Human machine interface device with biometric user authentication
By integrating biometric user authentication into HMI devices, the challenges of user access and security in current HMI systems are addressed, enabling efficient and secure multiple-user access without the need for traditional login methods.
Patent Information
- Application Number
- PCT/US2024/059359
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-14
- Filing Date
- 2024-12-10
- Publication Date
- 2025-06-19
AI Technical Summary
Current human machine interface (HMI) devices for complex processes face inefficiencies and security risks due to the need for users to exit screens before others can log in, and the cumbersome process of entering usernames and passwords on industrial touch screens.
The implementation of a biometric user authentication system within HMI devices, which uses biometric readers to authenticate users through methods like fingerprint, facial, or iris recognition, allowing multiple users with different access levels to interact with the same GUI simultaneously without the need for traditional login procedures.
This solution enhances security, reduces login time, and allows multiple users to access the HMI device simultaneously, improving operational efficiency and reducing the likelihood of security breaches.
Smart Images

Figure US2024059359_19062025_PF_FP_ABST
Abstract
Description
HUMAN MACHINE INTERFACE DEVICE WITH BIOMETRIC USER AUTHENTICATIONCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to Indian Patent Application No. 202311085525, filed on December 14, 2023, which is hereby incorporated by reference in its entirety.BACKGROUND[00021 In many complex processes such as. for example, process control environments including automotive manufacturing, chemical processing, oil and gas, food and beverage, medical device and equipment manufacturing, water treatment, paper manufacturing, mining, metal processing, packaging, filling, and others, various types of human machine interface (HMI) devices are used by humans to interface with the different aspects of a control system that controls a particular complex process.BRIEF DESCRIPTION OF THE DRAWINGS[00031 Various objects, features, and advantages of the disclosure can be more fully appreciated with reference to the following detailed description when considered with the following drawings.|0004] FIG. 1 is a block diagram showing components of an example control system that uses biometrics to authenticate users interacting with a human machine interface (HMI) device, in accordance with some aspects of the disclosure.
[0005] FIG. 2 is an illustration showing an example implementation of a screen and associated graphical user interface (GUI) objects that can be presented via the HMI device of FIG. 1 as a machine control interface, in accordance with some aspects of the disclosure.
[0006] FIG. 3 is an illustration showing an example implementation of a screen and associated GUI objects that can be presented via the HMI device of FIG. 1 as a restricted access interface, in accordance with some aspects of the disclosure.
[0007] FIG. 4 is an illustration showing an example implementation of a screen and associated GUI objects that can be presented via the HMI device of FIG. 1 as a user login interface, in accordance with some aspects of the disclosure.[0008| FIG. 5 is an illustration showing an example implementation of a screen and associated GUI objects that can be presented via the HMI device of FIG. 1 as a diagnostics interface, in accordance with some aspects of the disclosure.
[0009] FIG. 6 is an illustration showing an example implementation of a screen and associated GUI objects that can be presented via the HMI device of FIG. 1 as a machine control interface including a login window, in accordance with some aspects of the disclosure.|0010] FIG. 7 is an illustration showing an example implementation of a screen and associated GUI objects that can be presented via the HMI device of FIG. 1 as an alarms interface, in accordance with some aspects of the disclosure.10011] FIG. 8 is an illustration showing an example implementation of a screen and associated GUI objects that can be presented via the HMI device of FIG. 1 as a sensitive data interface, in accordance with some aspects of the disclosure.10012] FIG. 9 is a flow diagram illustrating an example process for use in the control system of FIG. 1 to authenticate users interacting with the HMI device of FIG. 1, in accordance with some aspects of the disclosure.
[0013] FIG. 10 is a flow diagram illustrating an example process for use in the control system of FIG. 1 to authenticate interactions with the HMI device of FIG. 1, in accordance with some aspects of the disclosure.DETAILED DESCRIPTION[0014| As noted, control systems enable controlling of various complex processes. The control systems may include human machine interface (HMI) devices that are used by humans to interface with the different aspects of the control system. For example, the HMI devices can enable a human operator to control and / or monitor different variables in a particular complex process. However, current devices, systems, methods, and media used for authenticating users of HMI devices leave room for technological improvements. For example, a logged-in user on an HMI device ty pically needs to exit a given screen before a new user with different access level permissions can login to the HMI device, thereby creating inefficiencies and preventing multiple users from simultaneously accessing the HMI device. Moreover, entry of all the different characters needed for a username and password by users via an industrial ty pe of touch screen display can be time consuming and cumbersome, and can also introduce various security’ risks depending on the application.
[0015] FIG. 1 illustrates a block diagram of an example control system 100 that uses biometrics to authenticate users interacting with a human machine interface (HMI) device 120, in accordance with some aspects of the disclosure. As shown in FIG. 1, the HMI device 120 can communicate with an engineering workstation 110 via a network 150. The engineering workstation 110 can include and execute HMI configuration software 112 that can be used bya user 142 to configure an HMI application 121 that can be downloaded to a memory 136 of the HMI device 120 via the network 150. Then, when processing circuitry 134 of the HMI device 120 executes the HMI application 121 stored in the memory' 136, the HMI application 121 running on the HMI device 120 can cause the HMI device 120 to present various screens with different graphical user interface (GUI) objects on a touch screen display 130 of the HMI device 120. For example, FIG. 1 shows both a screen 122 including GUI objects 123 and a screen 124 including GUI objects 125. Additionally, the HMI application 121 running on the HMI device 120 can include user authentication software 126 for authenticating users (e.g., a user 144 and a user 146 as shown) that interact with the HMI device 120 and sensitive data 128 associated with the control system 100. The HMI device 120 can also include a biometric reader 132 that reads biometrics associated with users that interact with the HMI device 120, such as, for example, the user 144 and the user 146.
[0016] The control system 100 can be any suitable ty pe of control system that controls the operation of equipment 160 as shown in FIG. 1. For example, the control system 100 can be implemented in various types of environments, such as. for example, complex process control environments including automotive manufacturing, chemical processing, oil and gas, food and beverage, medical manufacturing, water treatment, paper manufacturing, mining, metal processing, packaging, filling, and other types of process control environments. The equipment 160 can likewise include any suitable equipment that is generally controlled by the control system 100, such as, for example, various types of controllers (e.g., programmable logic controllers (PLCs)), sensors, valves, switches, actuators, regulators, power supplies, motors, drives, fluid tanks, various ty pes of machinery', and other types of equipment that can be controlled by a control system. The control system 100 generally uses inputs from various types of users (e.g., machine operators, electricians, facility stakeholders, engineers, etc.) that are provided via the touch screen display 130 of the HMI device 120. For example, via the touch screen display 130, users can affect operation of the equipment 160 and access of modify the sensitive data 128 by interacting with the screen 122 and the GUI objects 123 presented by the HMI device 120 via the touch screen display 130.
