Field device

Field devices with two-factor authentication and multiple communication technologies enhance security, addressing vulnerabilities in modern field devices by ensuring only authorized access, thus protecting production processes from cyber threats.

WO2025153519A1PCT designated stage expired Publication Date: 2025-07-24VEGA GRIESHABER GMBH & CO
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/050856
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-15
Filing Date
2025-01-15
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Modern field devices in process automation face challenges in supporting new communication channels while ensuring high security, making them vulnerable to cyberattacks that can disrupt production processes and cause economic damage.

Method used

Field devices are designed with a sensor arrangement to detect process variables and a communication arrangement for secure data transfer, utilizing at least two security factors for authentication to ensure only authorized access, incorporating various communication technologies like HART, Ethernet, Bluetooth, and wireless protocols.

Benefits of technology

The two-factor authentication significantly enhances security, reducing the vulnerability to cyberattacks and ensuring the integrity, availability, and confidentiality of production processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025050856_24072025_PF_FP_ABST
    Figure EP2025050856_24072025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure relates to a field device (10) for recording a process measurement variable, which device is, in particular, in the form of a fill level measuring device for recording a fill level of a medium, wherein the field device (10) has: - a sensor arrangement (11) configured to record a measurement signal correlating to the process measurement variable, and - a communication arrangement (12) configured for data communication (1) with an access device (20), wherein the field device (10) is configured to receive authentication data (2) based on at least two security factors, and wherein, in order to authenticate the data communication (1) between the field device (10) and the access device (20), the field device (10) is configured to evaluate at least one portion of the authentication data (2) that is based on at least one of the at least two security factors.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] field device

[0002] Reference to related applications

[0003] This application claims priority from German patent application No. 10 2024 200 341 .7, filed on January 15, 2024, which is incorporated in its entirety by reference into this document.

[0004] Technical area

[0005] The present disclosure relates to a field device for detecting a process measurement, an access device for data communication with a field device, an authentication device, a system with a field device and an access device and / or authentication device, a method for authenticating data communication between a field device and an access device, and a computer program product.

[0006] background

[0007] In industrial measurement technology, particularly in the field of process automation and process control, field devices are regularly used to record one or more process variables or, in other words, process measurement variables. Examples of field devices include flow, flow velocity, pressure, differential pressure, temperature, and level measuring devices. Using a corresponding measuring system, the field devices typically record a measurement signal that correlates with one or more process measurement variables. A computing arrangement in the respective field device can then determine a measured value for the respective process measurement variable based on the measurement signal and / or based on an evaluation of the measurement signal.

[0008] Such field devices are often part of a larger industrial control system. However, controlling and monitoring the processes in such a control system requires an ever-increasing amount of process information due to increasing levels of automation. This makes it necessary to measure and process more process parameters. This results in a significantly larger volume of data that must be transferred from field devices to the control systems. This, in turn, creates the need for ever more and newer communication channels.

[0009] Common communication systems for setting up industrial fieldbuses, such as HART, quickly reach their limits with the increased data volume, which is why new developments rely on wireless or Ethernet-based protocols. This makes it possible to achieve the goal of higher data rates and greater networking.

[0010] The inventors recognized that, given such increasingly interconnected systems, there may be a greater vulnerability to cyberattacks. Cyberattacks can lead to disruptions in production processes, which can result in downtime, production losses, and thus enormous economic damage.

[0011] One challenge in the development of modern field devices of the type mentioned above is therefore to increasingly support new communication channels while simultaneously ensuring a high level of security for these channels. Cybersecurity in field devices in the process industry is crucial to ensuring the integrity, availability, and confidentiality of production processes and the products produced.

[0012] Summary

[0013] It is an object of the present disclosure to enable the secure use of field devices. This object is achieved by the subject matter of the independent patent claims. Further developments of the present disclosure emerge from the subclaims and the following description of embodiments.

[0014] A first aspect of the present disclosure relates to a field device for detecting a process measurement variable, which can be designed in particular as a fill level measuring device for detecting a fill level of a medium, wherein the field device comprises: a sensor arrangement which is configured to detect a measurement signal correlating with the process measurement variable, and a communication arrangement which is configured for data communication with an access device, wherein the field device is configured to receive authentication data based on at least two, in particular different, security factors, and wherein the field device is configured to authenticate the data communication between the field device and the access device for evaluating at least a part of the authentication data which is based on at least one of the at least two security factors.

