Tamper protection for the clock of a field device
The field device's adjustable clock and public-key certificate system prevents timestamp manipulation, ensuring secure and accurate event logging, even in environments with limited internet access, by verifying time information and authenticating users.
Patent Information
- Application Number
- PCT/EP2025/072320
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-06
- Filing Date
- 2025-08-04
- Publication Date
- 2026-02-12
AI Technical Summary
Field devices in industrial plants face the challenge of having their internal clocks manipulated, allowing operators to set incorrect timestamps, which can compromise event logs and security, especially in environments where internet access is limited and cryptographically unsecured protocols are used.
Implementing a field device with an adjustable clock, non-volatile CA memory for public-key certificates, and interfaces to receive and verify time information, ensuring the clock is set only to times that are later than previously stored dates, using public-key certificates to authenticate and authorize users, and logging events with timestamps.
Prevents backdating of event logs, enhances security by making it difficult to manipulate timestamps, and ensures accurate logging even in environments with limited internet access, thereby maintaining regulatory compliance and safety standards.
Smart Images

Figure EP2025072320_12022026_PF_FP_ABST
Abstract
Description
Tamper protection for the clock of a field device REFERENCE TO RELATED REGISTRATIONS
[0001] The present application claims priority from German patent application No. 10 2024 122454.1, filed on August 6, 2024, which is incorporated in full by reference into this document. TECHNICAL AREA
[0002] The invention relates to the operation of field devices for use in industrial plants, wherein these field devices include an internal clock and the setting of this internal clock by the operator of the field device must be made possible despite the risk of malicious manipulation. BACKGROUND OF THE INVENTION
[0003] Field devices in industrial plants, such as sensors or actuators that physically interact with a production process running on the plant, have a built-in clock, which is needed, among other things, for time-stamping event logs. This clock is correctly set during the manufacturing of the field device. For times when the field device is without an external power supply, an alternative internal power supply (buffer), such as a battery or a capacitor, is provided.
[0004] During the operating life of a field device, situations where the buffer is exhausted and the clock's time setting is lost cannot be completely avoided. To allow the field device to continue operating, the operator must be able to reset the clock. However, this gives them the ability to set any time they like and thus, for example, to manipulate the timestamps with which the field device stores events in its internal event log. Even obtaining the time from a time server offers no protection against this, as the common protocols used for this purpose are not cryptographically secured. It is easily possible, for example, to redirect requests to this time server to a private server that responds with an incorrect time. TASK AND SOLUTION
[0005] The object of the present invention is therefore to enable the operator to set the clock of a field device while making it more difficult to manipulate the time.
[0006] This problem is solved according to the invention by a method for operating a field device according to the main claim. Further advantageous embodiments are described in the dependent claims relating thereto. REVELATION OF THE INVENTION
[0007] The invention provides a method for operating a field device. The field device has an adjustable clock and at least one non-volatile CA memory containing a public-key certificate of a trusted certification authority (CA). Furthermore, at least one interface is provided.
[0008] The interface can be configured, for example, as a network interface for communication with a network. However, any other interface through which the field device can receive input can also be used. The field device can, for example, read input optically (e.g., via a QR code). Alternatively, the field device can receive input via a keyboard or another human-machine interface. A fieldbus interface, a Bluetooth interface, a USB interface, or a serial interface can also be used. Furthermore, the field device can have additional interfaces, such as a connection via a 4-20 mA current loop.Unless explicitly stated otherwise, the term “interface” in the following refers to the interface of the field device used within the framework of the procedure proposed here, regardless of whether there are other interfaces or not.
[0009] The public key certificate of the trusted CA allows other public key certificates to be verified as having been signed by the trusted CA. The field device also has at least one non-volatile time memory for storing a date and / or time. This time memory does not need to be physically separate from the CA memory. Instead, for example, a portion of the same non-volatile memory can be designated for use by the CA memory and a portion for use by the time memory.
[0010] A public-key certificate can, for example, contain a public key that is part of a public-key and private-key pair for an asymmetric cryptosystem. The public-key certificate can, for example, certify that this public key is bound to any entity, such as a user or a machine, and can be signed by a trusted Certificate Authority (CA). In this way, the trusted CA can confirm that, in its opinion and / or after verification, the binding of the public key to the entity named in the certificate is correct.