[0017] The engineering workstation 110 can be implemented in a variety' of suitable manners, but generally the engineering workstation 110 is a computing system that can be used by the user 142 to access the HMI configuration software 112. For example, the engineering workstation 110 can be implemented as a workstation computer located in a manufacturing or chemical processing facility that engineers and other skilled personnel can use to access the HMI configuration software 1 12. The engineering workstation 110 can also be implementedvia a personal computing device, such as, for example, a laptop, a desktop computer, a tablet, a smartphone, and other ty pes of personal computing devices. In some implementations, the HMI configuration software 1 12 can be hosted at least in part on one or more remote (cloud) servers and / or one or more on-premises servers, and accessed via various types of computing devices. The HMI configuration software 112 can also be installed locally on the engineering workstation 110. The engineering workstation 110 can include suitable components for interfacing with the HMI configuration software 112, such as, for example, various types of displays, a keyboard, a mouse, and other suitable components. The engineering workstation 110 can be implemented as a computing device that is external to the HMI device 120 and sends the HMI application 121 to the HMI device 120, for example.|0018] The HMI configuration software 112 generally’ includes software that can be used by that engineers and other skilled personnel to configure the HMI application 121 that is installed on the HMI device 120. For example, via the HMI configuration software 112, the user 142 can configure and generate an application file that defines at least some aspects of the HMI application 121. The application file can include biometric data associated with a known set of users that the HMI device 120 can use as a reference to identify users that interact with the HMI device 120 and grant the appropriate level of access to the users that interact with the HMI device 120 by comparing collected biometric data to the biometric data associated with the known set of users. The know n set of users can include, for example, some or all of the employees and / or contractors associated with a particular facility, associated with a particular entity’, or any other suitable set of users that may interact with the HMI device 120. The application file can also include configurations for different screens and GUI elements presented via the touch screen display of the HMI device 120. including the screen 122, the GUI objects 123. the screen 124. the GUI objects 125. the authentication software 126, and the sensitive data 128.(0019] The HMI device 120 can be implemented using any suitable ty pe of HMI device. For example, the HMI device 120 can be implemented as a quick panel device, an industrial web panel device, an industrial monitor device, a panel personal computer (PC) device, an industrial web panel device, an RXi device, and other suitable types of HMI devices. The HMI device 120 can be one of multiple separate HMI devices installed in a given facility, or can be the only HMI device installed in a facility in some examples. Via the HMI device 120, the user 144 and the user 146, depending on their access level, can perform a variety of functions using the HMI device 120. For example, the user 144 can interact with the GUI objects 123 presented on the screen 122 to affect operation of the equipment 160 by causing the HMI device 120 tosend a control signal to the equipment 160 via the network 150. Also, the user 144 can access or modify the sensitive data 128 via the HMI device 120. Generally, the HMI device 120 provides an interface for humans to interact with the control system 100 via the touch screen display 130. While use of the touch screen display 130 is primarily described herein, inputs can be provided to the HMI device 120 in a variety of ways (e.g., via voice commands, via a keyboard or keypad, via a mouse) depending on the application. The HMI device 120 may not necessarily be a single device in the sense that it is contained within a single housing. Additionally, the HMI device 120 can be implemented as an “HMI system” including multiple separate, integrated components functioning together to provide an interface between the user 144, the user 146, and the control system 100.|OO20] The memory 136 can include any suitable storage device or devices that can be used to store machine-readable instructions, values, logic, etc., that can be used, for example, by the processing circuitry 134 to implement various functions of the HMI device 120. The memory 136 can include any suitable types of memoiy including volatile memory7, non-volatile memory, and / or suitable combinations thereof. For example, the memory 136 can include random-access memory (RAM), dynamic random-access memory (DRAM), read-only memory (ROM), electrically erasable programmable read-only memory7(EEPROM), one or more flash drives, one or more hard disks, one or more solid state drives, one or more optical drives, and / or other suitable types of memory. The memory 136 can include non-transitory computer-readable storage media having instructions stored thereon for execution by the processing circuitry 134. For example, the memory7136 can store a set of computer-readable instructions and associated data as defined by the HMI application 121 for execution by the processing circuitry7134. The processing circuitry 134 can be implemented using any suitable hardware processor or combination of hardware processors, including using central processing units (CPU), graphics processing units (GPU), and / or other types of hardware processing components. The processing circuitry 134 can further be implemented using a suitable number of processing cores, including single core processors, dual core processors, and other processor core configurations.[00211 The HMI application 121 can be implemented in a variety of ways, but generally the HMI application 121 includes suitable software that can be stored in the memory7136 and can be executed by the processing circuitry 134 to provide an interface between humans and machinery. As noted, at least some aspects of the HMI application 121 can be configured by the user 142 by accessing the HMI configuration software 112 via the engineering workstation 110. The HMI application 121 can define, at least in part, the screen 122, the GUI objects 123,the screen 124, the GUI objects 125, the authentication software 126, and the sensitive data 128, among other aspects of the HMI device 120. The HMI application 121 can be contained in an application file that is downloadable to the HMI device 120 from the engineering workstation 110 via the network 150. The HMI device 120 can include other software and / or firmware in addition to the HMI application 121 to control various aspects of the operation of the HMI device 120. in some implementations. The ability of the HMI application 121 to be configured and downloaded to the HMI device 120 can provide advantages in certain applications in that the user 142 can update the HMI application 121 for various purposes by accessing the HMI configuration software 112 via the engineering workstation 110.[0022| The network 150 can include any suitable types and / or combinations of electronic communication networks, such as. for example, various types of wired and / or wireless industrial communication networks used to implement the control system 100. For example, the network 150 can include any suitable electronic communications networks used in the control system 100 to communicate via protocols such as, for example, Ethernet (e.g., Ethernet Advanced Physical Layer (Ethemet-APL)), Wi-Fi, peer-to-peer (e.g., Bluetooth), cellular (e.g., 3G networks, 4G networks, 5G networks, etc.), and / or other suitable protocols. The network 150 can include local area networks (LAN), wide area networks (WAN), public networks (e.g., the Internet, which may be part of a WAN and / or LAN), private or semi-private networks (e.g., a corporate intranet), or any other suitable types of networks and communication protocols that may be used to facilitate electronic communications within the control system 100. The network 150 can be used to transmit the HMI application 121 to the HMI device 120 from the engineering workstation 110. The network 150 can also be used to transmit control signals from the HMI device 120 to the equipment 160. The engineering workstation 110 and the HMI device 120 can include any suitable communications interfaces (e.g., ports, radios, antennas, etc.) to facilitate communications via the network 150.
[0023] The user 142 can be any suitable type of user that configures the HMI application 121 by accessing the HMI configuration software 112 via the engineering workstation 110. For example, the user 142 can be an engineer, a contractor, an operator, an electrician or other type of technician, a facility stakeholder, a manager, or any other suitable type of user that configures the HMI application 121 by accessing the HMI configuration software 112 via the engineering workstation 110. The user 144 and the user 146 can be any suitable types of users that interact with the HMI device 120 to perform various types of operations within the control system 100, such as, for example, affecting the operation of the equipment 160 and / or accessing or modifying the sensitive data 128. For example, each of the user 144 and the user 146 canbe any of an engineer, a contractor, an operator, an electrician or other type of technician, a facility stakeholder, a manager, or any other suitable type of user that interacts with the HMI device 120. In some examples, the user 144 can be associated with a first access level (e.g., administrator level, supervisor level, etc.) and the user 146 can be associated with a second access level (e.g., an operator level, a maintenance level, etc.) in the authentication software 126. In some examples, additional users beyond the user 142, the user 144, and the user 146 as shown in FIG. 1 can interact with the control system 100 via the engineering workstation 110 and / or the HMI device 120. The user 142 can be the same as the user 144 orthe user 146. [0024| The touch screen display 130 of the HMI device 120 can be implemented using any suitable types and / or combinations of touch screen displays. For example, the touch screen display 130 can be implemented using a resistive touch screen, a surface capacitive touch screen, an infrared (IR) touch screen, a projected capacitive (P-Cap) touch screen, and / or a surface acoustic wave (SAW) touch screen. The touch screen display 130 can be implemented as a single, large touch screen on the HMI device 120, or the touch screen display 130 can be implemented using multiple separate, individuals touch screens on the HMI device 120 (e.g., a main touch screen display and one or more auxiliary touch screen displays, multiple similar touch screen displays, etc ). Generally, the user 144 and the user 146 can provide inputs to the HMI device 120 by interacting with the touch screen display 130. For example, the user 144 can provide an input to the HMI device 120 by pressing, tapping, holding, sliding, selecting, or otherwise interacting with one or more of the GUI objects 123 presented on the screen 122 using one or more fingers, using an instrument (e.g., a digital pen, etc.), etc.[0025| The screen 122 and the screen 124 can be any suitable types of screens that provide an interface betw een the user 144 and the control system 100 or the user 146 and the control system 100. Various example implementations of the screen 122 and the screen 124 are shown in FIGS. 2-8 and described in more detail below. The GUI objects 123 and the GUI objects 125, respectively, can include any suitable types of GUI elements that convey information to the user 144 or the user 146 and / or allow the user 144 or the user 146 to perform various actions associated with the control system 100. Again, various example implementations of the GUI objects 123 and the GUI objects 125 (also referred to as GUI elements 123 and 125, respectively) are shown in FIGS. 2-8 and described in more detail below-. In some examples, the screen 122 can be a first screen that the user 144 interacts with for authentication and then, upon authentication, the screen 124 can be a second screen presented to the user 144 based on an access level granted to the user 144 that allows the user 144 to view and / or modify the sensitive data 128. The screen 122, the GUI objects 123, the screen 124, and the GUI objects125 can be defined at least in part by the HMI application 121, and accordingly the screen 122, the GUI objects 123, the screen 124, and the GUI objects 125 can be configured by the user 142 by accessing the HMI configuration software 112 via the engineering workstation 110. The screen 122 and the screen 124 can both be used to provide different access levels to different users (e.g., the user 144 and the user 146) accessing the same GUI presented on the touch screen display 130 at the same time[0026| The authentication software 126 can include any suitable data and / or logic for use by the HMI device 120 to authenticate users (e.g., the user 144 and the user 146) that interact with the HMI device 120. For example, the authentication software 126 can include the biometric data associated with the known set of users received from the engineering workstation 110. The biometric data associated with the known set of users, and any identifying data associated with the known set of users, as well as any biometric data used by the HMI device 120 to authenticate users, can be anonymized and encrypted. The biometric data can include any suitable ty pes of biometric data including fingerprint data, retina scan data, iris scan data, facial recognition data, and other types of biometric data. The known set of users can include, for example, some or all of the employees and / or contractors associated with a particular facility, associated with a particular entity, or any other suitable set of users that may interact with the HMI device 120. When the user 144 or the user 146 interacts with the HMI device 120, for example via the touch screen display 130, the authentication software 126 can collect biometric data associated with the user 144 or the user 146 in certain instances.
