other with the aid of key information (FG2).

12. System comprising one or more first field devices (FG1, FG1') of the automation technology and a second field device (FG2) of the automation technology, wherein each of the first field devices (FG1, FG1') is integrated in an automation network (AN) via a corresponding first communication interface (KS1, KS1') and is designed to record measured variables relating to a process and to transmit them via the automation network (AN) and / or to receive control variables relating to the process engineering process, wherein each of the first field devices (FG1, FG1') each has a first resource capacity, wherein the second field device (FG2) has a second resource capacity, wherein the second resource capacity is greater than each of the first resource capacities, wherein each of the first field devices (FG1, FG1') is designed to continuously generate logbook data (LD1, LD1'), wherein the logbook data (LD1, LD1') contain safety-relevant data and / or data relating to the operation of the respective first field device (FG1, FG1'), wherein each of the first field devices (FG1, FG1') is designed to transmit its current logbook data (LD1, LD1') via a secure communication connection, which is transmitted via the first communication interface (KS1, KS1') via the automation network (AN) or via a second communication interface of the respective first field devices (FG1,FG1') is established via a further network, continuously or at predetermined times to the second field device (FG2), wherein the second field device (FG2) is configured to accumulate the current logbook data (LD1, LD1') and to store the accumulated logbook data (LD1, LD1') in a storage unit (SE2), in particular a persistent memory, of the second field device (FG2). System according to claim 12, wherein the second field device (FG2) is configured to create its own logbook data (LD2), to accumulate it, and to store it at regular intervals in the storage unit (SE2). System according to claim 12 or 13, wherein the second field device (FG2) is also part of the automation network (AN) and is configured toTo record measured variables relating to a process engineering process and transmit them via the automation network (AN) and / or to receive control variables relating to the process engineering process. The system according to claim 14, wherein the functionalities of receiving the current logbook data (LD1, LD1') of the respective first field devices (FG1, FG1'), accumulating the received current logbook data (LD1, LD1'), and storing the received logbook data (LD1, LD1') are implemented by an additional module, which additional module is connected to the second field device (FG2). The system according to claim 12 or 13, wherein the second field device (FG2) is a network device, in particular a gateway, switch, or edge device, a control unit, or a PC. System according to one or more of claims 12 to 16, further comprising a cloud-based platform (CP), wherein the second field device (FG2) is designed to transmit the accumulated logbook data (LD1, LD1', LD2) contained in the storage unit (SE2) to the cloud-based platform (CP), in particular via the Internet.