Method and system for the mutual checking of the integrity of a plurality of automation field devices
Patent Information
- Application Number
- EP2023817326
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-19
- Filing Date
- 2023-11-29
- Publication Date
- 2025-10-29
AI Technical Summary
The existing methods for checking the integrity of a large number of field devices in automation technology are time-consuming and costly, as they require manual manipulation of numerous adjustable parameters.
A method where field devices generate and store checksums for their parameters, allowing them to automatically and mutually verify their integrity through a communication network, detecting any changes or deviations, and triggering warnings for unauthorized changes, while also monitoring network performance patterns.
This approach simplifies the integrity check process, enabling quick detection of potential incidents and reducing manual intervention, while ensuring the integrity and security of field devices by automatically identifying unauthorized changes and maintaining system reliability.
Smart Images

Figure 1.1
Abstract
Description
[0001] Method and system for mutual verification of the integrity of a large number of field devices in automation technology
[0002] The invention relates to a method for mutually checking the integrity of a plurality of field devices in automation technology, wherein each of the field devices has at least one communication unit, wherein each of the communication units is designed to establish a communication connection to each of the other field devices via a communication network, wherein each of the field devices has a plurality of parameters which define the operation and / or the corresponding field device, and wherein each of the field devices additionally comprises an electronics unit and a memory unit.Furthermore, the invention relates to a system comprising a plurality of field devices, wherein each of the field devices has at least one communication unit, which communication unit is designed to establish a communication connection to each of the other field devices via a communication network, wherein each of the field devices has a plurality of parameters which define the operation and / or functionalities of the field device.
[0003] Field devices used in industrial plants are already known from the state of the art. Field devices are widely used in process automation technology as well as in manufacturing automation technology. Field devices essentially refer to all devices used close to the process and that provide or process-relevant information. Field devices are used to record and / or influence process variables. Measuring devices or sensors are used to record process variables. These are used, for example, for pressure and temperature measurement, conductivity measurement, flow measurement, pH measurement, level measurement, etc. and record the corresponding process variables such as pressure, temperature, conductivity, pH value, level, flow, etc. Actuators are used to influence process variables.These include, for example, pumps or valves that can influence the flow of a fluid in a pipe or the fill level in a container. In addition to the previously mentioned measuring devices and actuators, field devices also include remote I / Os, wireless adapters, and generally devices located at the field level.
[0004] A large number of such field devices are produced and distributed by the Endress+Hauser Group.
[0005] In modern industrial plants, field devices are usually connected to higher-level units via communication networks such as fieldbuses (Profibus®, Foundation® Fieldbus, HART®, etc.). These higher-level units are usually control systems (DCS) or control units, such as a PLC (programmable logic controller). The higher-level units are used, among other things, for process control, process visualization, process monitoring and for commissioning the field devices. The measured values recorded by the field devices, particularly sensors, are transmitted via the respective bus system to one (or possibly several) higher-level units. In addition, data transmission from the higher-level unit to the field devices via the bus system is also required, particularly for the configuration and parameterization of field devices and for controlling actuators.
[0006] Existing field devices already have well over one hundred adjustable parameters, and the number is increasing. Parameter manipulation, and thus the integrity testing of a field device, must be performed manually, which is a significant time and cost, especially when a large number of field devices are in use.
[0007] Based on this problem, the invention is based on the object of presenting a method which enables a simplified integrity check of field devices.
[0008] The object is achieved by a method for mutually checking the integrity of a plurality of field devices in automation technology, wherein each of the field devices has at least one communication unit, wherein each of the communication units is designed to establish a communication connection to each of the other field devices via a communication network, wherein each of the field devices has a plurality of parameters which define the operation and / or the corresponding field device, and wherein each of the field devices additionally comprises an electronic unit and a memory unit, wherein the respective electronic unit is designed to create a checksum of all parameters of the corresponding field device, and wherein the respective memory unit is designed to store the checksum of the corresponding field device and additionally the checksums of each of the other field devices,to which a communication connection can be established, comprising:
[0009] Retrieving, by means of the communication unit of a first field device from the plurality of field devices, a current checksum from at least one second field device from the plurality of field devices;
[0010] Comparing the current checksum of the second field device with the corresponding checksum stored in the electronics unit of the first field device for the second field device;
[0011] The electronics unit checks whether there is a deviation between the current checksum of the second field device and the corresponding checksum of the second field device stored in the memory unit of the first field device. According to the invention, field devices create a secure checksum (e.g., a hash value) for all parameters of the field device. Such a checksum is unique for each device configuration (and therefore collision-free). If a parameter value changes, the checksum also changes, eliminating the need to compare each individual parameter and its associated value. This checksum can be retrieved automatically by other field devices, whereby the existing system infrastructure in the form of the communication network is used for communication between the field devices.For this purpose, each device creates a list of other field devices it can reach via the communication network and stores the corresponding checksums of these accessible field devices. The list of stored checksums is checked periodically.