[0027] For example, the authentication software 126 can interact with the biometric reader 132 to collect a fingerprint, a facial recognition image, an iris scan, or a retina scan responsive to receiving an input from the user 144 or the user 146. Then, the authentication software 126 can compare the collected biometric data with the biometric data associated with the known set of users to identify the user 144 or the user 146 and grant an access level to the user 144 or the user 146 accordingly. The authentication software 126 can also be configured to implement one or more timeout periods associated with user authentication events. For example, if a predetermined period of time (e.g., 10 seconds, 30 seconds, etc.) elapses after the authentication software 126 grants the user 144 an administrator access level, the authentication software 126 can deactivate the administrator access level and require another biometric data collection event for the user 144 before granting the administrator access level again.|0028] The sensitive data 128 can include any data associated with the control system 100 that requires a certain level of authorization to access and / or modify. For example, the sensitive data 128 can include alarms associated with the equipment 160 in the control system 100,special scripts associated with the human machine interface device 120 (e g., specialized software functions), an audit trail associated with the human machine interface device 120, critical sensor readings associated with the control system 100, financial data associated with the control system 100, various types of user data managed by the human interface device 120, and any other types of sensitive data to which access can be restricted to certain types of users. The sensitive data 128 can be restricted in accordance with various access levels configured via the HMI configuration software 112 and defined by the HMI application 121, such as, for example, an administrator access level, an operator access level, a manager access level, a maintenance access level, a supervisor access level, and any other suitable types of access levels.|(I029] The biometric reader 132 can include any suitable components and combinations thereof that can be used to collect biometric data associated with users that interact with the HMI device 120 (e.g., the user 144 and the user 146). For example, the biometric reader can include one or more fingerprint scanners, cameras, eye scanning devices, and / or other similar types of biometric reading components and systems that can collect user biometric data. In some examples, the touch screen display 130 can include one or more built-in fingerprint reading components that can collect fingerprints from users that interact with the HMI device 120 in certain scenarios. The HMI device 120 can also include one or more fingerprint readers separate from the touch screen display 130 that can collect fingerprints from users that interact with the HMI device 120 in certain scenarios. The biometric reader 132, in some examples, can include one or more components that are separate from the HMI device 120 but interact with the HMI device 120 to facilitate user authentication processes. For example, a camera, an eye scanning device, and / or a fingerprint scanner separate from the HMI device 120 itself can be used to collect biometric data used by the HMI device 120 to authenticate users.|OO30] FIGS. 2-8 illustrate various examples of the screen 122, the GUI objects 123, the screen 124, and the GUI objects 125 that can be configured by the user 142 by accessing the HMI configuration software 112 via the engineering w orkstation 110 and accessed by the user 144 or the user 146 via the touch screen display 130 of the HMI device 120. The examples shown in FIGS. 2-8 are intended to assist the reader in understanding the disclosed subject matter, but are not intended to be limiting in any way. A wide variety of different types of screens and associated GUI elements can be configured and presented via the HMI device 120 depending on the application.
[0031] Referring to FIG. 2. an example implementation of the screen 122 as a machine control interface is shown, in accordance with some aspects of the disclosure. As shown, theGUI objects 123 presented on the machine control interface include virtual representations of mechanical switches and push buttons that can be used to affect the operation of the equipment 160. For example, the GUI objects 123 as shown include a switch that can be used to toggle a prime machine function between an off state and an automatic state. The GUI objects 123 as shown also include a jog conveyors push button that can be used to affect the operation of the equipment 160 by implementing a job function for one or more conveyors controlled by the control system 100. The GUI objects 123 as shown also include a switch that can be used to toggle a purge machine function between an off state and an automatic state. The GUI objects 123 as shown further include a reset product count push button that can be used to reset a product count associated with the control system 100 (e.g., a variable that counts the number of products produced by a manufacturing line over a given time period). The virtual representations of mechanical switches and push buttons as shown in FIG. 2 can be useful for presenting on the HMI device 120 in that they may be familiar to operators and technicians accustomed to interacting with these types of interface elements. The user 144 and / or the user 146 can select any of the GUI objects 123 as shown in FIG. 2 via the touch screen display 130 of the HMI device 120 to affect the operation of the equipment 160 in the control system 100. [00321 Referring to FIG. 3, an example implementation of the screen 122 as a restricted access interface is shown, in accordance with some aspects of the disclosure. As shown, the GUI objects 123 presented on the restricted access interface include an acknowledgement button and a logon window. For example, the acknowledgement button that reads “I agree with the above terms” can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to provide an indication that the user 144 acknowledged the terms as shown in FIG. 3. In some examples, upon selection of the acknow ledgement button by the user 144 via the touch screen display 130 of the HMI device 120, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, an iris scan, a retina scan, facial recognition data, etc.) from the user 144 according to instructions contained in the HMI application 121. Then, the authentication software 126 of the HMI device 120 can process the biometric data collected from the user 144 to grant an access level to the user 144 (e.g., administrator level, operator level, etc.). Depending on the access level granted to the user 144, the HMI device 120 can then present the screen 124 including the sensitive data 128 to the user 144 via the touch screen display 130 of the HMI device 120 according to instructions contained in the HMI application 121. By collecting and processing biometric data in this manner, the more traditional logon window requesting the user 144 to enter a name and password as shown in FIG. 3 may be bypassed. How ever, in some examples, the logon windowrequesting the user 144 to enter a name and password may also be used to authenticate the user 144.[00331 Referring to FIG. 4, an example implementation of the screen 122 as a user login interface is shown, in accordance with some aspects of the disclosure. As shown, the GUI objects 123 presented on the user login interface include an administrator logon button, a navigation button, and an error message. The administrator logon button can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to initiate a login event where the user 144 seeks to login to the HMI device 120 with administrator access level privileges, for example. In some examples, upon selection of the administrator logon button by the user 144 via the touch screen display 130 of the HMI device 120, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, facial recognition data, etc.) from the user 144 according to the instructions that are contained in the HMI application 121. Then, the authentication softw are 126 of the HMI device 120 can process the biometric data collected from the user 144 to either grant the user 144 the administrator access level privileges or deny the 144 the administrator access level privileges. If the authentication software 126 grants the user 144 the administrator access level privileges based on the collected biometric data, the authentication software 126 can allow- the user 144 to affect the operation of the equipment 160 and view or modify the sensitive data 128, for example. If the authentication software 126 does not grant the user 144 the administrator access level privileges based on the collected biometric data, the authentication software 126 can cause the HMI device 120 to present the error message indicating the user 144 has insufficient rights via the touch screen display 130 as shown in FIG. 4.[00.34| Similarly, the navigation button can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to initiate a navigation event where the user 144 seeks to navigate from the screen 122 to the screen 124 presented by the HMI device 120, for example. In some examples, upon selection of the navigation button by the user 144 via the touch screen display 130 of the HMI device 120, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, facial recognition data, etc.) from the user 144 according to the instructions contained in the HMI application 121. Then, the authentication software 126 of the HMI device 120 can process the biometric data collected from the user 144 to either allows the user 144 to navigate to the screen 124 or deny the user from navigating to the screen 124. If the authentication softw are 126 grants the user 144 a sufficient access level based on the collected biometric data, the authentication software 126 can allow the user 144 to navigate to the screen 124, where the user 144 can, for example,affect the operation of the equipment 160 and view or modify the sensitive data 128. If the authentication software 126 does not grant the user 144 a sufficient access level based on the collected biometric data, the authentication software 126 can cause the HMI device 120 to present the error message indicating the user 144 has insufficient rights via the touch screen display 130 as shown in FIG. 4.[0035 j Referring to FIG. 5, an example implementation of the screen 122 as a diagnostics interface is shown, in accordance with some aspects of the disclosure. As shown, the GUI objects 123 presented on the diagnostics interface include different types of selectable buttons, an alarms ovendew, and another error message. For example, as shown, the selectable buttons include a recipe button that can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to access and / or modify one or more recipes (e.g., definitions of settings used by the equipment 160 for various manufacturing lines in a manufacturing plant) used by the control system 100. The selectable buttons, as shown, also include an alarm history' button that can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to access historical alarm data associated with the control system 100 (e.g., for auditing purposes). The selectable butons, as shown, also include a system diagnostics buton that can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to access and / or modify diagnostic information associated with the control system 100 (e.g., key performance indicators (KPIs) associated with the control system 100 that can be used to diagnose and / or troubleshoot issues, sensor values, etc.). Also, the alarms overview as shown can include a listing of active alarms associated with the control system 100 and a selectable button (with a bell icon) buton that can be selected by the user 144 via the touch screen display 130 of the HMI device 120 to navigate from the screen 122 to the screen 124 (e.g., an alarms interface such as shown in FIG. 7.).|0036] Upon selection of any of the butons show n in diagnostics interface of FIG. 5 by the user 144 via the touch screen display 130 of the HMI device 120, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, facial recognition data, etc.) from the user 144 according to the instructions contained in the HMI application 121. Then, the authentication software 126 of the HMI device 120 can process the biometric data collected from the user 144 to either grant an appropriate access level to the user 144 or deny access. If the authentication softw are 126 grants the user 144 a sufficient access level to perform a given function associated with the selected button based on the collected biometric data, the authentication software 126 can allow the user 144 to perfonn that function via the HMI device 120. However, if the authentication software 126 cannot validate thecollected biometric data (e.g., due to poor fingerprint read, poor iris scan, no match found among the known users, etc.), the authentication software 126 can cause the HMI device 120 to present the error message indicating the user 144 provided an invalid logon command and the security level (access level) has been restored to zero via the touch screen display 130 as shown in FIG. 5.