[0011] As part of the process, a current date and / or time is received via the interface.
[0012] If a network interface is available, it is possible, for example, to request the current date and / or the current time via the network interface. The time is sent to a time server. The current date and / or time can then be received from the time server.
[0013] The current date or time can also be entered manually, for example, via the field device's controls as an interface.
[0014] The current date or time received via the interface, regardless of the method, is compared with the date or time stored in the time memory. If the current date or time is later than the date or time stored in the time memory, the adjustable clock of the field device is set to the current date or time.
[0015] It was recognized that this method prevents, at least, the date or time from being backdated to a date or time that has demonstrably already occurred. If information from any source indicating that a specific date or time has already occurred is stored in the time memory, then, in particular, the misuse of backdating entries written by the field device to its event memory can be prevented. The event memory is a non-volatile memory in which the field device logs the occurrence of events of one or more predefined types. The entries in the event memory are timestamped, with the date and / or time values being taken from the field device's adjustable clock.
[0016] In particular, this prevents the complete suppression of writing certain entries to the event memory. The event memory on field devices typically has a very limited capacity, for example, 32 KB, which is sufficient for a few thousand entries. This is because storage technologies with significantly larger capacities, such as SSDs, SD cards, or other flash memory, require too much energy for write operations.
[0017] The total energy available for operating a field device is almost always very limited. Firstly, some field devices are powered via an analog 4-20 mA current loop and provide feedback by regulating their own current consumption to a value between 4 mA and 20 mA. This means that, in the worst-case scenario, only 4 mA of current is available to power the entire field device. Secondly, many field devices are used in potentially explosive atmospheres. The explosion protection of many field devices relies on limiting the energy in all circuits to a level insufficient to ignite any potentially explosive atmosphere (e.g., through sparks or heating). Such field devices are called "intrinsically safe," which offers significant advantages for their design and handling. For example, the need for complex encapsulation of the housing is eliminated.Furthermore, repair work on field devices or the replacement of field devices during operation is permitted.
[0018] Flash memory now consumes a comparatively large amount of energy during write operations because electrons are forced through a virtually impervious barrier into an area (such as a floating gate or charge gate) by applying a comparatively high write voltage. Electrons must be transported to a trapping memory element where they can remain for extended periods. For this purpose, the electrons are essentially "forced" through the barrier using a process called "hot-carrier injection." Therefore, EEPROM memory is the preferred non-volatile memory in field devices. Here, electrons are transported through "Fowler-Nordheim tunnels" across a barrier whose height is altered by an electric field into the areas where they are to be stored. This requires larger physical structures, resulting in a lower storage density than in flash memory.
[0019] The limited storage capacity is the reason why the event memory in field devices is typically designed as a ring buffer. Once such a ring buffer is full, a newly added entry displaces the oldest entry. If the adjustable clock of the field device is backdated, this can potentially lead to newly logged events in the event memory being sorted not as recent events at the front, but as older events at the back. Only one or a few recent events need to be added for the incorrectly sorted event to disappear from the event memory.
[0020] The obvious solution of simply increasing the buffer capacity for the field device's adjustable clock is not available in most applications. The buffer typically lasts for a maximum of about 10 years. However, the service life of field devices can be significantly longer. It is not uncommon for field devices to be in operation and maintained for 30 or even 40 years. Creating a buffer capacity for such a long period is not practical. Batteries chemically age during this time and must be replaced, which would then interrupt the buffer's lifespan. Furthermore, a larger-capacity battery can compromise the inherent safety in terms of explosion protection because a greater amount of energy can be released in the event of a failure.
[0021] The improved protection of the event log against backdating entries is particularly relevant for the use of the field device in industries where specific documentation requirements are mandated by regulations. This applies, for example, to industries with special environmental requirements, such as those concerning emissions, or regulations governing the handling of toxic or radioactive substances. In this respect, the event log is comparable to the odometer of a motor vehicle, the reading of which cannot be manipulated by the customer using onboard tools. Optionally, the event log can include a write-only memory in which at least an indication of the existence of each entry, such as a timestamp, is recorded.
[0022] In a particularly advantageous implementation, a public-key certificate is received via the interface. This public-key certificate contains a date and / or time for the start and end of its validity. It is checked against the public-key certificate from the CA store to verify whether the received public-key certificate was validly signed by the trusted CA. If so, the date and / or time are then... The time in the time memory is replaced by the date and / or time at which the validity of the received public key certificate begins.
