Two-factor authentication for wireless field devices
The two-factor authentication method for handheld field maintenance tools and field devices enhances security by requiring a user to enter a first key and a second key generated by the device, preventing unauthorized access.
Patent Information
- Application Number
- JP2022507803
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-08-09
- Filing Date
- 2020-07-30
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2040-07-30
AI Technical Summary
Traditional security methods for handheld field maintenance tools and wirelessly-enabled field devices rely on keys like pins or passwords, which can be compromised, leading to unauthorized access.
A two-factor authentication method involving a portable field maintenance tool that generates and transmits a second key, which is verified by a remote system and field device, enhancing security by requiring a unique key generated outside the tool's knowledge.
Prevents unauthorized access by ensuring that both a first key known to the user and a second key generated by the field device must be correctly entered, adding an additional layer of security to the authentication process.
Smart Images

Figure 0007729805000001 
Figure 0007729805000002 
Figure 0007729805000003
Abstract
Description
[Technical Field]
[0001] background Security is paramount for handheld field maintenance tools and wirelessly-enabled field devices. Traditional security methods require some kind of key, such as a pin or password, to be entered before access to the field device is granted. This is an effective way to protect field devices from unauthorized access because the field device cannot be accessed without the key. However, if the key falls into the hands of a user who is not authorized to access the field device, that user can gain access to the system, compromising security. Summary of the Invention
[0002] overview A method for authenticating a user of a portable field maintenance tool is provided. The method includes moving the portable field maintenance tool near a field device. The field device receives a first key. The field device generates a second key and transmits the second key to a remote system. The remote system transmits the second key to a user of the portable field maintenance tool. The field device receives the second key. The field device authenticates the user of the portable field maintenance tool. [Brief explanation of the drawings]
[0003] [Figure 1] 1 is a schematic diagram illustrating an authentication environment for a portable field maintenance tool in which an embodiment of the present invention is particularly useful. [Figure 2] FIG. 1 is a block diagram illustrating an exemplary portable field maintenance tool authentication environment in accordance with an embodiment of the present invention. [Figure 3] 1 is a block diagram illustrating a portable field maintenance tool according to one embodiment of the present invention. [Figure 4]1 is a flow diagram illustrating a method for authenticating a portable field maintenance tool according to an embodiment of the present invention. [Figure 5] 1 is a flow diagram illustrating a method for authenticating a portable field maintenance tool according to an embodiment of the present invention. [Figure 6] 1 is a flow diagram illustrating a method for authenticating a portable field maintenance tool according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0004] FIG. 1 is a schematic diagram illustrating a portable field maintenance tool authentication environment in which embodiments of the present invention are particularly useful. The portable field maintenance tool authentication environment 100 includes a portable field maintenance tool 110 communicatively connected, directly or indirectly, to a field device 120 via a wireless communication module (not shown) and a field device 120 communicatively connected, directly or indirectly, to a remote system 130. The field device 120 is generally depicted as a wireless process variable transmitter, such as one sold under the trade name Model 3051S Wireless Process Transmitter by Emerson Automation Solutions, Inc., Chanhassen, Minnesota. However, those skilled in the art will recognize that the field device 120 can include other types of wireless field devices, as well as wireless actuators or valve positioners. Furthermore, those skilled in the art will appreciate that at least some of the methods and systems described herein are also applicable to wired field devices. Furthermore, embodiments of the present invention are also applicable to wired field devices incorporating wireless technology (e.g., Bluetooth® communication).
[0005] The portable field maintenance tool 110 is configured to communicate with the field devices 120 using known wireless process communication protocols. One wireless process communication technology standard is known as the WirelessHART standard, published by the HART® (Highway Addressable Remote Transducer) Communication Foundation in September 2007. Another wireless network communication technology is specified in ISA100.11A, maintained by the International Society of Automation (ISA), which proposed wireless communication at the 2.4 GHz frequency using radio circuits compliant with IEEE 802.15.4-2006. However, any suitable wireless process communication protocol can be used. Additionally, as described in more detail below, portable mobile devices such as the portable field maintenance tool 110 often communicate using the Bluetooth® protocol.