[0037] Referring to FIG. 6, an example implementation of the screen 122 as a machine control interface including a login window is shown, in accordance with some aspects of the disclosure. As shown, the GUI objects 123 presented on the machine control interface include a visual representation of a control process and associated data (e.g., maximum and minimum scan times) as well as the login window overtaxed on the visual representation of the control process and associated data. That is, the user 144, for example, can launch the login window as shown in FIG. 6 directly from a control interface to initiate a login event. As shown, the user 144 can select a particular one of the GUI objects 123 presented on the login window that is associated with an access level desired by the user 144 via the touch screen display 130, such as, for example, a production manager button, a maintenance button, a supervisor button, and an operator button as shown. The user 144 can also select a login button, a logoff button, a set user accounts button (e.g., to configure access levels associated with different users), and a done button presented on the login window via the touch screen display 130.
[0038] Upon selection of any of the buttons shown on the login window in FIG. 6 by the user 144 via the touch screen display 130 of the HMI device 120, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, facial recognition data, etc.) from the user 144 according to the instructions contained in the HMI application 121. Then, the authentication software 126 of the HMI device 120 can process the biometric data collected from the user 144 to either grant an appropriate access level to the user 144 or deny access. For example, responsive to receiving a selection of the maintenance button and / or a selection of the logon button, the authentication software 126 can evaluate the biometric data collected from the user 144 to determine whether the user 144 has sufficient rights to be granted the requested maintenance access level.[0039| Referring to FIG. 7, an example implementation of the screen 124 as an alarms interface is shown, in accordance with some aspects of the disclosure. As shown, the GUI objects 125 presented on the alarms interface include a listing of active and / or historical alarms, a history button, an alarm reset button, and an alann button. In some examples, the listing of active and / or historical alarms as shown in FIG. 7 can be part of the sensitive data 128 managed by the HMI device 120. The alarms interface allows the user 144 or the user 146 to easily viewand manage various types of alarms associated with the control system 100. The user 144, for example, can also select the alarm history button to access historical alarm data associated with the control system 100 (e.g., for auditing purposes). The user 144 can additionally select the alarm reset button to clear the alarms shown in the listing of active and / or historical alarms and thereby, in some examples, modify the sensitive data 128. The user 144 can further select the alarm button to perform any suitable additional functions related to alarms in the control system 100. Upon selection of any of the buttons shown in the alarm interface by the user 144 via the touch screen display 130 of the HMI device 120, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, facial recognition data, etc.) from the user 144 according to the instructions contained in the HMI application 121. Then, the authentication software 126 of the HMI device 120 can process the biometric data collected from the user 144 to either grant an appropriate access level to the user 144 or deny access.[00401 Referring to FIG. 8, an example implementation of the screen 124 as a sensitive data interface is shown, in accordance with some aspects of the disclosure. As shown, the GUI objects 125 presented on the sensitive data interface include various buttons and other types of process data indicator elements for presenting a variety of data associated with the control system 100 to the user 144 or the user 146 upon granting the user 144 or the user 146 an appropriate access level (e.g., an administrator access level). For example, via the sensitive data interface as shown in FIG. 8, the user 144 can view a variety of sensor data associated with the control system 100 as well as a listing of active alarms associated with the control system 100. Additionally, via the sensitive data interface as shown in FIG. 8, the user 144 can modify the sensitive data 128 (e.g., by selecting an acknowledge alarms button, selecting a remove door button, configuring variable limits, etc.) by interacting with the GUI objects 125. Upon selection of any of the GUI objects 125 shown in FIG. 8, or upon a timeout, for example, the biometric reader 132 of the HMI device 120 can collect biometric data (e.g., a fingerprint, eye tracking data, facial recognition data, etc.) from the user 144 according to the instructions contained in the HMI application 121. Then, the authentication software 126 of the HMI device 120 can process the biometric data collected from the user 144 to either grant an appropriate access level to the user 144 or deny access.100411 Referring to FIG. 9, a How diagram illustrating an example process 900 for use in the control system 100 to authenticate users interacting with the HMI device 120 is shown, in accordance with some aspects of the disclosure. The process 900 can be performed by the HMI device 120 as described above. For example, the HMI application 121 stored in the memory136 of the HMI device 120 can include machine-readable instructions executable by the processing circuitry 134 to implement the process 900. Advantageously, the process 900 can provide various improvements in terms of ease of use, efficiency, and security within the control system 100. In some previous approaches, user level access at HMI devices may be predicated on a login process that uses a particular username and password. However, in these approaches, a logged-in user typically needs to exit a given screen before a new user with different access level permissions can login to the HMI device, thereby creating inefficiencies and preventing multiple users from simultaneously or nearly simultaneously accessing the HMI device. Moreover, entry of all the characters needed for a username and password via an industrial ty pe of touch screen display can be time consuming and cumbersome, and can also introduce various security risks depending on the application.[0042} Advantageously, the process 900 can be used to provide different access levels to different users accessing the same GUI on the HMI device 120 at the same time. The process 900 can provide this functionality by, in some examples, reauthenticating users on each input (e.g., through in-screen fingerprint reading, eye scanning, camera images and / or video, etc.). For example, consider a scenario where the user 144 has operator level access privileges and the user 146 has administrator level access privileges. By implementing the process 900 for authentication, the user 144 can be using the screen 122 presented on the touch screen display 130, and the user 146 can be looking over the shoulder of the user 144 and see something on the screen 122 that is potentially problematic for the control system 100. In such a scenario, the user 146 can reach over and active administrator level controls and / or access permissions (e.g., shutdowns, alarms, etc.) without logging the user 144 out of the HMI device 120 and without requiring the user 146 to log into the HMI device 120. The user 144 can keep using any portions of the screen 122 that do not require the elevated permissions, while the user 146 can at the same time bring up the administrator level controls and / or access permissions.[0043| At 902, the process 900 can include receiving a first input from a user via a touch screen display of an HMI device. For example, the first input can include a selection of any of the GUI objects 123 presented on the screen 122 by the user 144 via the touch screen display 130 of the HMI device 120. The first input can also include other types of interactions with the touch screen display 130 of the HMI device 120, such as, for example, tapping a screen saver or otherwise providing an input to “wake up” the HMI device 120. The first input can be provided to the HMI device 120 by the user 144 in a variety of ways, such as, for example, by a human using one or more fingers to tap, touch, press, swipe, slide, or otherwise provide a gesture via the touch screen display 130. Also, the first input can be provided to the HMIdevice 120 using some type of object, such as, for example, a pen or another type of object that can be sensed by the touch screen display 130. The first input can include a selection by the user 144 of the acknowledgement button as shown in the restricted access interface of FIG. 3 by the user 144, a selection of the administrator logon button or the navigation button as shown in the user login interface of FIG. 4 by the user 144, or a selection of any of the buttons as shown on the login window in FIG. 6 by the user 144. for example, among various other types of inputs that can be provided by the user 144 via the touch screen display 130.[0044J At 904, the process 900 can include collecting biometric data from the user responsive to receiving the first input from the user. For example, upon receiving the first input from the user 144, the authentication software 126 can determine that the user 144 has not been granted an access level (e.g.. because the user 144 has never previously logged into the HMI device 120, because a session timeout has occurred for the user, etc.). Accordingly, the authentication software 126 can collect biometric data from the user 144 using the biometric reader 132. The biometric reader 132 can include any suitable components and combinations thereof that can be used to collect biometric data associated with the user 144, such as, for example, one or more fingerprint scanners, cameras, eye scanning devices, and / or other similar types of biometric reading components and systems that can collect user biometric data. The biometric data itself can include any suitable type of biometric data used to authenticate the user 144, such as, for example, a fingerprint, eye tracking data, an iris scan, a retina scan, facial recognition data, and / or other suitable types of biometric data.[0045J In some examples, the HMI device 120 can collect the biometric data from the user 144 at 904 when the user 144 provides the first input (e.g., the biometric reader 132 can collect a fingerprint from the user 144 when the user 144 provides the first input). The HMI device 120 can also collect the biometric data from the user 144 at 904 after the user provides the first input. For example, the HMI device 120 can prompt the user 144 (e.g., by providing an alert on the touch screen display 130, by illuminating a fingerprint scanner, etc.) to provide the biometric data (e.g., by providing a fingerprint via a fingerprint scanner, by providing a retina scan or an iris scan via an eye scanning device, by providing facial imaging and / or video data toa camera, etc.). The HMI device 120 can also initiate a biometric data collection event responsive to receiving the first input, such as, for example, by activating a camera or activating an eye scanning device, among other possible examples of initiating a biometric data collection event.