[0015] Advantageously, this provides a field device whose data communication to or with an access device is authenticated using two security factors. The fact that two security factors are required to authenticate data communication increases security, ensuring that only authorized users or authorized access devices are granted access. This increased security significantly reduces the field device's vulnerability to a cyberattack and the chances of a cyberattack being successful.

[0016] The field device can, for example, be a flow, flow velocity, pressure, differential pressure, temperature, level, and / or point level measuring device. Depending on its design, it can be used in various systems and / or environments. For example, a level and / or point level measuring device can be used in a measuring container to monitor its fill level and / or detect a point level. Depending on the design of the field device, various sensor arrangements or sensors of the sensor arrangement can be used, such as a flow sensor, flow velocity sensor, pressure sensor, temperature sensor, and / or radar sensor, etc.

[0017] In addition to the sensor arrangement and the communication arrangement, the field device can also have a computing arrangement, which can include, for example, a computer, processor, and / or microcontroller. The computing arrangement can be configured to acquire or calculate the process measurement variable from the acquired measurement signals. Additionally or alternatively, the computing arrangement can be configured to authenticate the data communication between the field device and the access device by evaluating at least part of the authentication data.

[0018] The communication arrangement can comprise one or more communication units. The communication arrangement or the various communication units can be configured for a wireless and / or wired connection. Accordingly, wireless and / or wired data communication can take place between the field device and the access device. The communication technology can be any desired. Examples of possible communication technologies include HART, Ethernet, Bluetooth, Wi-Fi, 4G, LTE, Lora, NB-IoT, etc.

[0019] The terms authentication data and security factor are to be interpreted broadly. The authentication data can be any type of information, data, or signal that can be read and evaluated by the field device. The authentication data can be based on one or more security factors. This includes the possibility that the authentication data can include data, information, or signals relating to the security factors. For example, a part of the authentication data that is based on one of the security factors can include the security factor or related information, such as a password, a one-time generated code, information about a fingerprint, or the like. A security factor is understood here in particular to be a factor that can be evaluated to ensure the security of the field device in order to authenticate data communication.The security factor can take different forms and include or be based on different information or data, such as a password, code, fingerprint, etc. The security factor can be based on an input and / or output, as explained in more detail below.

[0020] Receiving the authentication data by the field device can be provided by various arrangements, the communication arrangement being merely one example. Alternatively or additionally, it is possible to receive the authentication data by means of an input on an input arrangement, which may be part of the field device, in particular attached thereto or an integral part thereof. Of course, the access device or an authentication device explained in more detail below may also have an input arrangement to perform authentication. In this case, however, the field device will typically receive the authentication data based on the input at the input arrangement of the access and / or authentication device by means of data communication with the access and / or authentication device.In particular, it is possible for the field device to be configured to receive different portions of the authentication data, which may be based on different security factors, from different arrangements or devices. For example, a portion of the authentication data based on one of the security factors may be received by the input arrangement on the field device, while another portion of the authentication data based on another of the security factors may be received by the access device or the authentication device via data communication.

[0021] The evaluation of at least a portion of the authentication data by the field device, in particular by its computing arrangement, requires that both or not both security factors must be authenticated by the field device. For example, it can be provided that a first security factor of a portion of the authentication data has already been authenticated by the access device and / or the authentication device in order to generate the remaining portion of the authentication data based on a second security factor. This remaining portion of the authentication data can then be evaluated by the field device to authenticate the data communication. The authentication data is nevertheless based on both security factors because the second security factor could not have been generated without the first security factor, thus achieving increased security.It is not necessary, although possible, for the field device to also evaluate the other part of the authentication data with respect to the other security factor. Instead, or alternatively, it is particularly possible that a registration with respect to a security factor has already taken place once. For example, an access device and / or authentication device may have been initially paired with the field device, in particular using a special key or password, for example, during initial setup, and / or by the manufacturer of the field device, for example, through remote access to the field device, so that the access device and / or authentication device is considered known or trustworthy (to the field device).By securing the access device and / or authentication device with a first security factor for access to it, for example, using a password, one of the two security factors can be evaluated and fulfilled. For example, it is possible for the second security factor to comprise a code generated by the field device or another device or server, sent to or received by the trusted device, and then sending a message or code back to the field device or generating a code for input at the field device, which is evaluated by the field device for authentication. Furthermore, it is not necessary, although possible, for the authentication data evaluated by the access device to contain data relating to both security factors.