[0006] In order for the portable field maintenance tool 110 to connect to the field device 120, the tool 110 must be authenticated. Authenticating the portable field maintenance tool using the two-factor authentication methods described herein prevents unauthorized tools from connecting to and accessing the field device. Additionally, the authentication methods prevent unauthorized users of the portable field maintenance tool from using a trusted network to access the field device.
[0007] 2 is a block diagram of a portable field maintenance tool authentication environment 200 in accordance with one embodiment of the present invention. The portable field maintenance tool authentication environment 200 illustratively includes a portable field maintenance tool 210 in communication with a field device 240 and a remote system 230 in communication with the field device 240.
[0008] The portable field maintenance tool 210 is illustratively operated by a user 220. The user 220 can use the portable field maintenance tool 210 within communication range 250 of one or more field devices 240. As shown in FIG. 2 , when the user 220 is within communication range 250 of the field device 240, the field device 240 can request 222 a first key and a second key from the user 220 of the portable field maintenance tool 210. The display 211 on the portable field maintenance tool 210 can provide user interface elements that allow the user 220 to enter 224 his or her first key and second key.
[0009] The field device 240 is illustratively communicatively connected to the remote system 230. As shown in FIG. 2 , the remote system 230 requests 232 a second key from the field device 240, and the field device 240 transmits 234 the second key to the remote system 230. As an example, the remote system 230 can request the second key generated by the field device 240 before the portable field maintenance tool 210 communicatively connects with the field device 240. As another example, the remote system 230 can request the second key generated by the field device 240 only after the portable field maintenance tool 210 communicatively connects with the field device 240 and the first key is successfully entered. Once the remote system 230 obtains the second key from the field device 240, the remote system 230 can transmit the second key to the user 220 over the trusted network. The trusted network may include transmitting the second key to user 220 via encrypted or unencrypted email, encrypted or unencrypted text message, telephone call, or handheld walkie-talkie. As one example, an operator of remote system 230 may transmit the second key to user 220. As another example, user 220 may access remote system 230 and receive the second key for themselves.
[0010] 3 is a block diagram of a handheld field maintenance tool according to one embodiment of the present invention. The handheld field maintenance tool 300 is shown as an example of a mobile device such as that sold generally under the trade name AMS Trex Device Communicator by Emerson Automation Solutions, Inc., of Chanhassen, Minnesota. However, other suitable mobile devices, such as a personal digital assistant, laptop computer, tablet, or smartphone, may also be used.
[0011] The portable field maintenance tool 300 includes at least one wireless process communication protocol module 310. Suitable examples of the wireless process communication protocol module 310 include any module that generates and / or receives appropriate signals according to a known process communication protocol, such as the WirelessHART protocol, Fieldbus protocol, HART® protocol, or as specified in the aforementioned ISA100.11A, or another suitable communication protocol. While FIG. 3 depicts a single wireless process communication protocol module 310, it is expressly contemplated that any suitable number of wireless process communication protocol modules may be used to communicate according to various wireless process communication protocols now existing or later developed.
[0012] The portable field maintenance tool 300 may also include at least one second wireless communication protocol module 320. The wireless communication protocol module 320 may communicate according to one or more of the options illustrated by the dotted lines in Figure 3. Specifically, the wireless communication protocol module 320 may communicate according to the Bluetooth standard 322, the Wi-Fi standard 324, the Radio Frequency Identification (RFID) standard 326, a cellular communication technology 328, satellite communication 330, or any other suitable wireless data communication technology, such as Long Term Evolution (LTE). Although one wireless communication protocol module 320 is shown in Figure 3, any suitable number of wireless communication protocol modules 320 may be used.
[0013] In one embodiment, the wireless process communication protocol module 310 and the wireless communication protocol module 320 are each connected to a controller 340, which is also connected to a wired process communication module 350. The controller 340 is preferably a microprocessor that executes instruction sequences for performing a number of portable field maintenance tasks. The wired process communication module 350 allows the portable field maintenance tool 300 to be physically connected to, for example, field devices via a wired connection at terminals 352, 354. Examples of suitable wired process communication protocols include the HART protocol, FOUNDATION® Fieldbus protocol, and others. The portable field maintenance tool 300 also includes a memory component 360 configured to store one or more applications 362, as well as a data store 364.