[0012] This type of mutual monitoring represents a decentralized IDS (Intrusion Detection System), which enables the plant operator to react quickly to a potentially dangerous incident.
[0013] Examples of field devices mentioned in the method according to the invention have already been listed in the introductory part of the description.
[0014] According to an advantageous embodiment, the method further comprises: generating a warning in the event of a deviation between the current checksum of the second field device and the corresponding checksum of the second field device stored in the memory unit of the first field device.
[0015] A parameter change is necessarily accompanied by a checksum change. Therefore, if a deviation occurs, this means that at least one parameter value has been changed. Such a change can be transmitted, for example, to a control system of the plant in which the field devices are installed. A cloud-based platform can also be considered as a destination for transmitting the warning. The warning is transmitted, in particular, by the corresponding field device that detects the deviation.
[0016] According to an advantageous embodiment of the method according to the invention, a plausibility check of the deviation is performed before the warning is generated, and the warning is only generated if the plausibility of the change cannot be successfully verified. For example, this can be done by checking whether the corresponding field device is in service mode. According to an advantageous embodiment of the method according to the invention, a plausibility check of the change is performed if a user is authorized to change the parameters on the second field device. In this case, the changes are desired and do not trigger a warning.
[0017] According to an advantageous embodiment of the method according to the invention, it is provided that the steps of retrieving and comparing are repeated at defined times, in particular at regular intervals.
[0018] According to an advantageous embodiment of the method according to the invention, if a user provides appropriate feedback to the first field device upon generation of the warning, the checksum of the second field device stored in the memory unit of the first field device is overwritten with the current checksum of the second field device. This feedback then means that the change to the parameter values is desired. In this case, the old checksum is no longer valid and would continually lead to warnings, e.g., fail to detect new, unwanted changes, which is why the stored checksum is overwritten.
[0019] According to an advantageous embodiment of the method according to the invention, when a new field device is added to the communications network, its checksum is only stored in the respective memory units of the plurality of field devices after a first defined period of time has elapsed since the addition and / or since the last change to one or more of its parameters. This prevents warning messages that would otherwise be generated due to the parameters changed during commissioning of a field device (and thus a changed checksum).
[0020] According to an advantageous embodiment of the method according to the invention, the checksums, or the corresponding additional checksums, are additionally generated via at least one piece of software located on the corresponding field devices, in particular a firmware or an application, or wherein first additional checksums, or corresponding first additional current checksums, are generated from the at least one piece of software located on the corresponding field devices, which are then compared accordingly and checked for deviations. Thus, not only unauthorized changes to the parameters of a field device, but also, for example, a changed firmware version or changes to the device applications can be automatically detected.Furthermore, the object is achieved by a system comprising a plurality of field devices, wherein each of the field devices has at least one communication unit, which communication unit is designed to establish a communication connection to each of the other field devices via a communication network, wherein each of the field devices has a plurality of parameters which define the operation and / or functionalities of the field device, and wherein each of the field devices additionally comprises:.
[0021] An electronic unit designed to create a checksum of all parameters of the corresponding field device,
[0022] A storage unit configured to store the checksum, wherein the storage unit additionally stores the checksums of each of the other field devices, wherein each of the field devices is configured to retrieve, via the corresponding communication unit, the respective current checksums of each of the field devices to which a communication connection exists, wherein the electronics unit is configured to compare the current checksums with the checksums stored in the electronics unit and to generate a first warning in the event of a deviation of one of the current checksums from the corresponding stored checksum of at least one of the field devices.