[0046] At 906. the process 900 can include processing the biometric data to grant an access level to the user. For example, the authentication software 126 can process the biometric datareceived by the user 144 to grant an appropriate access level to the user 144. The access level can be any of a variety’ of types of access levels with different associated privileges, such as, for example, an administrator level, a supervisor level, an operator level, a maintenance level, and any other type of access level configured by the user 142 by accessing the HMI configuration software 112 via the engineering workstation 110 and downloading the HMI application 121 to the HMI device 120. The privileges can include varying levels of privileges related to affecting operation of the equipment 160 in the control system 100, accessing and / or modifying the sensitive data 128, and other suitable types of privileges configured by the user 142 by accessing the HMI configuration software 112 via the engineering workstation 110 and downloading the HMI application 121 to the HMI device 120. The authentication software 126 can determine an appropriate access level to grant to the user 144 by comparing the biometric data received at 904 to the biometric data associated with the known set of users as configured by the user 142 by accessing the HMI configuration software 112 via the engineering workstation 110 and downloading the HMI application 121 to the HMI device 120 among other possible approaches to determining the appropriate access level to grant to the user 144.[0047| At 908, the process 900 can include receiving a second input from the user selecting a GUI object presented on the touch screen display. For example, the second input can again include a selection of any of the GUI objects 123 presented on the screen 122 or any of the GUI objects 125 presented on the screen 124 by the user 144 via the touch screen display 130 of the HMI device 120. The second input can be provided to the HMI device 120 in a variety of ways by the user 144, such as, for example, by a human that uses one or more fingers to tap, touch, press, swipe, slide, or otherwise provide a gesture via the touch screen display 130. Also, the second input can be provided to the HMI device 120 by the user 144 using some type of object, such as, for example, a pen or another type of object that can be sensed by the touch screen display 130. The second input can include a selection of any of the virtual representations of mechanical switches and push buttons as shown in the machine control interface of FIG. 2 by the user 144, a selection of the navigation button as shown in the user login interface of FIG. 4 by the user 144, a selection of the recipe button as shown in the diagnostics interface of FIG. 5 by the user 144, or a selection of the alarm reset button as shown in the alarms interface of FIG. 7 by the user 144, among various other types of inputs that can be provided by the user 144 via the touch screen display 130.
[0048] At 910. the process 900 can include determining whether or not the user is authorized to perform an action based on the access level granted to the user. For example, theauthentication software 126 can identify one or more functions associated with the GUI object selected at 908 based on the configuration of the selected GUI object as defined by the HMI application 121. The functions associated with the GUI object selected at 908 can be configured by the user 142 via the HMI configuration software 112 accessed on the engineering workstation 110. The authentication software 126 can then evaluate the one or more functions associated with the selected GUI object relative to the privileges defined by the access level granted to the user 144 at 906 to determine whether the user 144 is authorized to perform an action associated with the selected GUI object. For example, if the access level granted to the user 144 at 906 is an administrator access level, the authentication software 126 can authorize the user 144 to perform actions including both affecting the operation of the equipment 160 and accessing and / or modifying the sensitive data 128. However, if the access level granted to the user 144 at 906 is an operator access level, the authentication software 126 can authorize the user 144 to perform actions including affecting the operation of the equipment 160 but deny the user 144 from performing actions including and accessing and / or modify ing the sensitive data 128.[00491 At 912, the process 900 can include allowing the user to perform the action or denying the user responsive to the determination about whether the user is authorized to perform the action based on the access level granted to the user. For example, if the authentication software 126 determines that the user 144 is indeed authorized to affect the operation of the equipment 160, the authentication software 126 can allow the user 144 to send a control signal to the equipment 1 0 to affect the operations of the equipment 160. However, if the authentication software 126 determines that the user 144 is not authorized to affect the operation of the equipment 160, the authentication software 126 can cause the HMI device 120 to present an error message to the user 144 via the touch screen display 130. Similarly, if the authentication software 126 determines that the user 144 is indeed authorized to view and / or modify the sensitive data 128, the authentication software 126 can cause the HMI device 120 to present the screen 124 including the sensitive data 128 instead of the screen 122 to the user 144 via the touch screen display 130. However, if the authentication software 126 determines that the user 144 is not authorized to view and / or modify the sensitive data 128, the authentication softw are 126 can cause the HMI device 120 to present an error message to the user 144 via the touch screen display 130.|OO50] At 914, the process 900 can include receiving a third input from the user via the touch screen display of the HMI device. For example, the third input can again include a selection of any of the GUI objects 123 presented on the screen 122 by the user 144 via the touch screendisplay 130 of the HMI device 120. The third input can also include other ty pes of interactions with the touch screen display 130 of the HMI device 120, such as, for example, tapping a screen saver or otherwise providing an input to “wake up” the HMI device 120. The third input can be provided to the HMI device 120 in a variety of ways, such as, for example, by a human using one or more fingers to tap, touch, press, swipe, slide, or otherwise provide a gesture via the touch screen display 130. Also, the third input can be provided to the HMI device 120 using some type of object, such as, for example, a pen or another type of object that can be sensed by the touch screen display 130. The third input can include any suitable type of input similar to the first input and / or the second input.[00511 At 916, the process 900 can include determining that a predetermined period of time has elapsed since the first input and / or the second input was received. For example, the authentication software 126 can determine that a predetermined period of 10 seconds, 30 seconds, 2 minutes, 5 minutes, or any other suitable period of time as defined by the HMI application 121 has elapsed. This timeout period can be used to provide an added layer of security’ by preventing unauthorized access to control functionality for the equipment 160 and / or the sensitive data 128 via the HMI device 120. Upon determining that the predetermined period of time has elapsed since the first input and / or the second input yvas received, the authentication software 126 can reset a current access level for the HMI device 120 to zero, for example. The authentication software 126 can also implement a variety of added security layers in addition to or instead of the timeout period. For example, using eye tracking data from the biometric reader 132, the authentication software 126 can determine that the user 144 has looked away from the touch screen display 130 for a predetermined period of time (e.g., 5 seconds, 10 seconds, etc.) and reset the current access level for the HMI device 120 to zero, among a variety of other possible approaches.
