Method and system for authorizung an operating action sent from a first field device to a second field device

EP4732168A1Pending Publication Date: 2026-04-29ENDRESS HAUSER PROCESS SOLUTIONS AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
ENDRESS HAUSER PROCESS SOLUTIONS AG
Filing Date
2024-06-04
Publication Date
2026-04-29

AI Technical Summary

Technical Problem

The increasing complexity of field devices in industrial systems leads to a higher risk of errors and security vulnerabilities, particularly during subcomponent installation and maintenance, as there is no guaranteed authorization of trained personnel and lack of traceability for changes, making systems susceptible to attacks and inconsistencies.

Method used

A method and system that utilize security elements with logic and identification information for each subcomponent to authenticate, authorize, and validate distributed operations between field devices, ensuring secure communication and logging of actions through public and private key systems, and defining permitted actions within a set of rules.

Benefits of technology

This approach enhances the security and traceability of subcomponent changes, preventing unauthorized actions and ensuring only permitted operations are executed, thereby reducing the risk of errors and attacks while maintaining a record of all changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024065302_26122024_PF_FP_ABST
    Figure EP2024065302_26122024_PF_FP_ABST
Patent Text Reader

Abstract

The invention comprises a method for authorizing an operating action sent from a first field device (FG1) to a second field device (FG2), wherein the first field device (FG1) comprises at least one first subcomponent (SK1), wherein the first subcomponent (SK1) is configured to enable the first field device (FG1) to perform at least one additional functionality, wherein the first subcomponent (SK1) has a first security element (SE1), wherein a first logic element (LE1) and first identification information (ID1) are stored in the first security element (SE1), wherein the second field device (FG2) is communicatively connected to the first field device (FG1) via a communication network (KN) and comprises at least one second subcomponent (SK2), wherein the second subcomponent (SK2) is configured to enable the second field device (FG2) to perform at least one additional functionality, wherein the second subcomponent (SK2) has a second security element (SE2), wherein a second logic element (LE2) and second identification information (ID2) are stored in the second security element (SE2), comprising: - an operator initiating an operating action on the first field device (FG1), wherein the operating action relates to the second subcomponent (SK2) on the second field device (FG2); - checking the operating action by way of the second logic element (LE2); and - authorizing the operating action if successfully checked by the second logic element (LE2).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method and system for authorizing an operating action sent from a first field device to a second field device

[0002] The invention relates to a method for authorizing an operator action sent from a first field device to a second field device. Furthermore, the invention relates to a system.

[0003] Field devices used in industrial plants are already known from the state of the art. Field devices are widely used in process automation technology as well as in manufacturing automation technology. In principle, field devices are all devices that are used close to the process and that provide or process-relevant information. Field devices are used to record and / or influence process variables. Measuring devices or sensors are used to record process variables. These are used, for example, for pressure and temperature measurement, conductivity measurement, flow measurement, pH measurement, level measurement, etc. and record the corresponding process variables pressure, temperature, conductivity, pH value, level, flow, etc. Actuators are used to influence process variables.These include, for example, pumps or valves that can influence the flow of a fluid in a pipe or the fill level in a container. In addition to the previously mentioned measuring devices and actuators, field devices also include remote I / Os, wireless adapters, and generally devices located at the field level.

[0004] A large number of such field devices are produced and distributed by the Endress+Hauser Group.

[0005] In modern industrial plants, field devices are usually connected to higher-level units via communication networks such as fieldbuses (Profibus®, Foundation® Fieldbus, HART®, etc.). These higher-level units are usually control systems (DCS) or control units, such as a PLC (programmable logic controller). The higher-level units are used, among other things, for process control, process visualization, process monitoring and for commissioning the field devices. The measured values ​​recorded by the field devices, particularly sensors, are transmitted via the respective bus system to one (or possibly several) higher-level units. In addition, data transmission from the higher-level unit to the field devices via the bus system is also required, particularly for the configuration and parameterization of field devices and for controlling actuators.

[0006] The complexity of process automation systems is constantly increasing. More and more system components and field devices are being interconnected.

[0007] But the field devices themselves are also increasing in complexity and software options (especially ordering options / activation codes for functions). This means that field devices often consist of a multitude of subcomponents. These subcomponents are often designed as hardware modules, for example, as plug-in cards, especially for WLAN modules or IO cards, and define important, often safety-relevant information or functions of a field device. In some cases, these subcomponents even need to be modified during the process or during service.