[0023] According to an advantageous embodiment of the system according to the invention, it is provided that each of the field devices is designed to detect a pattern of a network performance of each of the field devices to which a communication connection exists.
[0024] According to an advantageous embodiment of the system according to the invention, it is provided that the network performance is determined based on metadata, including, for example, packet size, number of packets, sender addresses and / or receiver addresses.
[0025] According to an advantageous embodiment of the system according to the invention, the corresponding electronic unit of the respective field devices is configured to generate a second warning if the corresponding network communication pattern deviates from a predetermined pattern by at least a defined amount. In addition to retrieving the checksums of the other field devices, this establishes a further security mechanism. This is also established by the plurality of field devices as an IDS and functions based on the same inventive concept that the field devices mutually and independently check their integrity.
[0026] According to an advantageous embodiment of the system according to the invention, it is provided that the
[0027] Field devices are designed to continuously record the network performance pattern of each of the field devices. Deviations from the known pattern can thus be detected immediately,
[0028] According to an alternative advantageous embodiment of the system according to the invention, it is provided that the field devices are designed to detect the pattern of a network performance only at defined or random times, whereby resources can be saved.
[0029] According to an advantageous embodiment, the system further comprises a higher-level unit or another network participant, in particular a PC, a gateway, or a cloud, wherein the corresponding communication units of the respective field devices are configured to transmit the first warning and / or the second warning to the higher-level unit or the other participant of the communication network. For this purpose, the transmission takes place via the communication network and / or the Internet.
[0030] According to an advantageous embodiment, the checksum target values are configured centrally from the higher-level unit, which is in particular a PC, a gateway, or a cloud, and are distributed within the mutually checking field device group. Transmission for this purpose takes place via the communications network and / or the internet.
[0031] In particular, this includes the transmission of a signal by the higher-level unit to the field device group, which indicates that the checksums currently recorded in the system are valid.
[0032] For the method according to the invention, the field device parameters are advantageously divided into a group of static parameters, for example, device settings critical for operation, and a group of dynamic parameters, for example, non-critical device settings or settings that change during normal operation, such as an operating hours counter or a setting parameter, a time display, or settings related to daylight saving time or standard time. The checksum is calculated using only the static parameters. For the purposes of this disclosure, device parameters are understood to be static parameters.
[0033] The invention is explained in more detail with reference to the following figure. It shows
[0034] Fig. 1: a schematic of an embodiment of the method according to the invention. Fig. 1 shows a plurality of field devices FG1, FG2, FGn, which are connected to a communication network KN, in particular a fieldbus (e.g. Profibus or Foundation Fieldbus, or an Ethernet-based fieldbus) via corresponding communication units KE1, KE2, KEn. Each of the field devices FG1, FG2, ..., FGn has a plurality of parameters Pn, Pn', Pn": The field device FG1 comprises the parameters P1, P2, ..., Pn; the field device FG2 comprises the parameters P1', P2', ..., Pn'; The field device FGn comprises the parameters P1", P2", ..., Pn".
[0035] The parameters Pn, Pn', Pn" define the operation of the respective field device FG1, FG2, ..., FGn and also contain security-relevant parameters, such as cryptographic keys, user authorization levels or, if applicable, access codes / passwords.
[0036] To protect against unwanted, accidental changes or deliberate manipulation of the parameters Pn, Pn', Pn", each of the field devices FG1, FG2, ..., FGn creates a current checksum PS1, PS2, ..., PSn for all parameters Pn, Pn', Pn" using a corresponding electronic unit EE1, EE2, ..., EEn. Such a checksum PS1, PS2, ..., PSn is unique for each device configuration (and therefore collision-free). If a parameter value of a parameter Pn, Pn', Pn" changes, the checksum of the corresponding field device FG1, FG2, ..., FGn also changes.
[0037] An obvious method for determining the checksum is so-called cryptographic hash functions, such as those described in the RFC 6234 standard, e.g. SHA-256 or SHA-512.