[0022] Alternatively, it is possible, and can be provided, for the field device to be configured to evaluate the authentication data. The field device can evaluate both security factors. This can be the case, for example, if the field device receives the authentication data relating to both security factors via an input device or receives parts of the authentication data based on each of the security factors from different devices and / or devices, for example, from the input device and the access device, the input device and the authentication device, or the access device and the authentication device.

[0023] The authentication data can be evaluated by comparing the information or data it contains, in particular relating to one or both security factors, with the expected information or data. In a particularly simple case, one of the two security factors can be a password request, for example. In this case, a password entered via the input arrangement of the field device or received via the data communication or the communication arrangement can be compared with an expected or predetermined password, which can be stored in a data memory of the field device. If the received password matches the expected password, a security factor can be confirmed, fulfilled, or in other words, authenticated. If a further security factor is now also confirmed orauthenticated, whether by the field device itself or on another device as previously described, the data communication can be authenticated.

[0024] The two security factors can be different types of security factors or the same type of security factors. For example, both security factors can be a password and / or a fingerprint type. It is possible for security factors of different types or the same type to be distributed across different devices, such as a field device, access device, and / or authentication device. This includes input, output, and / or evaluation of the security factor on the various devices.

[0025] The field device can be configured to allow read and / or write access from the access device to the field device during authenticated data communication. Data communication between the access device and the field device can also be provided and permitted even before the data communication is authenticated. This can, for example, enable the field device to receive the authentication data from the access device. However, functions or access options on the part of the access device to the field device can be blocked if the data communication, or in other words, the data connection, is not authenticated. Thus, partial or full read and / or write access to the field device can be granted using authenticated data communication between the field device and the access device.Reading and writing refers in particular to data stored on the field device, for example, relating to the parameterization of the sensor array, which can be read and written, and in particular also overwritten. The field device can be configured to allow one of at least two different access authorizations of the access device to the field device, depending on at least part of the evaluated authentication data. The different access authorizations can, for example, relate to different data and / or reading and / or writing.For example, one access authorization may only permit reading and / or writing of a portion of the data on the field device, for example, for parameterizing the sensor array. Another, more comprehensive access authorization may permit reading and writing of more or all of the data on the field device, enabling more comprehensive programming of the sensor array or field device. This allows for simple simultaneous communication and evaluation of access authorizations based on the authentication data. This is suitable, for example, for assigning different access authorizations to different users, such as a field device user and a service technician.

[0026] The field device can be configured to allow parameterization of the sensor arrangement by the access device during authenticated data communication. This allows the field device to be used for a specific application and / or environment. In particular, different field devices can be used for different applications and / or be exposed to different environments. In order to determine precise process variables, the field device, in particular its sensor arrangement with one or more sensors, can be configured to be parameterized for the different applications and / or environments. Parameterization makes it possible to allow high measurement precision. Parameterization can be understood in particular as characterizing the field device through parameters that influence the acquisition of the process variable.The parameterization can include at least parameters of the field device itself, in particular settings of the field device, for example, a measurement sensitivity. Alternatively or additionally, the parameterization can also include external parameters, such as measurement conditions, for example, density of a medium to be measured, volume of a measuring container containing the medium, etc., as well as or alternatively environmental parameters, such as ambient temperature, ambient pressure, etc. It is possible for the communication arrangement to be configured to receive at least part of the authentication data, which is based on at least one of the at least two security factors, from the access device and / or an authentication device.Accordingly, at least part of the authentication data is provided by another device, which, as previously explained, can be classified as trustworthy, particularly through prior coupling with the field device, thus further increasing security. Alternatively or additionally, it is possible to receive all or part of the authentication data via an input arrangement in the form of an input on the field device.