[0008] Subcomponents can alternatively or additionally be implemented as software. Such software (e.g., heartbeat or custody transfer functionalities) can be available as an option for the field device and can be dynamically combined / recombined in the field. Upon purchase of such an option, a special activation code can be delivered. After entering the activation code in the field device, the software-based subcomponent is available.

[0009] With this increasing complexity comes an increasing risk of errors and security attacks.

[0010] Furthermore, errors can occur when switching subcomponents during the product lifecycle, especially during the installation and maintenance phase. There is no guarantee that only trained and authorized personnel can install or replace subcomponents. Furthermore, there is no information about who installed or modified a subcomponent, with what rights, and at what time, which complicates traceability and poses a security risk.

[0011] Attackers could exploit these described vulnerabilities in a variety of ways, for example, through spoofing or denial of service attacks, by injecting malware, etc. Incorrect software modules could also be ordered and activated, which could lead to inconsistencies.

[0012] Based on this problem, the invention is based on the object of presenting a method which enables subcomponents of a field device to be changed in a secure manner.

[0013] The object is achieved by a method according to claim 1 and by a system according to claim 12.

[0014] With regard to the method, it is provided that the method serves to authorize an operating action sent from a first field device to a second field device, wherein the first field device comprises at least one first subcomponent, wherein the first subcomponent is designed to enable the first field device to execute at least one additional functionality, wherein the first subcomponent has a first security element, wherein a first logic element and first identification information are stored in the first security element, wherein the second field device is in communication connection with the first field device via a communication network and comprises at least one second subcomponent, wherein the second subcomponent is designed to enable the second field device to execute at least one additional functionality, wherein the second subcomponent has a second security element,wherein a second logic element and a second identification information are stored in the second security element, comprising:

[0015] - initiating an operating action by an operator on the first field device, wherein the operating action affects the second subcomponent on the second field device;

[0016] - Checking the operating action by the second logic element; and authorizing the operating action in case of successful checking by the second logic element.

[0017] The core of the method according to the invention is that for each subcomponent of a field device, an architecture in the form of a security element is provided in which the distributed authentication, authorization and authenticity of the subcomponents of the other field devices can be validated.

[0018] An advantageous embodiment of the method according to the invention provides that the second identification information contains a set of rules that defines at least one action permitted on the second module, and wherein the second security element only authorizes the operating action if the operating action originating from the first field device is defined as a permitted action in the set of rules. Otherwise, the operating action is rejected.

[0019] According to a preferred embodiment of the method, it is provided that the first field device sends the operating action as a telegram via the communication network to the second field device.

[0020] According to a preferred embodiment of the method, the second subcomponent comprises a logbook, wherein the received operator actions initiated by the first field device are recorded in the logbook. All steps, including who created which component relationship, when, and who created it, are stored in a traceable manner. Advantageously, the name of the operator and their role are also entered for each operator action.

[0021] An advantageous embodiment of the method provides that a first key system consisting of a first private key and a first public key is assigned to the first field device, wherein the first private key is stored in the first security element and wherein the first public key is stored in the second field device. Accordingly, it can be provided that a second key system consisting of a second private key and a second public key is assigned to the second field device, wherein the second private key is stored in the second security element and wherein the second public key is stored in the first field device.

[0022] For example, the private keys can be written into the security element during production of the subcomponent.

[0023] According to an advantageous embodiment of the method, the second security element only authorizes the operating action if the first field device can authenticate itself to the second field device using the second public key. Authorization is accordingly rejected if the authenticity of the first field device or its first subcomponent is not met.

[0024] An advantageous embodiment of the method provides that a secure communication connection is established between the first field device and the second field device by means of the first key system and the second key system.

[0025] According to a preferred embodiment of the method, the operating action is one of the following:

[0026] - Initial or new installation of the second subcomponent;

[0027] - Changing a configuration and / or parameter value of the second subcomponent.

[0028] An advantageous embodiment of the method provides that the first subcomponent and the second subcomponent exchange their respective identification information, and operating actions can only be transmitted if the first subcomponent and the second subcomponent are compatible with each other. For this purpose, a subcomponent, for example, has a list of all compatible subcomponent types, with which the received identification information is compared.