[0038] To protect against accidental and / or intentional data manipulation during transmission on the network interface between the field devices FG1, FG2, ..., FGn, the checksums for transmission are advantageously transmitted together with a cryptographic checksum calculated using the checksum PS1, PS2, ...PSn, in particular a cryptographic message authentication code (MAC) or a cryptographic signature (SIG). In this case, the receiver first checks the cryptographic checksum (MAC / SIG) for correctness before checking the checksum PS1. If the network checksum (MAC or SIG) is calculated using a counter or timestamp (TS), this also advantageously detects so-called replay attacks on the network. To enable the verification of the cryptographic network checksums, a cryptographic signature (SIG) is generated during commissioning of the field device group FG1, ...FGn is a step in which the cryptographic keys (KEYa, KEYa', KEYb, KEYb' ...., KEYm, KEYnT) required to generate and verify the network checksums (MAC / SIG) are distributed within the field device group. Examples of network checksums can be found, for example, in the Internet standards RFC 2104 and RFC 4493 (MAC) or RFC 8032 and RFC 8017 (SIG).
[0039] For example, the transmitting field device would calculate a network checksum NPS1 using a key KEYa stored there, based on the checksum PS1 and a timestamp TS1:
[0040] NPS1 = HMAC-SHA512( (PS1 , TS1), KEYa)
[0041] This network checksum is transmitted together with the data PS1 and TS1. The receiver would use a key KEYa' associated with KEYa to check the network checksum NPS1 and the timestamp TS1 for tampering during transmission before verifying the checksum PS1. In the case of message authentication codes, the same key KEYa = KEYa' is used to verify the checksum NPS1 as was used to generate it. In the case of a signature procedure, the checksum NPS1 is calculated using a private key KEYa, and the verification of NPS1 is performed using a key KEYa' that is different from the private key KEYa.
[0042] Using the corresponding communication units KE1, KE2, ..., Ken, each of the field devices FG1, FG2, ..., FGn retrieves the current checksums PS1, PS2, ..., PSn of the other field devices via the communication network KN and stores them as a list in a respective storage unit SE1, SE2, ..., SEn. This storage process can be initiated, for example, via a signal from a higher-level PC unit or alternatively via operator guidance on a locally available display / operating module.
[0043] At several points in time, the field devices FG1, FG2, ..., FGn retrieve the current checksums PS1, PS2, ..., PSn of the other field devices and compare them with the stored checksums.
[0044] This process is described below for the field devices FG1, FG2:
[0045] - The field device FG1 creates an updated checksum PS1 each time a parameter value P1, P2..., Pn changes;
[0046] - The field device FG2 periodically requests the current checksum PS1 from field device FG1;
[0047] - The FG2 field device compares the received current checksum PS1 with the stored list value. In case of a deviation, the FG2 field device generates an alert, which is transmitted, for example, to the plant's control center or to a cloud-based platform.
[0048] Before generating the warning, the second field device, FG2, can perform a plausibility check. For example, it checks whether field device FG1 was in service or maintenance mode and parameter changes were permitted, whether an authorized user made the changes, and / or whether field device FG1 was recently commissioned, making parameter changes likely. The warning is only generated if the plausibility check is successful.
[0049] Additionally, information regarding the device's software, such as firmware or applications, can be added to the checksum PS1, PS2, ..., PSn. This can also be achieved using an additional checksum, which is also stored and regularly checked by the other field devices.
[0050] By means of the method or system according to the invention, a mutual and independent integrity check of the field devices FG1, FG2, ..., FGn is possible.
[0051] The network communication of the field devices FG1, FG2, ..., FGn can also be mutually monitored in order to detect unwanted manipulation or malfunction. Several metadata relating to the network performance are collected by the individual field devices FG1, FG2, ..., FGn themselves. The metadata includes, for example, packet size, number of packets, sender addresses and / or receiver addresses. From this data, the field devices FG1, FG2, ..., FGn, or their electronic units EE1, EE2, ..., EEn, create current patterns regarding the network performance. The principle corresponds to that of the checksums PS1, PS2, ..., PSn of the parameters P1, P2, ..., Pn: If metadata changes, the pattern changes.
[0052] Analogous to the checksums PS1, PS2, ..., PSn described above, the field devices FG1, FG2, ..., FGn store the patterns of the other field devices and retrieve the current patterns of the other field devices at specified intervals and generate a warning in the event of a deviation.