[0014] The memory 360 may include instructions that, when executed, cause the portable field maintenance tool 300 to execute one or more of the applications 362. For example, a user may wish to connect to a field device by authenticating the portable field maintenance tool 300. The user may indicate a desire to execute one of the applications 362, for example, via an input / output mechanism 374, which may be part of the user interface 370 of the portable field maintenance tool 300. In response to the received instruction, the portable field maintenance tool 300 may execute the stored instructions, causing the field device to respond and form an initial connection between the field device and the portable field maintenance tool 300 for authentication purposes. As one example, the portable field maintenance tool 300 may be configured to store the results of the authentication attempt, for example, in the data store 364. As another example, the portable field maintenance tool 300 may be configured to transmit a report of the results of the authentication attempt, for example, to a remote control room or other remote system.
[0015] The user can indicate which field device they wish to connect to using the appropriate buttons or via the navigation of the portable field maintenance tool 300, which is displayed on the display 372 of the portable field maintenance tool 300. When the device authentication function is selected, the controller 340 can cause the display 372 to provide one or more user interface elements to assist the user in authenticating the portable field maintenance tool 300 to the selected field device. For example, the user interface 370 can include a drop-down box that lists all known field devices within the proximity of the portable field maintenance tool 300. As another example, the user interface 370 can include a drop-down box that lists all known field devices that are communicatively connected to a remote system. The user can then select which field device they wish to connect to by selecting the appropriate button.
[0016] 4 is a flow diagram of a method for authenticating a portable field maintenance tool according to one embodiment of the present invention. The method 400 can be used to authenticate a portable field maintenance tool 430 to access a field device 420 and to establish a wireless connection between the portable field maintenance tool 430 and the field device 420. This can be useful, for example, to prevent security breaches by unauthorized portable field maintenance tools and / or users.
[0017] In block 440, the remote system 410 requests the second key from the field device 420. As one example, the remote system 410 requests the second key from the field device 420 because the field device 420 has been selected by a user of the portable field maintenance tool 430. As another example, the remote system 410 may generate an automatic request for the second key from the field device 420 upon receiving a signal from the field device 420 that a connection with the portable field maintenance tool 430 is desired.
[0018] In block 445, the field device 420 generates a second key and sends the key back to the remote system 410. As an example, the second key may be a one-time key, meaning that after the key is successfully entered and the portable field maintenance tool 430 is connected to the field device 420, the key is no longer valid for subsequent authentication attempts. Instead, a new second key is generated by the field device 420. As another example, the second key may have an expiration date associated with it, meaning that after a certain amount of time has passed without successful authentication, the second key is no longer valid and a new second key needs to be generated by the field device 420. It should be noted that the second key may include any length of combination of numbers, syllabaries, or all characters generated by the field device 420, or alone.
[0019] In block 450, the remote system 410 receives the generated second key from the field device 420, and the user of the portable field maintenance tool 430 that requested the second key brings the portable field maintenance tool 430, along with the second key, into proximity of the field device 420. As an example, this may include bringing the portable field maintenance tool 430 within communication range of the field device 420.
[0020] As one example, bringing the portable field maintenance tool 430 into range of the field device 420 includes the portable field maintenance tool 430 displaying a prompt on a display component indicating that the user may be in range and requesting confirmation. The prompt may include a display of what the field device looks like or where the device is located, since many field devices may not be located at eye level. It is also expressly contemplated that the user may initiate a connection via the portable device by selecting the field device from a list of available field devices that are within range.
[0021] In block 460, the portable field maintenance tool 430 initiates a connection with the field device 420. As one example, initiating the connection includes the portable field maintenance tool 430 displaying a prompt on a display component indicating that the user may be within communication range of the field device and requesting confirmation, with the user confirming the request. As another example, initiating the connection includes the portable field maintenance tool 430 automatically connecting with the field device 420 when the user is within communication range of the field device 420.