[0027] It is possible for the field device to be configured with at least one output arrangement for outputting at least one signal for generating at least part of the authentication data based on at least one of the at least two security factors. The output arrangement can comprise one, two, or more output units. The signal can in turn be recognized and / or read by another device, in particular the access device and / or the authentication device, in order to generate at least part of the authentication data, in particular with regard to one of the at least two security factors. The authentication data generated in this way can be transmitted to the field device for authentication. The combination of the signal output by the field device and the authentication data generated by another device provides increased security against an authorized access device gaining access to the field device.

[0028] The output device can comprise at least one of a display, a radio signal transmitter, and a light generator. Any combination of one or more of the aforementioned output units is also possible.

[0029] The signal can be embodied as at least one of a machine-readable code, a radio signal, and a light code. Accordingly, for example, a display can output a machine-readable code, for example in the form of a barcode or QR code. This can be scanned and read by the separate device to generate the authentication data. Alternatively or additionally, a radio signal can be generated and transmitted by a radio signal transmitter. This radio signal can be received, for example, by the access device and / or the authentication device, which then generates and transmits a counter radio signal. This can be received by the radio signal transmitter or a radio signal receiver of the field device, whereupon the authentication data can be generated. Finally, it is possible for a light code to be generated.The light code can be generated, for example, by illuminating one or more light sources, such as an LED or a display. The light can be encoded by different and / or changing luminous colors, thus forming the light code. Alternatively, or additionally, the light code can be formed by a frequency of switching the light on and off and / or an intensity of the light. The light code can be read, for example, by the access device and / or authentication device, for example, using a camera, whereupon the authentication data is generated.

[0030] Furthermore, it is preferable for the field device to be configured with an input device for inputting at least part of the authentication data based on at least one of the at least two security factors. In this respect, the reception of at least part of the authentication data or the complete authentication data can take place directly via such an input device instead of via the communication device.

[0031] For example, it is possible for the input arrangement to comprise at least one of a display, a keyboard, a fingerprint sensor, a camera, a radio signal receiver and a microphone.

[0032] For example, it is possible for the input to be embodied as at least one of a password, a fingerprint, an image or video of at least part of a user, a radio signal, and a voice. The password can be entered, for example, via the display, in particular a touch display, and / or a keyboard. The fingerprint can be entered, for example, via the fingerprint sensor. The image or video of at least part of the user can, for example, include the user's face, the user's eyes, in particular the iris, a gait cycle of the user, or the like, so that in each case a specific or unique optical characteristic of the user is used, which can be used for authentication. The image or video can be recorded via the camera. The radio signal receiver can receive the previously explained counter radio signal.Finally, the microphone can record the user's voice, for example when they speak a password or give an instruction.

[0033] A second aspect of the present disclosure relates to an access device for data communication with a field device according to the first aspect of the present disclosure, wherein the access device is configured to generate and send at least part of the authentication data based on at least one of the at least two security factors to the field device.

[0034] A third aspect of the present disclosure relates to an authentication device configured to generate at least a portion of the authentication data that can be evaluated by the field device according to the first aspect of the present disclosure, wherein the portion of the authentication data is based on at least one of the at least two security factors.

[0035] A fourth aspect of the present disclosure relates to a system comprising a field device according to the first aspect of the present disclosure and at least one of the access device according to the second aspect of the present disclosure and the authentication device according to the third aspect of the present disclosure.

[0036] A fifth aspect of the present disclosure relates to a method for authenticating a data communication between a field device for detecting a process measurement variable, which can be designed in particular as a level measuring device for detecting a level of a medium, and an access device, the method comprising:

[0037] Receiving authentication data based on at least two security factors, and

[0038] - Evaluating at least part of the authentication data based on at least one of the at least two security factors to authenticate the data communication.

[0039] The method can, for example, be executable on or by the field device according to the first aspect and / or on or by other devices, such as the access device and / or authentication device, in particular the system. Furthermore, the method can comprise further steps, as explained herein with reference to the various devices.

[0040] A sixth aspect of the present disclosure relates to a computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method according to the fifth aspect of the present disclosure.