[0052] At 918, the process 900 can include collecting second biometric data from the user in response to determining that the predetermined period of time has elapsed since the first input and / or the second input was received. For example, the authentication software 126 can collect biometric data from the user 144 using the biometric reader 132. The biometric reader 132 can again include any suitable components to collect biometric data associated with the user 144, such as, for example, one or more fingerprint scanners, cameras, eye scanning devices, and / or other similar types of biometric reading components and systems that can collect user biometric data. The second biometric data can again include any suitable type of biometric data used to authenticate the user 144, such as. for example, a fingerprint, eye tracking data, an iris scan, a retina scan, facial recognition data, and / or other suitable types of biometric data. At 920, theprocess 900 can include processing the second biometric data to grant the access level to the user. For example, the authentication software 126 can process the second biometric data received by the user 144 to grant the user 144 the same access level as granted at 906.10053] In some examples, certain steps of the process 900 can be repeated as appropriate for a second user, such as, for example, the user 146. Also, while the steps of the process 900 are shown in a particular order in FIG. 9, the process 900 may not include all steps shown, may include additional steps, or may include the steps in a different order. For example, the user 144 may timeout between providing the first input and the second input, among various other possibilities.|0054| Referring to FIG. 10, a flow diagram illustrating an example process 1000 for use in the control system 100 to authenticate interactions with the HMI device 120 is shown, in accordance with some aspects of the disclosure. The process 1000 can be performed by the HMI device 120 as described above. For example, the HMI application 121 stored in the memory7136 of the HMI device 120 can include machine-readable instructions that can be executed by the processing circuitry 134 to implement the process 1000. Advantageously, the process 900 can provide various improvements in terms of ease of use, efficiency, and secunty within the control system 100. In some previous approaches, user level access at HMI devices may be predicated on a login process that uses a particular username and password. How ever, in these approaches, a logged-in user typically needs to exit a given screen before a new user with different access level permissions can login to the HMI device, thereby creating inefficiencies and preventing multiple users from simultaneously or nearly simultaneously accessing the HMI device. Moreover, entry of all the characters needed for a username and password via an industrial type of touch screen display can be time consuming and cumbersome, and can also introduce various security risks depending on the application.|0055] Advantageously, the process 1000 can also be used to provide different access levels to different users accessing the same GUI on the HMI device 120 at the same time. The process 1000 can provide this functionality' by, in some examples, reauthenticating users on each input (e.g., through in-screen fingerprint reading, eye scanning, camera images and / or video, etc.). For example, consider a scenario where the user 144 has operator level access privileges and the user 146 has administrator level access privileges. By using the process 1000 for authentication, the user 144 can be using the screen 122 presented on the touch screen display 130, and the user 146 can be looking over the shoulder of the user 144 and see something on the screen 122 that is potentially problematic for the control system 100. In such a scenario, the user 146 can reach over and active administrator level controls and / or access permissions(e.g., shutdowns, alarms, etc.) without logging the user 144 out of the HMI device 120 and without requiring the user 146 to log into the HMI device 120. The user 144 can keep using any portions of the screen 122 that do not require the elevated permissions, while the user 146 can at the same time bring up the administrator level controls and / or access permissions.
[0056] At 1002, the process 1000 can include receiving a first input including a first interaction with a touch screen display of an HMI device. For example, the first input can include a selection of any of the GUI objects 123 presented on the screen 122 made by the user 144 via the touch screen display 130 of the HMI device 120. The first input can also be received based on other ty pes of interactions with the touch screen display 130 of the HMI device 120, such as, for example, tapping a screen saver or otherwise providing an input to “wake up’' the HMI device 120. The first input can be provided to the HMI device 120 in a variety of ways, such as, for example, by a human using one or more fingers to tap, touch, press, swipe, slide, or otherwise provide a gesture via the touch screen display 130. Also, the first input can be provided to the HMI device 120 using some ty pe of object, such as, for example, a pen or another type of object that can be sensed by the touch screen display 130. The first input can include a selection by the user 144 of the acknowledgement button as shown in the restricted access interface of FIG. 3 by the user 144, a selection of the administrator logon button or the navigation button as show n in the user login interface of FIG. 4 by the user 144, or a selection of any of the buttons as shown on the login window in FIG. 6 by the user 144, for example, among various other types of inputs that can be provided by the user 144 via the touch screen display 130.
[0057] At 1004, the process 1000 can include collecting first biometric data while receiving the first input. For example, responsive to detecting the first interaction with the touch screen display 130, the biometric reader 132 can collect the first biometric data associated with the first input. The first biometric data can include only a fingerprint, only facial recognition data, only eye scan data (e.g., retina scan or iris scan), or only another suitable type of biometric data associated with the first input. The first biometric data can also include various combinations of different types of biometric data associated with the first input, such as a fingerprint and facial recognition data, a fingerprint and eye scan data, and other combinations. Depending on the application, various advantages can be provided when collecting certain ty pes and / or combinations of biometric data associated with the first input. For example, if personnel at a given facility wear certain types of protective equipment (e.g., gloves, masks, etc.), some types of biometric data may not be suitable (e.g., fingerprints, facial recognition). In collecting thefirst biometric data while receiving the first input, the process 1000 can provide improved efficiency in terms of user authentication when compared to some previous approaches.(00581 At 1006, the process 1000 can include processing the first biometric data to grant a first access level for the first input. For example, the authentication software 126 can process the first biometric data to grant an appropriate access level for the first input. The access level can be any of a variety of types of access levels with different associated privileges, such as, for example, an administrator level, a supervisor level, an operator level, a maintenance level, and any other type of access level that can be configured by the user 142 by accessing the HMI configuration software 112 via the engineering workstation 110 and downloading the HMI application 121 to the HMI device 120. The privileges can include varying levels of privileges related to affecting operation of the equipment 160 in the control system 100. accessing and / or modifying the sensitive data 128, and other suitable types of privileges. The authentication software 126 can identify the appropriate access level to grant for the first input by comparing the first biometric data to the biometric data associated with the known set of users as configured by the user 142 via the HMI configuration software 112, for example, among other possible approaches to determining the appropriate access level to grant for the first input. The authentication software 126 can map the first biometric data collected at 1004 to an appropriate access level defined by the HMI application 121. In some examples, granting the first access level at 1006 can include logging a first user account associated with the first biometric data into the HMI device 120. The first user account can be associated with a particular individual and / or can be associated with the first access level, among other possible implementations of a user account.[0059| At 1008, the process 1000 can include performing a first action associated with a control system based on the first input in accordance with the first access level. The HMI device 120 can perform any of a variety of suitable functions responsive to receiving the first input in accordance with the first access level. For example, if the HMI device 120 receives the first input from an operator, the first action can be any suitable type of standard operator action that may be performed by the HMI device 120. For example, the first input can include a selection of the jog conveyors push button as shown in FIG. 2. If the first access level indicates authorization to perform a jog conveyors action associated with the jog conveyors push button, then the first action can include performing the jog conveyors action. However, if the first access level does not indicate authorization to perform the jog conveyors action associated with the jog conveyors push button, then the first action can include presenting an error message on the touch screen display 130. The first action can also include presenting thescreen 124 or presenting operating data associated with the control system 100, among other suitable types of actions.
[0060] At 1010, the process 1000 can include receiving a second input including a second interaction with the touch screen display of the HMI device. For example, the second input can include a selection of any of the GUI objects 123 presented on the screen 122 made by the user 146 via the touch screen display 130 of the HMI device 120. Notably, the second input can be received via the same screen (e.g., the screen 122) presented on the touch screen display 130 of the HMI device 120 as the first input. The second input can be received based on a variety of types of interactions with the touch screen display, such as, for example, by a human using one or more fingers to tap, touch, press, swipe, slide, or otherwise provide a gesture via the touch screen display 130. Also, the second input can be received by the HMI device 120 via some type of object, such as, for example, a pen or another type of object that can be sensed by the touch screen display 130. The second input can include a selection by the user 146 of the administrator logon button or the navigation button as shown in the user login interface of FIG. 4 or a selection of any of the buttons as shown on the login window in FIG. 6 by the user 146, for example, among various other types of inputs. The second input can advantageously be received by the HMI device 120 at a time when the first user account associated with the first input is still logged into the HMI device 120. Additionally, various steps of the process 1000 including 1012, 1014, 1016, and / or other aspects of the process 1000 can be performed without logging the first user account out of the HMI device 120 and / or without logging a second user account associated with the second biometric data into the HMI device 120.[0061 | At 1012, the process 1000 can include collecting second biometric data while receiving the second input. For example, responsive to detecting the second interaction with the touch screen display 130, the biometric reader 132 can collect the second biometric data associated with the second input. The second biometric data can include only a fingerprint, only facial recognition data, only eye scan data (e.g., retina scan or iris scan), or only another suitable ty pe of biometric data associated with the second input. The second biometric data can alternatively include various combinations of different types of biometric data associated with the second input, such as a fingerprint and facial recognition data, a fingerprint and eye scan data, and other combinations. Depending on the application, various advantages can be provided when collecting certain types and / or combinations of biometric data associated with the second input. For example, if personnel at a given facility w ear certain types of protective equipment (e.g., gloves, masks, etc.), some types of biometric data may not be suitable (e.g., fingerprints, facial recognition). In collecting the second biometric data while receiving thesecond input, the process 1000 can provide improved efficiency in terms of user authentication when compared to some previous approaches.