[0029] With regard to the system, it is intended that the system shall include:

[0030] - a first field device comprising at least one first subcomponent, wherein the first subcomponent is designed to enable the first field device to execute at least one additional functionality, wherein the first subcomponent has a first security element, wherein a first logic element and a first identification information item are stored in the first security element, and

[0031] - a second field device which is in communication connection with the first field device via a communication network which comprises at least one second subcomponent, wherein the second subcomponent is designed to enable the second field device to execute at least one additional functionality, wherein the second subcomponent has a second security element, wherein a second logic element and second identification information are stored in the second security element, and wherein the second logic element is designed to authorize operating actions initiated by the first field device on the second subcomponent of the second field device.

[0032] The core of the system according to the invention is that for each subcomponent of a field device, an architecture in the form of a security element is provided in which the distributed authentication, authorization and authenticity of the subcomponents of the other field devices can be validated.

[0033] A subcomponent and its components (safety element and the corresponding elements such as identification information, logic unit, etc.) can be implemented as hardware with corresponding chipsets (containing a processor, a memory unit, etc.) – particularly designed for side-channel protection – or as software. The communication network can be an automation fieldbus, such as Modbus, Profibus PA / DP, Foundation Fieldbus, etc. Alternatively, it can be a direct cable connection between the two field devices or a wireless connection.

[0034] According to a first variant of the system, the first field device is an operating unit. Such an operating unit is, in particular, an operating unit in which an FDT or FDI frame application runs. Alternatively, the operating unit can be a PC or a mobile device, in particular a smartphone or tablet.

[0035] One embodiment of this first variant provides that the second field device is an automation technology field device that has at least one sensor for detecting a physical, chemical, or biological variable of a process and / or an actuator for influencing a physical, chemical, or biological variable of a process. Alternatively, network devices such as control units, gateways, edge devices, etc. can also be considered field devices within the meaning of the present invention.

[0036] According to a second variant of the system, it is provided that the first field device and the second field device are field devices of automation technology, which each have at least one sensor for detecting a physical, chemical or biological variable of a process engineering process and / or an actuator for influencing a physical, chemical or biological variable of a process engineering process.

[0037] The invention is explained in more detail with reference to the following figure. It shows

[0038] Fig. 1: An exemplary embodiment of the method according to the invention. Fig. 1 depicts a first field device FG1. The first field device FG1 is an operating device used to configure and / or parameterize field devices designed as sensors or actuators. Components of the first field device FG1 are referred to below as "first" components.

[0039] The first field device FG1 has several first subcomponents SK1, SKT, which provide functionalities for the first field device FG1. Subcomponents within the meaning of this invention can be designed, for example, as hardware, in particular as a plug-in card, or as software. In the present part, the first subcomponent SK1 is designed as a software component and serves to operate field devices. The further first subcomponent SKT serves, for example, a diagnostic function of the field device FGT.

[0040] The first subcomponent SK1 comprises a first security element SET. The first security element SE1 is a software component which has a first identification information ID1 relating to the first subcomponent SK1, a first logic unit LE1 and a first key pair comprising a first private key PrK1 and a first public key PuK1.

[0041] Furthermore, a second field device FG2 is present. The second field device FG1 is a sensor device, for example, a flow or pressure measuring device. Further examples of field devices are listed in the introductory part of the description. In the following, components of the second field device FG2 are referred to as "second" components.

[0042] The second field device FG2 has several second subcomponents SK2, SK2', which provide functionalities for the second field device FG2. In the present part, the first subcomponent SK1 is designed as a hardware component, accordingly has a processor and a memory unit, and provides the second field device FG2 with heartbeat functionality. The further second subcomponent SK2' serves, for example, to process measured values ​​of a process engineering process acquired by a sensor unit assigned to the second field device FG2. The second subcomponent SK2 comprises a second security element SE2. The second security element SE2 is, for example, a separate chipset provided on the hardware component.The second security element SE2 has a second identification information ID2 relating to the second subcomponent SK2, a second logic unit LE2 and a second key pair comprising a second private key PrK2 and a second public key PuK2.

[0043] The first field device FG1 is connected to the second field device FG2 via a communication network KN. The communication network KN can be an automation fieldbus, such as Modbus, Profibus PA / DP, Foundation Fieldbus, etc. Alternatively, it can be a direct cable connection between the two field devices FG1 and FG2 or a wireless connection.

[0044] Alternatively, no direct communication connection is established between the two field devices FG1, FG2, but an indirect communication connection is used, in which a data carrier, for example a USB stick or an SD card, is exchanged between the two field devices FG1, FG2, on which the data described in the following sections, which are exchanged via the direct communication connection, are located.