[0041] The computer program product can be a computer program as such or a product on which the computer program is stored. Such a product can, for example, be a storage medium that is readable, in particular, by a computer or the computer's processor. A computer can, for example, also be or include a microprocessor. A computer can, for example, be present in the form of electronics of the field device or in the form of a control unit of the field device.

[0042] The features of the individual aspects of this disclosure explained herein may be combined with one another as desired and independently of the respective aspects concerned.

[0043] Further embodiments of the present disclosure are described below with reference to the figures. Where the same reference numerals are used in the following description of the figures, they denote identical or similar elements. The representations in the figures are schematic and not to scale.

[0044] Short description of the characters

[0045] Fig. 1a to 1e show schematic views of systems with a field device with different authentication processes.

[0046] Fig. 2a to 2c show schematic views of different input and / or output orders of the field devices from Fig. 1a to 1e.

[0047] Fig. 3a to 3c show schematic views of different scenarios of a part of an exemplary authentication process.

[0048] Fig. 4 schematically shows a method for authenticating a data communication. Detailed description of embodiments

[0049] Fig. 1a shows a schematic view of a system 100 with a field device 10 according to an exemplary embodiment. The field device 10 of this embodiment can be embodied, for example, as a level measuring device, such as a liquid limit switch. Alternatively, the field device 10 can also take on a different embodiment, for example, the form of a pressure measuring device or other field device 10.

[0050] The field device 10 has a sensor arrangement 11, which can have at least one sensor (not shown), for example, a tuning fork in the example of the level measuring device. This allows the sensor arrangement 11 to detect measurement signals correlating with a process measurement variable, here, for example, an oscillation frequency as the measurement signal, wherein the process measurement variable can be a fill level, here, for example, a limit fill level that is determined by the position of the sensor. In a measuring container, for example, the oscillation frequency decreases when the liquid within the measuring container increases in fill level and reaches the sensor. The sensor arrangement 11 of the field device 10 can determine the frequency difference and thus detect the limit fill level as a process measurement variable. A pump can then be switched off, for example, to prevent further filling of the measuring container.

[0051] Furthermore, the field device 10 comprises a communication arrangement 12, which may, for example, comprise one or more communication interfaces or channels, for example in the form of at least one antenna for wireless data communication 1 with another device, in this case, for example, an access device 20 of the system 100.

[0052] Furthermore, the field device 10, as shown by way of example in Fig. 1a, can comprise an output arrangement 13, an input arrangement 14, a computing arrangement 15, and / or a computer program product 16. The computing arrangement 15 can comprise, for example, a computer or processor. Using the computing arrangement 15, measured values ​​of the process variable can be determined based on the measurement signals, for example, the reaching of the liquid limit level, as well as an evaluation of these measured values, for example, to shut down the pump.

[0053] The access device 20 may in turn also comprise a communication arrangement 21, a computing arrangement 22 and a computer program product 23, which may in principle have the same structure as described herein with reference to the field device 10.

[0054] The field device 10 can now, as shown in the example in Fig. 1a, establish a data communication 1 with the access device 20, for example, a smartphone or other computer system with a screen, input devices, and the like. The purpose of this can be, for example, to allow the access device 20 read and / or write access to the field device 10, for example, to allow the access device 20 to parameterize the sensor system 11.

[0055] It can now be provided that the data communication 1 is authenticated by the field device 10. In other words, the field device 10 should ensure that the access device 20 or its user has the necessary authorization for read access, write access, and / or parameterization. This can be achieved by the field device 10 receiving and evaluating authentication data 2. If the evaluation shows that the access device 20 or its user is authorized, the data communication 1 is authenticated. Otherwise, the data communication 1 is not authenticated, and the access device 20 or its user is denied access.

[0056] In the example of Fig. 1a, the field device 10 receives the authentication data 2 by transmitting it via data communication 1 between the field device 10 and the access device 20. The authentication data 2 is based on two security factors, although more security factors are also possible. At least a portion of the authentication data 2 that is based on one of the two security factors is evaluated by the field device 10 to authenticate the data communication 1.