[0022] In block 465, the field device 420 requests a first key from the portable field maintenance tool 430. As an example, the portable field maintenance tool 430 may display a prompt on a display component indicating that the user may enter the user's first key using an interface element. The first key may include a password or pin of any length, or a combination of numbers, syllabaries, or all characters, or alone. As an example, the first key is unique to the user of the portable field maintenance tool 430. As another example, the first key can be unique to the portable field maintenance tool 430. As yet another example, the first key can be unique to the field device 420.
[0023] At block 470, a user of the portable field maintenance tool 430 enters a first key using an interface element. At block 475, the field device 420 receives the first key and identifies whether the key is acceptable. As an example, the field device 420 may include a memory component having a data store containing all acceptable first keys that may be entered by a user of the portable field maintenance tool 430. As another example, the field device 420 may transmit the entered first key to the remote system 410, whereby an operator of the remote system 410 may receive and verify the entered first key and transmit a verification to the field device 420 regarding whether the first key is acceptable. As an example, if the first key is rejected by the field device 420, the user may be prompted by the portable field maintenance tool 430 to re-enter the first key on a display component. As another example, the field device 420 may terminate its connection with the portable field maintenance tool 430, thereby prompting the user of the tool 430 to re-establish the connection if desired.
[0024] In block 480, the field device 420 requests the second key from the portable field maintenance tool 430. As an example, the portable field maintenance tool 430 may display a prompt on a display component indicating that the user can enter the second key using an interface element. In block 485, the user of the portable field maintenance tool 430 enters the second key generated by the field device 420. The user may have received the second key via a trusted communication channel, such as using the user's cell phone, walkie-talkie, or encrypted email / text message.
[0025] In block 490, the field device 420 receives the second key and identifies whether the second key entered by the user of the portable field maintenance tool 430 matches the second key generated by the field device 420. As an example, if the second key is rejected by the field device 420, the user of the tool 430 can be prompted by the portable field maintenance tool 430 on a display component to re-enter the second key. As another example, the field device 420 can terminate the connection with the portable field maintenance tool 430, thereby prompting the user to re-establish the connection if desired.
[0026] In block 495 , the portable field maintenance tool 430 is authenticated by the field device 420 .
[0027] 5 is a flow diagram of a method for authenticating a portable field maintenance tool according to one embodiment of the present invention. The method 500 can be used to authenticate a portable field maintenance tool 510 to access a field device 520 and to establish a wireless connection between the portable field maintenance tool 510 and the field device 520. This can be useful, for example, to prevent security breaches due to unauthorized use of the portable field maintenance tool.
[0028] At block 540, the portable field maintenance tool 510 initiates a connection with the field device 520. The connection can be established when a user of the portable field maintenance tool 510 is within communication range of the field device 520. As one example, when the portable field maintenance tool 510 is near the field device 520, the portable field maintenance tool 510 can display a prompt on a display component indicating that the user is likely within communication range of the field device 520 and request confirmation from the user. The prompt can include an indication of what the field device 520 looks like or where the field device 520 is located, since many field devices may not be located at eye level. As another example, the portable field maintenance tool 510 can automatically connect with the field device 520 when within communication range of the field device 520. It is also expressly contemplated that a user can initiate a connection via the portable device by selecting a field device from a list of available field devices within communication range.
[0029] In block 545, the field device 520 requests a first key from the user of the portable field maintenance tool 510. As an example, the portable field maintenance tool 510 may display a prompt on a display component indicating that the user may enter the user's first key using an interface element. The first key may include any length of numbers, syllabaries, or any combination of characters, or may alone be a password or pin. As an example, the first key may be unique to the user of the portable field maintenance tool 510. As another example, the first key may be unique to the portable field maintenance tool 510. As yet another example, the first key may be unique to the field device 420.