[0053] EE1, EE2, EEn electronic units
[0054] FG1 , FG2, FGn Field devices of automation technology KE1 , KE2, KEn Communication units
[0055] KN Communication Network
[0056] Pn, Pn', Pn“ parameters
[0057] PS1, PS2, PSn checksums
[0058] SE1, SE2, SEn storage units
Claims
Patent claims 1 . Method for mutually checking the integrity of a plurality of field devices (FG1, FG2, FGn) of automation technology, wherein each of the field devices (FG1, FG2, FGn) has at least one communication unit (KE1, KE2, KEn), wherein each of the communication units (KE1, KE2, ..., KEn) is designed to establish a communication connection to each of the other field devices (FG1, FG2, ..., FGn) via a communication network (KN), wherein each of the field devices (FG1, FG2, ..., FGn) has a plurality of parameters (Pn, Pn', Pn") which define the operation and / or the corresponding field device (FG1, FG2, ..., FGn), and wherein each of the field devices (FG1, FG2, ..., FGn) additionally has an electronic unit (EE1, EE2, ..., EEn) and a memory unit (SE1, SE2, ..., SEn), wherein the respective electronic unit (EE1 , EE2, ..., EEn) is designed to create a checksum (PS1, PS2, ..., PSn) over all parameters (Pn, Pn', Pn") of the corresponding field device (FG1, FG2, ..., FGn), and wherein the respective storage unit (SE1, SE2, ..., SEn) is designed to store the checksum (PS1, PS2, ..., PSn) of the corresponding field device (FG1, FG2, ..., FGn) and additionally the checksums (PS1, PS2, ..., PSn) of each of the other field devices (FG1, FG2, ..., FGn) to which a communication connection can be established, comprising: Retrieving, by means of the communication unit (KE1, KE2, ..., KEn) of a first field device (FG1) from the plurality of field devices, a current checksum (PS2) from at least one second field device (FG2) from the plurality of field devices; Comparing the current checksum (PS2) of the second field device (FG2) with the corresponding checksum stored in the memory unit (EE1) of the first field device (FG1) for the second field device (FG2); Checking, by the electronic unit (EE1), whether there is a deviation between the current checksum (PS2) of the second field device (FG2) and the corresponding checksum of the second field device (FG2) stored in the memory unit (SE1) of the first field device (FG1).
2. The method according to claim 1, further comprising: Creating a warning in case of a deviation of the current checksum (PS2) of the second field device (FG2) from the corresponding checksum of the second field device (FG2) stored in the memory unit (SE1) of the first field device (FG1).
3. The method according to claim 2, wherein a plausibility check of the deviation is carried out before the warning is generated, and wherein the warning is only generated if the plausibility of the change cannot be successfully checked.
4. The method according to claim 3, wherein a plausibility of the change occurs when a user is authorized to change the parameters (Pn, Pn', Pn") on the second field device (FG2).
5. Method according to one or more of the preceding claims, wherein the steps of retrieving and comparing are repeated at defined times, in particular at regular time intervals.
6. Method according to one or more of the preceding claims, wherein, in the event that a user gives the first field device (FG1) a corresponding feedback when the warning is generated, the checksum of the second field device (FG2) stored in the memory unit (SE1) of the first field device is overwritten with the current checksum (PS2) of the second field device (FG2).
7. Method according to one or more of the preceding claims, wherein in the event that a new field device is added to the communication network (KN), its checksum (PS1, PS2, ..., PSn) is only stored in the respective memory units (SE1, SE2, ..., SEn) of the plurality of field devices (FG1, FG2, ..., FGn) after a first defined period of time has elapsed since the addition, and / or since a last change to one or more of its parameters (Pn, Pn', Pn").
8. Method according to one or more of the preceding claims, wherein the checksums (PS1, PS2, ..., PSn) are additionally formed via at least one software located on the corresponding field devices (FG1, FG2, ..., FGn), in particular a firmware or an application, or wherein the checksums (PS1, PS2, ..., PSn) are additionally formed via at least one software located on the corresponding field devices (FG1, FG2, ..., FGn). FG2, ..., FGn) software, additional current checksums are created, which are compared accordingly and checked for deviations.