[0057] In the example of Fig. 1a, for example, it can be provided that the access device 20 or an application thereon, which is configured for read access, write access, and / or parameterization of the field device 10, is protected with a password or via another security check, such as a fingerprint or a facial scan or other scan of an optical characteristic of a user of the access device 20. This can form one of the two security factors. A second security factor can, for example, be a PIN, TAN, password, or the like generated for one-time access to the access device 20, which is generated, for example, by a remote server, such as the manufacturer's, and sent to the access device 20, in particular a separate application.The access device 20 can be initially coupled, in particular using a special key or password, for example during initial setup, or by the manufacturer of the field device 10, for example through remote access to the field device 10, so that the access device 20 is considered known or trustworthy. Accordingly, the access device 20 can receive the PIN, TAN, or password generated for one-time access and then transmit authentication data 2 to the field device 10, which is based on both the password for accessing the application and the PIN, TAN, or password generated once, i.e., based on two security factors. For example, the authentication data 2 can contain the PIN, TAN, or password. For example, the PIN, TAN, or password can also have been received by the field device 10 via the remote server.The evaluation by the field device 10 can be performed accordingly, for example, by comparing the two PINs, TANs, or passwords, i.e., the one received from the server and the one received from the access device 20. If both match, the data communication 1 can be authenticated accordingly by the field device 10, allowing, for example, parameterization of the sensor arrangement 11 using the access device 20. Such an authentication method can be carried out when the computer program product 16 is executed by the computing arrangement 15.

[0058] Fig. 1 b shows a system 100 that uses an authentication device 30 in addition to the field device 10 and access device 20. Here, for example, part of the authentication data 2 or all of the authentication data 2 is provided by the authentication device 30 and transmitted from the access device 20 to the field device 10. In this example, the authentication device 30 itself does not communicate directly with the field device 10, but only indirectly via the access device 20. The authentication device 30, in turn, can also comprise a communication arrangement 31, a computing arrangement 32, and a computer program product 33, which in principle can have the same structure as described herein with reference to the field device 10 or the access device 20.

[0059] Alternatively, Fig. 1c shows a system 100 that also uses an authentication device 30, but in which the access device 20 and the authentication device 30 each send separate parts of the authentication data 2, each based on one of the two security factors, to the field device 10. Only when the field device 10 receives both parts of the authentication data 2 and evaluates them to authenticate the data communication 1 does the access device 20 gain access to the field device 10.

[0060] A further alternative is shown in Fig. 1d, in which the complete authentication data 2 is received directly from the authentication device 30 at the field device 10 or a part of the authentication data 2 is received based on one of the two security factors from the authentication device 30 at the field device 10, while another part of the authentication data 2 can be received directly at the field device 10, namely by means of the input arrangement 14.

[0061] An example of an embodiment of the field device 10 for the variant of Fig. 1d is shown, for example, in Fig. 2b. The input arrangement 14 is implemented here, for example, as a password input. A security factor can thus be checked by verifying a specified password as input 4 from the user on the field device 10. Accordingly, a first part of the authentication data 2 relating to the password is received as a security factor on the field device 10 and evaluated by comparing it with the known password, for example, as indicated in the form of a 4-digit PIN. A further part of the authentication data 2 is provided in Fig. 2b by the authentication device 30. The field device 10 here has, for example, an output arrangement 13 in the form of a light generator, which outputs a light code as a signal 3.This signal 3 can be read by the authentication device 30, which can be designed as a special reader for the signal 3. The authentication device 30 can thereby generate at least a portion of the authentication data 2. It can then transmit this data directly, as shown in Fig. 1d, or indirectly via the access device 20, as shown in Fig. 1b, to the field device 10, where the authentication data 2 is evaluated based on the security factor relating to the signal 3. If, for example, the portion of the authentication data 2 relating to the signal 3 corresponds to an authentication data 2, such as a code, expected by the field device 10 based on the output signal 3, and the password of the input 4 also corresponds to the expected password, then the data communication 1 can be authenticated.

[0062] Fig. 2a shows an alternative with a machine-readable code as signal 3 of the output device 13, for example in the form of a display. Here, too, the authentication device 30 can be provided to read the signal 3 and generate at least part of the authentication data 2. Alternatively or additionally, the access device 20 can also be configured to generate part of the authentication data 2 based on the signal 3.