[0045] The first field device FG1 transmits the first public key PuK1 to the second field device FG2 via the communication network KN, with the first public key PuK1 being stored in the second security element SE2. The second field device FG2 transmits the second public key PuK2 to the first field device FG1, with the second public key PuK2 being stored in the first security element SE1. This key exchange occurs once and under supervision.

[0046] Alternatively, the two public keys PuK1, PuK2 are transmitted by a user to the field devices FG1, FG2. To do this, the user connects to the field devices FG1, FG2 using an operating unit, for example via a wireless communication connection (Bluetooth, etc.), and transmits the corresponding public keys PuK1, PuK2. Advantageously, the public keys PuK1, PuK2 are also signed so that the respective logic units LE1, LE2 can check, upon receipt of a public key PuK1, PuK2, whether this has a valid signature and whether it is a genuine or plausible public key. The respective logic unit LE1, LE2 of the corresponding security elements SE1, SE2 validates the authenticity of the respective sub-component SK1, SK2, orof the other security element SE1, SE2 by checking the received public keys PuK1, PuK2 and establishes a secure communication connection between the field devices FG1, FG2 using the key systems.

[0047] In the next step, the security elements SE1, SE2 exchange the identification information ID1, ID2 of the respective subcomponents SK1, SK2 via the established secure communication connection. The respective logic units LE1, LE2 use the received identification information ID1, ID2 to check whether the two subcomponents SK1, SK2 are compatible with each other and whether the subsequent steps can be executed in this subcomponent combination.

[0048] If the two subcomponents are compatible with each other, the respective logic unit LE1, LE2 of a subcomponent SK1, SK2 can check whether operating actions of the subcomponent of the other field device FG1, FG2 can be permitted. To do this, the corresponding logic unit LE1, LE2 must know the operating actions of the subcomponent of the other field device FG1, FG2. This can be implemented, for example, in such a way that a safety element SE1, SE2 has a memory unit that contains various possible operating actions of defined types of subcomponents. Using the received identification information ID1, ID2 of the other subcomponent SK1, SK2, the logic unit LE1, LE2 can look up the corresponding operating actions. Alternatively, the possible operating actions are contained in the identification information ID1, ID2 as a set of rules, provided that the file size of an identification information ID1, ID2 may be sufficiently large.

[0049] In this example, the first field device FG1 is to make a parameter change in the second subcomponent SK2. After successfully establishing the secure communication connection and sending the respective identification information ID1, ID2, the field device FG1, or more precisely the subcomponent SK1, sends the corresponding operating action via the secure communication connection to the second field device FG. The second logic unit LE2 checks the operating action and authorizes it. The corresponding action is then carried out by the second field device FG2, or more precisely by the second subcomponent SK2. If the second logic unit LE2 does not authorize the operating action, it is rejected and not carried out.

[0050] It can be provided that the safety elements SE1, SE2 each have a storage unit that serves as a logbook. All operating actions received by a subcomponent SK1, SK2 are stored in a logbook. This allows all steps and operating actions to be traced. It can also be provided that the corresponding user who initiated the operating action and their role are stored in the logbook.

[0051] The method according to the invention can also be implemented with more than two field devices or with more than one compatible subcomponent per field device. For this purpose, each subcomponent receives the public keys and identification information of all compatible subcomponents accessible via the communication network. In such a configuration, it is also possible for a logic unit of a subcomponent to check operating actions that are not directed to its own subcomponent and trigger an alarm if the operating action is not permitted (either because the sending subcomponent is not permitted to send such an operating action, or because the receiving subcomponent is not permitted to receive such an operating action). List of reference symbols