[0030] In block 550, a user of the portable field maintenance tool 510 enters a first key using an interface element. In block 555, the field device 520 receives the first key and identifies whether the key is acceptable. As an example, if the first key is rejected by the field device 520, the user may be prompted on a display component by the portable field maintenance tool 510 to re-enter the first key using an interface element. As another example, the field device 520 may terminate its connection with the portable field maintenance tool 510, thereby prompting the user to re-establish the connection if desired.
[0031] In block 560, once the acceptable first key is entered, the field device 520 generates a second key and transmits the key to the remote system 530. Once the second key is generated, the remote system 530 is notified of the pending connection between the portable field maintenance tool 510 and the field device 520. The second key can be transmitted to the remote system 530 using known process communication lines, such as HART commands. As one example, the field device 520 automatically generates and transmits the second key to the remote system 530 once the acceptable first key is entered by the user. As another example, the portable field maintenance tool 510 can display a prompt on a display component indicating that the user has entered an acceptable first key and request permission from the user to transmit the second key to the remote system 530.
[0032] At block 570, the remote system 530 transmits the second key to the user of the portable field maintenance tool 510 over a trusted network. The trusted network may include a telephone call to the user, a handheld transceiver such as a walkie-talkie, or an encrypted or unencrypted email or text message to the user, or any other form of trusted network.
[0033] In block 580, the field device 520 requests a second key from the portable field maintenance tool 510. In block 585, a user of the portable field maintenance tool 510 uses an interface element to enter the second key received over the trusted network.
[0034] In block 590, the field device 520 receives the second key and identifies whether the second key matches the second key generated by the field device 520. As an example, if the second key is rejected by the field device 520, the user may be prompted on a display component by the portable field maintenance tool 510 to re-enter the second key using an interface element. As another example, the field device 520 may terminate the connection with the portable field maintenance tool 510, thereby prompting the user to re-establish the connection if desired.
[0035] At block 595 , the portable field maintenance tool 510 is authenticated by the field device 520 .
[0036] 6 is a flow diagram of a method for authenticating a portable field maintenance tool according to one embodiment of the present invention. The method 600 can be used to authenticate a portable field maintenance tool 610 to access a field device 620 and to establish a wireless connection between the portable field maintenance tool 610 and the field device 620. This can be useful, for example, to prevent security breaches due to the use of unauthorized portable field maintenance tools.
[0037] At block 640, the portable field maintenance tool 610 initiates a connection with the field device 620. The connection may be established when a user of the portable field maintenance tool 610 is within communication range of the field device 620. When the portable field maintenance tool 610 is near the field device 620, the portable field maintenance tool 610 may display a prompt on a display component indicating that the user may be within communication range of the field device 620 and request confirmation from the user. The prompt may include an indication of what the field device 620 looks like or where the device 620 is located, since many field devices may not be located at eye level. It is also expressly contemplated that a user may initiate a connection via the portable device by selecting a field device from a list of available field devices that are within communication range.
[0038] In block 645, the field device 645 requests a first key from the user of the portable field maintenance tool 610. The first key may comprise a password or pin, a combination of numbers, syllabaries, or all characters of any length, or alone. As one example, the first key may be unique to the user of the portable field maintenance tool 610. As another example, the first key may be unique to the portable field maintenance tool 610. As yet another example, the first key may be unique to the field device 420.
[0039] In block 650, the user of the portable field maintenance tool 610 enters a first key. In block 655, the field device 620 receives the first key and identifies whether it is acceptable. As an example, if the first key is rejected by the field device 620, the user may be prompted by the portable field maintenance tool 610 to re-enter the first key. As another example, the field device 610 may terminate the connection with the portable field maintenance tool 610, thereby prompting the user to re-establish the connection if desired.
[0040] In block 660, the field device 620 requests identification information from the portable field maintenance tool 610. The portable field maintenance tool 610 then provides the identification information to the field device 620, as indicated by reference numeral 662. The field device 620 then transmits the identification information to the remote system 630, as indicated by reference numeral 664. The obtained identification information may include certain identification information from the portable field maintenance tool 610, such as what type of tool it is, security credentials that only authorized portable field maintenance tools may have, and / or unique identification information specific to the portable field maintenance tool, such as its identification number.