[0023] In this way, information about a date and / or time that has definitely already occurred can be obtained even with only unidirectional communication via the interface. Typically, field devices are not connected to a network with internet access, but, if at all, only to an internal network intended for point-to-point communication between each field device and at least one controller assigned to that field device (such as a programmable logic controller, PLC). Retrieving a date and time from a trusted time server via a suitably secure protocol, on the other hand, would require bidirectional communication and usually also internet access.However, in most applications, it is a fundamental safety principle that the internal network for the field devices is not connected to the Internet, but is strictly isolated from the Internet ("air-gapped").
[0024] In particular, the date and / or time at which the validity of the received public key certificate begins can only be written to the time memory if this date and / or time is later than the date and / or time already stored there. Therefore, if, for example, several certificates with different start dates are in circulation, the date and / or time in the time memory will not jump back and forth between these different start dates. At the same time, it will not be overwritten if a later date and / or time has already been observed from another source.
[0025] The public key certificate received via the interface can, in particular, be used for, for example, • a counterpart with which encrypted communication is to be established over a network, and / or • be assigned to a user and / or machine that is to authenticate and / or authorize itself on the field device.
[0026] In many field device installations, the management of different levels of access rights is handled via public key certificates. The purchaser (operator) of the field device initially has full access and can subsequently delegate this to other users with different roles. For example, a plant operator can have limited access, and a plant electrician even more restricted access. The purchaser can issue and manage the certificates using their own Certificate Authority (CA), or this can be handled as a service, for example, by the field device manufacturer.
[0027] In a further particularly advantageous embodiment, the current date and / or time, according to the field device's clock, is stored in the time memory during operation when a predefined condition is met. In this way, Even independently of the arrival of certificates, for example via a network connection, a current time that has definitely already occurred is recorded in the time memory. This further complicates backdating, even within the validity period of the certificates received by the field device. Even backdating by a few days or hours can fail due to a correspondingly recent entry in the time memory.
[0028] The predefined condition can, for example, include the requirement that a predetermined periodic or randomly selected interval has elapsed since the date or time in the time memory. This allows for a balance between making it more difficult to backdate and the frequency of write operations to the time memory. Similar to flash memory, the lifespan of EEPROM memory, for example, is also limited in possible write cycles.
[0029] In a further advantageous embodiment, the field device determines the time zone in which it is located. This time zone is used when comparing the current date or time with the date or time in the time memory. In this way, the accuracy with which backdating can be prevented can be increased even further. The time zone can be determined, for example, based on... • Location and / or language settings of the field device, and / or • a position determined by the field device via a satellite-based positioning system, and / or • an IP address through which the field device gains access to the Internet.
[0030] However, it is also possible, for example, for the field device to operate internally entirely in Coordinated Universal Time (UTC) and only display times in other time zones on its screen or another user interface (such as a web interface) at the user's request. This is particularly advantageous in connection with retrieving time information from received public key certificates, as this time information is usually also given in UTC.
[0031] As previously explained, public key certificates presented to the field device can be used, in particular, for access control. This allows, for example, the mapping of different roles that different users assume when interacting with the field device.
[0032] Therefore, in a further, particularly advantageous embodiment, the field device receives a user public key certificate, which a user and / or machine uses to request authentication and / or authorization from the field device. This user public key certificate contains a date and / or time for the start and end of its validity. The field device checks whether the date or time, according to its configurable clock, falls within the validity period of this user public key certificate. If so, the field device grants authentication and / or authorization to the user or machine. In this context, the procedure described here makes it particularly difficult to unlawfully delay the expiration of the validity period and thus the loss of temporarily granted access rights. For example, an employee of an external company could, after completing the process, of an assignment for which he has been granted temporary access, he can no longer use this access by simply backdating the adjustable clock of the field device.
[0033] This is particularly advantageous in conjunction with a further configuration in which the user public key certificate additionally contains information about which subset of the total functionality and / or performance provided by the field device is activated for the user or the machine. This allows not only the purchaser (operator) of the field device to delegate their access in a tiered manner, but also enables the purchaser (operator) to be granted access by the field device manufacturer only to the extent for which corresponding licenses have been acquired. In this way, versions of the field device with different performance levels can be implemented without requiring any physical modifications to the device itself. Physically identical manufacturing, in turn, reduces production costs. Functions can also be activated for a limited time.If certain functions or service levels are only needed temporarily, costs can be saved compared to permanently sizing the scope of functions or services to the maximum conceivable need.