[0052] FG1 first field device

[0053] FG2 second field device

[0054] ID1 first identification information

[0055] ID2 second identification information

[0056] KN Communication Network

[0057] LE1 first logic element

[0058] LE2 second logic element

[0059] PrK1 first private key

[0060] PrK2 second private key

[0061] PuK1 first public key

[0062] PuK2 second public key

[0063] SE1 first security element

[0064] SE2 second security element

[0065] SK1 first subcomponent

[0066] SK2 second subcomponent

[0067] SKT, SK2' further subcomponents

Claims

Patent claims 1. A method for authorizing an operating action sent from a first field device (FG1) to a second field device (FG2), wherein the first field device (FG1) comprises at least one first subcomponent (SK1), wherein the first subcomponent (SK1) is designed to enable the first field device (FG1) to execute at least one additional functionality, wherein the first subcomponent (SK1) has a first security element (SE1), wherein a first logic element (LE1) and first identification information (ID1) are stored in the first security element (SE1), wherein the second field device (FG2) is in communication with the first field device (FG1) via a communication network (KN) and comprises at least one second subcomponent (SK2), wherein the second subcomponent (SK2) is designed to enable the second field device (FG2) to execute at least one additional functionality,wherein the second subcomponent (SK2) has a second security element (SE2), wherein a second logic element (LE2) and a second identification information (ID2) are stored in the second security element (SE2), comprising: - initiating an operating action by an operator on the first field device (FG1), wherein the operating action relates to the second subcomponent (SK2) on the second field device (FG2); - Checking the operating action by the second logic element (LE2); and - Authorizing the operating action in case of successful verification by the second logic element (LE2).

2. The method according to claim 1, wherein the second identification information (ID2) contains a set of rules which defines at least one action permitted on the second module, and wherein the second security element (SE2) authorizes the operating action only if the operating action originating from the first field device (FG1) is defined in the set of rules as a permitted action.

3. The method according to claim 2, wherein the first field device (FG1) sends the operating action as a telegram via the communication network (KN) to the second field device (FG2).

4. Method according to one of the preceding claims, wherein the second subcomponent (SK2) comprises a logbook, wherein the received operating actions initiated by the first field device (FG1) are entered in the logbook.

5. The method according to claim 4, wherein a name of the operator and his role are additionally entered for each operating action.

6. Method according to one of the preceding claims, wherein the first field device (FG1) is assigned a first key system consisting of a first private key and a first public key, wherein the first private key is stored in the first security element (SE1) and wherein the first public key is stored in the second field device (FG2).

7. Method according to one of the preceding claims, wherein a second key system consisting of a second private key and a second public key is assigned to the second field device (FG2), wherein the second private key is stored in the second security element (SE2) and wherein the second public key is stored in the first field device (FG1).

8. The method according to claim 6, wherein the second security element (SE2) authorizes the operating action only if the first field device (FG1) can authenticate itself to the second field device (FG2) using the second public key.

9. The method according to any one of claims 6 to 8, wherein a secure communication connection is established between the first field device (FG1) and the second field device (FG2) by means of the first key system and the second key system.

10. Method according to one of the preceding claims, wherein the operating action is one of the following: - First or new installation of the second subcomponent (SK2); - Changing a configuration and / or a parameter value of the second subcomponent (SK2).

11. Method according to one of the preceding claims, wherein the first subcomponent (SK1) and the second subcomponent (SK2) exchange their respective identification information (ID1, ID2) and operating actions can only be transmitted if the first subcomponent (SK1) and the second subcomponent (SK2) are compatible with each other.

12. System comprising: - a first field device (FG1) comprising at least one first subcomponent (SK1), wherein the first subcomponent (SK1) is designed to enable the first field device (FG1) to execute at least one additional functionality, wherein the first subcomponent (SK1) has a first security element (SE1), wherein a first logic element (LE1) and a first identification information item (ID1) are stored in the first security element (SE1), and - a second field device (FG2) which is in communication connection with the first field device (FG1) via a communication network (KN) which comprises at least one second subcomponent (SK2), wherein the second subcomponent (SK2) is designed to enable the second field device (FG2) to execute at least one additional functionality, wherein the second subcomponent (SK2) has a second security element (SE2), wherein a second logic element (LE2) and a second identification information item (ID2) are stored in the second security element (SE2), and wherein the second logic element (LE2) is designed to be able to receive from the first field device (FG1) to authorize initiated operating actions on the second subcomponent (SK2) of the second field device (FG2).

13. System according to claim 12, wherein the first field device (FG1) is an operating unit.

14. System according to claim 12 and 13, wherein the second field device (FG2) is an automation field device which has at least one sensor for detecting a physical, chemical or biological variable of a process engineering process and / or an actuator for influencing a physical, chemical or biological variable of a process engineering process.

15. System according to claim 12, wherein the first field device (FG1) and the second field device (FG2) are field devices of automation technology, each having at least one sensor for detecting a physical, chemical or biological variable of a process engineering process and / or an actuator for influencing a physical, chemical or biological variable of a process engineering process.