[00621 At 1014, the process 1000 can include processing the second biometric data to grant a second access level for the second input. For example, the authentication software 126 can process the second biometric data to grant an appropriate access level for the second input. The access level can be any of a variety of types of access levels with different associated privileges, such as, for example, an administrator level, a supervisor level, an operator level, a maintenance level, and any other type of access level that can be configured via the HMI configuration software 112. The privileges can include varying levels of privileges related to affecting operation of the equipment 160 in the control system 100, accessing and / or modifying the sensitive data 128, and other suitable types of privileges. The authentication software 126 can identify the appropriate access level to grant for the second input by comparing the second biometric data to the biometric data associated with the known set of users as configured via the HMI configuration software 112, for example, among other possible approaches to determining the appropriate access level to grant for the second input. The authentication software 126 can map the second biometric data collected at 1012 to an appropriate access level defined by the HMI application 121.1 063] At 1016, the process 1000 can include performing a second action associated with the control system based on the second input in accordance with the second access level. For example, the second action can include sending a control signal to the equipment 160 in the control system 100 to affect operation of the equipment 160 in the control system 100. The second action can also include causing the touch screen display 130 to present the screen 124 including one or more of the GUI objects 125, where one or more of the GUI objects 125 allow access and / or modification of the sensitive data 128. The second action can further include causing the touch screen display 130 to present an administrator window (e.g., on the screen 122) including administrator level GUI objects selectable to perform administrator level functions, presenting an errors message, or other possible ty pes of actions. For example, the second input can again include a selection of the jog conveyors push button as shown in FIG. 2. If the second access level indicates authorization to perform a jog conveyors action associated with the jog conveyors push button, then the second action can include sending a control signal to the equipment 160 via the network 150 that causes the equipment 160 to perform the jog conveyors action. However, if the second access level does not indicate authorization to perform the jog conveyors action associated with the jog conveyors pushbuton, then the second action can again include presenting an error message on the touch screen display 130.[0064| In some examples, certain steps of the process 1000 can be repeated as appropriate for additional inputs. Also, while the steps of the process 1000 are shown in a particular order in FIG. 10, the process 1000 may not include all steps shown, may include additional steps, or may include the steps in a different order. For example, in scenarios where the second action performed at 1016 includes causing the touch screen display 130 to present an administrator window including administrator level GUI objects selectable to perform administrator level functions, a third input can be received by the HMI device 120 including a third interaction with the touch screen display 130. The third interaction can include a selection of a second graphical user interface element presented on the administrator window, and the second action performed at 1016 can include sending a control signal to the equipment 160 based on the third interaction.[0065| Moreover, the authentication software 126 can implement a variety of different timeout periods within the process 1000 to provide additional security layers for the HMI device 120. For example, the authentication software 126 can cause the administrator window to be removed from the screen 122 responsive to determining that a predetermined period of time has elapsed since the HMI device 120 received the second input or received the third input. The authentication software 126 can also reset the timeout period (e.g., 5 seconds. 10 seconds, 30 seconds, etc.) associated with the administrator window, or any other timeout period, each time the authentication software 126 grants a certain access level based on biometric data (e.g., each time the authentication software 126 grants an administrator access level).[0066| This disclosure is not limited in its application to the details of construction and the arrangement of components set forth in this description or illustrated in the accompanying drawings. The disclosure is capable of other embodiments and of being practiced or of being carried out in various ways. Also, it is to be understood that the phraseology and terminology used herein is for the purpose of description and should not be regarded as limiting. The use of '■including", "comprising", "containing", or “having’7and variations thereof herein is meant to encompass the items listed thereafter and equivalents thereof as well as additional items. Unless specified or limited otherwise, the terms “mounted”, “connected”, “supported”, “coupled”, and different variations thereof are used broadly and encompass both direct and indirect mountings, connections, supports, and couplings. Further, “connected” and "coupled” are not restricted to physical or mechanical connections or couplings.
[0067] Some embodiments, including computerized implementations of methods according to the disclosure, can be implemented as a system, method, apparatus, or article of manufacture using standard programming or engineering techniques to produce software, firmware, hardware, or any combination thereof to control a processor device (e.g., a serial or parallel processor chip, a single- or multi-core chip, a microprocessor, a field programmable gate array, any variety of combinations of a control unit, arithmetic logic unit, and processor register, and so on), a computer (e.g., a processor device operatively coupled to a memory), or another electronically operated controller to implement aspects detailed herein. Accordingly, for example, embodiments of the disclosure can be implemented as a set of instructions, tangibly embodied on a non-transitory computer-readable media, such that a processor device can implement the instructions based upon reading the instructions from the computer-readable media.
[0068] Some embodiments of the disclosure can include (or utilize) a control device such as, for example, an automation device, a computer including various computer hardware, software, firmware, and so on, consistent with the discussion below. As specific examples, a control device can include a processor, a microcontroller, a field-programmable gate array, a programmable logic controller, logic gates, etc., and other typical components that are known in the art for implementation of appropriate functionality (e.g., memory, communication systems, power sources, user interfaces and other inputs, etc.). Also, functions performed by multiple components may be consolidated and performed by a single component. Similarly, the functions described herein as being performed by one component may be performed by multiple components in a distributed manner. Additionally, a component described as performing particular functionality' may also perform additional functionality' not described herein. For example, a device or structure that is “configured” in a certain way is configured in at least that way, but may also be configured in ways that are not listed.
[0069] The term “article of manufacture” as used herein is intended to encompass a computer program accessible from any computer-readable device, carrier (e.g., non-transitory signals), or media (e.g., non-transitory media). For example, non-transitory computer-readable media can include but are not limited to magnetic storage devices (e.g., hard disk, floppy disk, magnetic strips, and so on), optical disks (e.g., compact disk (“CD”), digital versatile disk (“DVD”’), and so on), smart cards, and flash memory' devices (e.g., card, stick, and so on). Additionally, it should be appreciated that a carrier wave can be employed to carry computer- readable electronic data such as, for example, those used in transmitting and receiving electronic mail or in accessing a network such as, for example, the Internet or a local areanetwork (“LAN”). Those skilled in the art will recognize that many modifications may be made to these configurations without departing from the scope or spirit of the claimed subject matter.|0070] Certain operations of methods according to the disclosure, or of systems executing those methods, may be represented schematically in the figures or otherwise discussed herein. Unless otherwise specified or limited, representation in the figures of particular operations in particular spatial order may not necessarily require those operations to be executed in a particular sequence corresponding to the particular spatial order. Correspondingly, certain operations represented in the figures, or otherwise disclosed herein, can be executed in different orders than are expressly illustrated or described, as appropriate for particular embodiments of the disclosure. Further, in some embodiments, certain operations can be executed in parallel, including by dedicated parallel processing devices, or separate computing devices configured to interoperate as part of a large system.(0071] As used herein in the context of computer implementation, unless otherwise specified or limited, the tenns “component,” “system,” “module,” and the like are intended to encompass part or all of computer-related systems that include hardware, software, a combination of hardware and software, or software in execution. For example, a component may be, but is not limited to being, a processor device, a process being executed (or executable) by a processor device, an object, an executable, a thread of execution, a computer program, or a computer. By way of illustration, both an application running on a computer and the computer can be a component. One or more components (or system, module, and so on) may reside within a process or thread of execution, may be localized on one computer, may be distributed betw een two or more computers or other processor devices, or may be included within another component (or system, module, and so on).|0072] In some implementations, devices or systems disclosed herein can be utilized or installed using methods embodying aspects of the disclosure. Correspondingly, description herein of particular features, capabilities, or intended purposes of a device or system is generally intended to inherently include disclosure of a method of using such features for the intended purposes, a method of implementing such capabilities, and a method of installing disclosed (or otherwise known) components to support these purposes or capabilities. Similarly, unless otherwise indicated or limited, discussion herein of any method of manufacturing or using a particular device or system, including installing the device or system, is intended to inherently include disclosure, as embodiments of the disclosure, of the utilized features and implemented capabilities of such device or system.[00731 As used herein, unless otherwise defined or limited, ordinal numbers are used herein for convenience of reference based generally on the order in which particular components are presented for the relevant part of the disclosure. In this regard, for example, designations such as, for example, “first,” “second,” etc., generally indicate only the order in which the relevant component is introduced for discussion and generally do not indicate or require a particular spatial arrangement, functional or structural primacy or order.
[0074] As used herein, unless otherwise defined or limited, directional terms are used for convenience of reference for discussion of particular figures or examples. For example, references to downw ard (or other) directions or top (or other) positions may be used to discuss aspects of a particular example or figure, but do not necessarily require similar orientation or geometry in all installations or configurations.10075] As used herein, unless otherwise defined or limited, the phase “and / or” used with tw o or more items is intended to cover or include the items individually and the items together. For example, a device having “a and / or b” is intended to cover or include: a device having a (but not b); a device having b (but not a); and a device having both a and b.
[0076] This discussion is presented to enable a person skilled in the art to make and use embodiments of the disclosure. Various modifications to the illustrated examples will be readily apparent to those skilled in the art, and the generic principles herein can be applied to other examples and applications without departing from the principles disclosed herein. Thus, embodiments of the disclosure are not intended to be limited to embodiments shown, but are to be accorded the widest scope consistent with the principles and features disclosed herein and the claims below; The provided detailed description is to be read with reference to the figures, in which like elements in different figures have like reference numerals. The figures, which are not necessarily to scale, depict selected examples and are not intended to limit the scope of the disclosure. Skilled artisans will recognize the examples provided herein have many useful alternatives and fall within the scope of the disclosure.