[0063] Alternatively, it is possible, for example, for the authentication data 2 to be evaluated with regard to both security factors, i.e., completely, on the field device 10. This is shown, for example, in Fig. 1e, in which the field device 10 receives the authentication data 2 and authenticates the data communication 1 between the field device 10 and the access device 20, without the access device 20 itself participating in the authentication except for the data communication 1 with the field device 10 and the associated confirmations, such as the query as to whether the data communication 1 with the access device 20 should be authenticated. This is possible, for example, with the input arrangement 14 of the field device 10 in Fig. 2c. The input arrangement 14 is implemented here, for example, as a fingerprint sensor. A security factor can thus be verified by verifying the fingerprint as input 4 of the user on the field device 10.Accordingly, a first part of the authentication data 2 relating to the fingerprint is received as a security factor at the field device 10 and evaluated by comparing it with a known or previously stored fingerprint. Another part of the authentication data 2 is schematically indicated in Fig. 2c as input 4 relating to a password input, for example, with 4 dots for a 4-digit PIN input. Accordingly, the second part of the authentication data 2 relating to the PIN or password is also received as a security factor at the field device 10 and evaluated by comparing it with the stored PIN or password. If both security factors are met, the data communication 1 is authenticated.

[0064] Finally, Figs. 3a to 3c show a further variant of an authentication of the data communication 1 of the field device 10 with the access device 20, in which an authentication device 30 according to one of Figs. 1b, 1c and 1d is used. In these examples, the field device 10 comprises an output arrangement 13 in the form of a radio signal transmitter for generating a radio signal as signal 3, in particular within a specific range, which is indicated here by way of example by a circle around the field device 10. Furthermore, the field device 10 comprises an input arrangement 14 in the form of a radio signal receiver for receiving a radio signal as input 4. The authentication device 30 is now designed, for example, as or with a radio beacon, which can output the radio signal as input 4 when it receives the signal 3.The radio signal as input 4 can form part of the authentication data 2 regarding a security factor, which can be received accordingly by the field device 10 from the authentication device 30.

[0065] For example, Fig. 3a shows a user s within the range of the signal 3 but without the authentication device 30. Accordingly, no authentication data 2 is received by the field device 10 based on the security factor of the input 4 in the form of the radio signal. The user 5 cannot authenticate themselves or cannot do so completely on the field device 10, as they are missing the authentication device 30. In Fig. 3b, the user 5 is within the range of the signal 3 and is equipped with the authentication device 30, which accordingly generates the radio signal as input 4 and transmits it to the field device 10 as part of the authentication data 2. In Fig. 3c, the user 5 is equipped with the authentication device 30, but is outside the range of the signal 3, so that no authentication data 2 is generated with regard to the input 4. If the user 5 is in Fig. 3c compared to Fig.3b has been removed, data communication 1 can no longer be authenticated.

[0066] Figure 4 shows a purely schematic representation of a method 200 for authenticating the data communication 1 between the field device 10 and the access device 20. The method 200 comprises, in step 201, receiving the authentication data 2 based on two security factors. As explained, parts of the authentication data 2, each part being based on one of the two security factors, can be received by different devices and / or arrangements.

[0067] In step 202 of method 200, at least a portion of the authentication data 2, which is based on at least one of the two security factors, is evaluated to authenticate the data communication 1. As explained, the authentication data 2 or the portion of the authentication data 2 can be compared with expected information or data. If the evaluation is successful, for example, if the authentication data 2 or the portion thereof matches the expected information or data, the data communication 1 can be authenticated.

[0068] Finally, in the case of authenticated data communication 1, in step 203 of the method 200, the read and / or write access of the access device 20 to the field device 10 can be permitted.