[0041] In block 670, the remote system 630 receives identification information for the portable field maintenance tool 610. In block 680, the remote system 630 identifies whether the portable field maintenance tool 610 is authenticated. As an example, the remote system 630 can automatically authenticate or terminate the connection between the portable field maintenance tool 610 and the field device 620 based on the received identification information. As another example, an operator of the remote system 630 can determine whether the portable field maintenance tool 610 is authenticated, and the operator can either authenticate or terminate the connection of the portable field maintenance tool 610 with the field device 620. In this manner, the remote system instructs the field device to either allow the connection to continue and authenticate the tool, or to terminate the connection and not authenticate the tool.
[0042] In block 682, the remote system 630, or an operator of the remote system 630, terminates the connection between the portable field maintenance tool 610 and the field device 620. As one example, the portable field maintenance tool 610 may prompt the user of the tool 610 to re-establish the connection and initiate the connection process if desired. As another example, the portable field maintenance tool 610 may be locked by the remote system 630, thereby preventing further action by the user of the portable field maintenance tool 610. This embodiment is described with respect to FIG. 6, but is also applicable to other embodiments, such as those shown in FIGS. 4 and 5.
[0043] At block 684 , the remote system 630 or an operator of the remote system 630 authenticates the connection between the portable field maintenance tool 610 and the field device 620 .
[0044] The embodiments described herein serve to enhance field device security by adding another layer or step to the security process: when a handheld field maintenance tool wants to access a field device via a wireless connection, not only does it need to enter a key that it knows, but it must also enter a separate, second key that can be generated outside the handheld field maintenance tool's knowledge and distributed over a trusted network.
Claims
1. 1. A method for providing two-factor authentication of a mobile device to a field device, comprising: initiating a connection between the mobile device and the field device, the initiating a connection between the mobile device and the field device including the mobile device being moved into a communication range of the field device; receiving, by the field device, a first key; the field device identifying whether the received first key is acceptable; if the received first key is acceptable, generating, using the field device, a second key prompted by a request for a second key by a remote system; the field device transmitting the second key to the remote system; the remote system transmitting the second key to the user of the mobile device over a trusted network; receiving, by the field device, the second key transmitted to the user of the mobile device; the field device identifying whether the received second key matches a second key generated by the field device; allowing the mobile device to access the field device if the received second key matches a second key generated by the field device; The method comprising:
2. The method of claim 1 , wherein the trusted network is selected from the group consisting of a handheld walkie-talkie, an email, a text message, and a telephone call.
3. The method of claim 1 , wherein the second key is a one-time use key.
4. 4. The method of claim 3, wherein the second key expires after a predetermined amount of time.
5. The method of claim 1 , wherein the second key is transmitted after the connection is initiated and the first key is entered.
6. The method of claim 1 , wherein the mobile device is a handheld field maintenance tool.
7. The method of claim 1 , wherein initiating a connection between the mobile device and the field device includes initiating a wireless connection between the mobile device and the field device.
8. The method of claim 1, wherein the field device transmits the second key to the remote system via a process communication network.
9. 1. A method for authenticating a mobile device, comprising: initiating an unauthenticated wireless communication session between the mobile device and a field device; receiving, at the field device, a first keystroke provided by the mobile device via the unauthenticated session; determining whether the first key input is a correct first key in the field device; selectively generating and transmitting to the remote system, by the field device, a second key requested by the remote system based on whether the first key is a correct first key; the remote system transmitting the second key to the user of the mobile device over a trusted network; receiving, by the field device, a user input; selectively initiating an authenticated wireless session between the mobile device and the field device based on whether the user input matches the second key; The method comprising:
10. 10. The method of claim 9, wherein the second key is generated after the field device determines that the first key input is a correct first key.
11. The method of claim 9 , wherein the second key is transmitted by the field device using a process communication network.
12. The method of claim 9 , wherein the first key input comprises identification information provided by the mobile device.
Citation Information
Patent Citations
Authentication system, authentication method, program, and recording medium therefor
JP2002245006A
Field equipment system
JP2007026020A