[0077] While the inventive subject matter herein disclosed has been described in terms of specific embodiments and applications thereof, numerous modifications and variations could be made thereto by those skilled in the art without departing from the scope of the inventive subject matter set forth in the claims.
Claims
CLAIMS1. A human machine interface device for use in a control system, comprising: a touch screen display; and processing circuitry configured to: receive a first input comprising a first interaction with the touch screen display; collect first biometric data while receiving the first input, the first biometric data comprising a first fingerprint; process the first biometric data comprising the first fingerprint to grant a first access level for the first input; perform an action associated with the control system based on the first input in accordance with the first access level ; receive a second input comprising a second interaction with the touch screen display, the second interaction comprising a selection of a graphical user interface element presented on the touch screen display that is selectable via the touch screen display to affect operation of equipment in the control system; collect second biometric data while receiving the second input, the second biometric data comprising a second fingerprint; process the second biometric data comprising the second fingerprint to grant a second access level for the second input, the second access level different from the first access level; and send a control signal to the equipment in the control system to affect the operation of the equipment in the control system based on the second input responsive to determining that the second access level indicates authorization to affect the operation of the equipment in the control system.
2. The human machine interface device of claim 1 , wherein a first user account associated with the first input is logged into the human machine interface device at a time when the second input is received.
3. The human machine interface device of claim 1. the processing circuitry configured to receive both the first input and the second input while a first screen is presented on the touch screen display.
4. The human machine interface device of claim 3. the processing circuitry configured to:cause the touch screen display to present an administrator window on the first screen responsive to receiving the second input; receive a third input comprising a third interaction with the touch screen display, the third interaction comprising a selection of a second graphical user interface element presented on the administrator window on the first screen; and send the control signal to the equipment in the control system to affect the operation of the equipment in the control system based on the third input.
5. The human machine interface device of claim 4, the processing circuitry configured to: determine that a predetermined period of time has elapsed since the third input was received; and cause the administrator window to be removed from the first screen presented on the touch screen display responsive to determining that the predetermined period of time has elapsed since the third input was received.
6. The human machine interface device of claim 1, the processing circuitry configured to: receive a fourth input comprising a fourth interaction with the touch screen display, the fourth interaction comprising a second selection of the graphical user interface element presented on the touch screen display that is selectable via the touch screen display to affect the operation of the equipment in the control system; collect third biometric data while receiving the fourth input, the third biometric data comprising a third fingerprint; process the third biometric data comprising the third fingerprint to grant the first access level for the third input; and cause the touch screen display to present an error message responsive to determining that the first access level does not indicate authorization to affect the operation of the equipment in the control system.
7. The human machine interface device of claim 1, wherein: the processing circuitry' is configured to receive, from an external device, an application file comprising biometric data associated with a known set of users and the graphical user interface element that is selectable via the touch screen display to affect the operation of the equipment in the control system; and to process the second biometric data comprising the second fingerprint to grant the second access level, the processing circuitry is configured to compare the second fingerprint to the biometric data associated with the known set of users.
8. The human machine interface device of claim 1, wherein: the human machine interface device comprises a camera; the second biometric data comprises eye tracking data generated using the camera; and the processing circuitry is configured to process the second biometric data comprising both the second fingerprint and the eye tracking data to grant the second access level for the second input.
9. The human machine interface device of claim 1, wherein: the human machine interface device comprises a camera; the second biometric data comprises facial recognition data generated using the camera; and the processing circuitry is configured to process the second biometric data comprising both the second fingerprint and the facial recognition data to grant the second access level for the second input.
10. The human machine interface device of claim 1. wherein: the human machine interface device comprises an eye scanning device; the second biometric data comprises an iris scan or a retina scan generated using the eye scanning device; and the processing circuitry’ is configured to process the second biometric data comprising both the second fingerprint and the iris scan or the retina scan to grant the second access level for the second input.1 1. One or more non-transitory computer-readable storage media having instructions stored thereon that, when executed by processing circuitry, cause the processing circuitry to implement operations comprising: receiving, at a human machine interface device in a control system, a first input comprising a first interaction with a touch screen display of the human machine interface device; collecting, at the human machine interface device, first biometric data while receiving the first input; processing, at the human machine interface device, the first biometric data to grant a first access level for the first input; performing, by the human machine interface device, an action associated with the control system based on the first input in accordance with the first access level;receiving, at the human machine interface device, a second input comprising a second interaction with the touch screen display, the second interaction comprising a selection of a graphical user interface element presented on the touch screen display that is selectable via the touch screen display to affect operation of equipment in the control system; collecting, at the human machine interface device, second biometric data while receiving the second input; processing, at the human machine interface device, the second biometric data to grant a second access level for the second input, the second access level different from the first access level; and sending, from the human machine interface device, a control signal to the equipment in the control system to affect the operation of the equipment in the control system based on the second input responsive to determining that the second access level indicates authorization to affect the operation of the equipment in the control system.
12. The one or more non-transitory computer-readable storage media of claim 11, wherein a first user account associated with the first input is logged into the human machine interface device at a time when the second input is received.
13. The one or more non-transitory computer-readable storage media of claim 11, the operations comprising receiving both the first input and the second input while a first screen is presented on the touch screen display.
14. The one or more non-transitory’ computer-readable storage media of claim 13, the operations comprising: causing, by the human machine interface device, the touch screen display to present an administrator window on the first screen responsive to receiving the second input; receiving, at the human machine interface device, a third input comprising a third interaction with the touch screen display, the third interaction comprising a selection of a second graphical user interface element presented on the administrator window on the first screen; sending, from the human machine interface device, the control signal to the equipment in the control system to affect the operation of the equipment in the control system based on the third input; and causing, by the human machine interface device, the administrator window to be removed from the first screen presented on the touch screen display responsive to determining that a predetermined period of time has elapsed since the third input was received.
15. The one or more non-transitory computer-readable storage media of claim 11, the operations comprising: receiving, at the human machine interface device, a fourth input comprising a fourth interaction with the touch screen display, the fourth interaction comprising a second selection of the graphical user interface element presented on the touch screen display that is selectable via the touch screen display to affect the operation of the equipment in the control system; collecting, at the human machine interface device, third biometric data while receiving the fourth input; processing, at the human machine interface device, the third biometric data to grant the first access level for the third input; and causing, by the human machine interface device, the touch screen display to present an error message responsive to determining that the first access level does not indicate authorization to affect the operation of the equipment in the control system.
16. A method for use in a control system, comprising: receiving, at a human machine interface device in the control system, a first input comprising a first interaction with a touch screen display of the human machine interface device; collecting, at the human machine interface device, first biometric data while receiving the first input; processing, at the human machine interface device, the first biometric data to grant a first access level for the first input; performing, by the human machine interface device, an action associated with the control system based on the first input in accordance with the first access level; receiving, at the human machine interface device, a second input comprising a second interaction with the touch screen display, the second interaction comprising a selection of a first graphical user interface element presented on the touch screen display that is selectablevia the touch screen display to access or modify sensitive data associated with the control system; collecting, at the human machine interface device, second biometric data while receiving the second input; processing, at the human machine interface device, the second biometric data to grant a second access level for the second input, the second access level different from the first access level; and causing, by the human machine interface device, the touch screen display to present a second graphical user interface element different from the first graphical user interface element based on the second input that allows access or modification of the sensitive data associated with the control system responsive to determining that the second access level indicates authorization to access or modify the sensitive data associated with the control system.
17. The method of claim 16. wherein a first user account associated with the first input is logged into the human machine interface device at a time when the second input is received.
18. The method of claim 16, comprising receiving both the first input and the second input while a first screen is presented on the touch screen display.
19. The method of claim 1 , comprising: determining, at the human machine interface device, that a predetermined period of time has elapsed since the second input was received; and causing, by the human machine interface device, the second graphical user interface element to be removed from presentation via the touch screen display responsive to determining that the predetermined period of time has elapsed since the second input was received.
20. The method of claim 16, comprising: receiving, at the human machine interface device from an external device, an application file comprising biometric data associated with a known set of users; wherein processing, at the human machine interface device, the second biometric data to grant the second access level for the second input comprises comparing, at the human machine interface device, the second biometric data to the biometric data associated with the known set of users to grant the second access level for the second input; andwherein the sensitive data associated with the control system comprises an alarm associated with equipment in the control system, a script associated with the human machine interface device, or an audit trail associated with the human machine interface device.
Citation Information
Patent Citations
Distinctive user identification and authentication for multiple user access to display devices
US20090058598A1
Enabling Single Finger Tap User Authentication and Application Launch and Login using Fingerprint Scanning on a Display Screen
US20180260544A1
KR20230164867A