[0069] The terms used in the claims should be construed to give them the broadest possible reasonable interpretation consistent with the foregoing description. For example, the use of the article "a" or "the" in introducing an element should not be construed to exclude a plurality of elements. Likewise, the mention of "or" should be construed to include a plurality of elements, so that the mention of "A or B" does not exclude "A and B" unless it is clear from the context or the preceding description that only one of A and B is intended.Furthermore, the phrase "at least one of A, B, and C" should be understood as one or more elements from a group of elements consisting of A, B, and C, and should not be interpreted as requiring at least one of each of the listed elements A, B, and C, whether A, B, and C are related as categories or otherwise. Furthermore, the reference to "A, B, and / or C" or "at least one of A, B, or C" should be interpreted to include each individual unit of the listed elements, e.g., A, each subset of the listed elements, e.g., A and B, or the entire list of elements A, B, and C.

Claims

Patent claims 1 . Field device (10) for detecting a process measurement variable, which is designed in particular as a fill level measuring device for detecting a fill level of a medium, wherein the field device (10) has: a sensor arrangement (11) which is set up to detect a measurement signal correlating with the process measurement variable, and a communication arrangement (12) which is set up for data communication (1) with an access device (20), wherein the field device (10) is set up to receive authentication data (2) based on at least two security factors, and wherein the field device (10) is set up to authenticate the data communication (1) between the field device (10) and the access device (20) for evaluating at least a part of the authentication data (2) which is based on at least one of the at least two security factors.

2. Field device (10) according to claim 1, wherein the field device (10) is configured to allow read access and / or write access of the access device (20) to the field device (10) during authenticated data communication (1).

3. Field device (10) according to claim 1 or 2, wherein the field device (10) is configured to allow one of at least two different access authorizations of the access device (20) to the field device (10) depending on the at least part of the evaluated authentication data (2).

4. Field device (10) according to one of the preceding claims, wherein the field device (10) is configured to allow parameterization of the sensor arrangement (11) by the access device (20) during authenticated data communication (1).

5. Field device (10) according to one of the preceding claims, wherein the communication arrangement (12) is configured to receive at least part of the authentication data (2) stored on at least one of the at least two security factors, is set up by the access device (20) and / or an authentication device (30).

6. Field device (10) according to one of the preceding claims, wherein the field device (10) is configured to have at least one output arrangement (13) for outputting at least one signal (3) for generating at least part of the authentication data (2) based on at least one of the at least two security factors.

7. Field device (10) according to claim 6, wherein the output arrangement (13) comprises at least one of a display, a radio signal transmitter and a light generator.

8. Field device (10) according to claim 6 or 7, wherein the signal (3) is formed as at least one of a machine-readable code, a radio signal and a light code.

9. Field device (10) according to one of the preceding claims, wherein the field device (10) is configured to have an input arrangement (14) for inputting (4) at least part of the authentication data (2) based on at least one of the at least two security factors.

10. The field device (10) of claim 9, wherein the input arrangement (14) comprises at least one of a display, a keyboard, a fingerprint sensor, a camera, a radio signal receiver, and a microphone.

11. Field device (10) according to claim 10, wherein the input (4) is configured as at least one of a password, a fingerprint, an image or video of at least part of a user, a radio signal, and a voice.

12. Access device (20) for data communication (1) with a field device (10) according to one of the preceding claims, wherein the access device (20) is configured to generate and send at least part of the authentication data (2) based on at least one of the at least two security factors to the field device (10).

13. Authentication device (30), configured to generate at least part of the data that can be evaluated by the field device (10) according to one of claims 1 to 11 Authentication data (2), wherein the part of the authentication data (2) is based on at least one of the at least two security factors.

14. System (100) comprising a field device (10) according to any one of the preceding claims and at least one of the access device (20) according to claim 12 and the authentication device (30) according to claim 13.

15. A method (200) for authenticating a data communication (1) between a field device (10) for detecting a process measurement variable, which is designed in particular as a level measuring device for detecting a level of a medium, and an access device (20), the method comprising: Receiving authentication data based on at least two security factors (2), and - Evaluating at least part of the authentication data (2) based on at least one of the at least two security factors to authenticate the data communication (1).

16. A computer program product (16) comprising instructions which, when executed by a computer (15), cause the computer (15) to carry out the method (200) according to claim 15.

Citation Information

Patent Citations

  • field device

    DE102024200341A1

  • method for authenticating at least one first unit to at least one second unit

    DE102014112611A1

  • Method for secure communications with a field measuring device used for process technology and corresponding field measuring instrument

    EP3410241A1