9. Method according to one or more of the preceding claims, wherein cryptographic keys are stored in the memory of the field devices (FG1, ..., FGn), with which an integrity and authenticity check of the checksum information (PS1, PS2, ..., PSn) transmitted on the communication interface is carried out, in particular using cryptographic signatures (SIG) or cryptographic message authentication codes (MAC), which are generated in particular by the second field device and transmitted together with the checksum information (PS1, PS2, ..., PSn) and checked by the first field device.
10. System comprising a plurality of field devices (FG1, FG2, FGn), wherein each of the field devices (FG1, FG2, FGn) has at least one communication unit (KE1, KE2, KEn), which communication unit (KE1, KE2, ..., KEn) is designed to establish a communication connection to each of the other field devices (FG1, FG2, ..., FGn) via a communication network (KN), wherein each of the field devices (FG1, FG2, ..., FGn) has a plurality of parameters (Pn, Pn', Pn") which define the operation and / or functionalities of the respective field device (FG1, FG2, ..., FGn), and wherein each of the field devices (FG1, FG2, ..., FGn) additionally comprises: An electronic unit (EE1, EE2, ..., EEn) which is designed to create a checksum (PS1, PS2, ..., PSn) over all parameters (Pn, Pn', Pn") of the corresponding field device (FG1, FG2, ..., FGn), A memory unit (SE1, SE2, ..., SEn) which is designed to store the checksum (PS1, PS2, ..., PSn), wherein the memory unit (SE1, SE2, ..., SEn) additionally stores the checksums (PS1, PS2, ..., PSn) of each of the other field devices (FG1, FG2, ..., FGn), wherein each of the field devices (FG1, FG2, ..., FGn) is designed to retrieve the respective current checksums (PS1, PS2, ..., PSn) from each of the field devices (FG1, FG2, ..., FGn) to which a communication connection exists via the corresponding communication unit (KE1, KE2, ..., KEn), wherein the electronic unit (EE1, EE2, ..., EEn) is designed to compare the current checksums (PS1, PS2, ..., PSn) with the checksums stored in the electronic unit (EE1, EE2, ..., EEn) stored checksums (PS1, PS2, ..., PSn) and in case of a deviation of one of the current checksums (PS1, PS2, ..., PSn) from the corresponding stored checksum (PS1, PS2, ..., PSn) of at least one of the field devices (FG1, FG2, ..., FGn) to create a first warning.
11. The system of claim 10, wherein each of the field devices (FG1, FG2, ..., FGn) is configured to capture a pattern of network performance of each of the field devices (FG1, FG2, ..., FGn) to which a communication connection exists.
12. The system of claim 11, wherein the network performance is determined based on metadata, including, for example, packet size, packet count, sender addresses and / or receiver addresses.
13. System according to claim 11 or 12, wherein the corresponding electronic unit (EE1, EE2, ..., EEn) of the respective field devices (FG1, FG2, ..., FGn) is designed to generate a second warning in the event that the corresponding pattern of the network communication deviates from a predetermined pattern by at least a defined amount.
14. System according to one or more of claims 11 to 13, wherein the field devices (FG1, FG2, ..., FGn) are configured to continuously record the pattern of a network performance of each of the field devices (FG1, FG2, ..., FGn).
15. System according to one or more of claims 11 to 13, wherein the field devices (FG1. FG2, ..., FGn) are designed to capture the pattern of a network performance only at defined or random points in time.
16. System according to one or more of claims 10 to 15, additionally comprising a higher-level unit or a further network participant, in particular a PC, a gateway or a cloud, wherein the corresponding communication units (KE1, KE2, ..., KEn) of the respective field devices (FG1, FG2, ..., FGn) are designed to transmit the first warning and / or the second warning to the higher-level unit or the further participant of the communication network (KN).
17. System according to one or more of claims 10 to 16, wherein cryptographic keys are stored in the memory of the devices of the field device group (FG1, ..., FGn), with which an integrity and authenticity check of the checksum information (PS1, PS2, ..., PSn) transmitted on the communication interface is carried out, in particular using cryptographic signatures (SIG) or cryptographic message authentication codes (MAC), which are generated in particular by the second field device and transmitted together with the checksum information (PS1, PS2, ..., PSn) and checked by the first field device.