[0034] In a further advantageous embodiment, the field device logs at least one event with a timestamp containing a date and / or time from the field device's adjustable clock. As previously explained, an event memory of the field device, such as a ring buffer, can be used for this purpose. However, any other form of logging can also be used. For example, the timestamped events can be sent to a log host via a network interface. Regardless of the logging method, the procedure presented here offers the advantage that the event timestamp cannot be maliciously manipulated. Besides making events disappear from a ring buffer event memory, a possible motivation for such manipulation is to conceal the originator of certain events.For example, an employee could blame a colleague who was in charge at the time of the falsified incident for an event that resulted in increased emissions.
[0035] In a further, particularly advantageous embodiment, an abusive backdating attempt is detected when the current date or time received via the interface (e.g., from the time server) is more than a predefined tolerance before the date or time in the time memory. This backdating attempt can be addressed in any suitable manner. For example, the attempt can be logged in a special security protocol that records only security-relevant events and / or reported to the manufacturer of the field device or another trusted entity at the next opportunity to contact them (e.g., via the network). In particular, the backdating attempt must be stopped after such a report. The issue is documented outside the control of the field device operator and cannot be completely rectified.
[0036] An abusive backdating attempt can be interpreted, for example, as an attempt to circumvent authentication and / or authorization on the field device based on public key certificates. Therefore, in a further advantageous embodiment, in response to the detection of an abusive backdating attempt, • the authentication and / or authorization of at least one user, and / or at least one machine, on the field device is prevented, and / or • at least a subset of the total range of functions and / or services provided by the field device is blocked.
[0037] The method can be wholly or partially computer-implemented. Therefore, the invention also relates to a computer program with machine-readable instructions which, when executed on one or more computers and / or compute instances, cause the computer(s) and / or compute instance(s) to execute the described method. In this sense, field devices, vehicle control units, and embedded systems for technical devices that are also capable of executing machine-readable instructions are also to be considered computers. Compute instances can be, for example, virtual machines, containers, or serverless execution environments, which can be provided, in particular, in a cloud.
[0038] The invention also relates to a machine-readable data carrier and / or a downloadable product containing the computer program. A downloadable product is a digital product that can be transmitted over a data network, i.e., downloaded by a user of the data network, and which can, for example, be offered for immediate download in an online shop.
[0039] Furthermore, one or more computers and / or compute instances can be equipped with the computer program, the machine-readable data carrier, or the download product. DESCRIPTION OF THE FIGURES
[0040] The subject matter of the invention is explained below with reference to figures, without thereby limiting the subject matter of the invention. The following are shown:
[0041] Figure 1 (Figures 1a and 1b): Exemplary embodiment of the method 100 for operating a field device 1;
[0042] Figure 2: Exemplary representation of the communication paths when field device 1 is integrated into a network 6.
[0043] Figure 1, split into Figures 1a and 1b for reasons of space, is a schematic flowchart of an embodiment of method 100 for operating a field device 1. The field device 1 has an adjustable clock 2, which manages a current time 2a, and at least one non-volatile CA memory 3 with a public-key certificate 3a. a trusted certification authority (CA), at least one non-volatile time memory 4 for recording a date and / or time 4a, and at least one interface 5. In the embodiment shown in Figure 1, this Interface 5 is configured as a network interface for communication with a network 6. As explained previously, however, any other interface 5 can also be used, even if this interface 5 can only receive data unidirectionally from any remote device, such as an operator. How communication can proceed in the embodiment shown here, in which the field device is connected to a network 6 via a network interface 5, is explained in more detail in conjunction with Figure 2.
[0044] In the example shown in Figure 1, a public key certificate 9 is received via network interface 5 in step 110. This public key certificate 9 contains a date and / or time 9a for the start of its validity as well as a date and / or time 9b for the end of its validity. According to block 111, the received public key certificate 9 can, in particular, be used for... • a counterpart with which encrypted communication is to be established via network 6, and / or • be assigned to a user and / or machine that is to authenticate and / or authorize itself on field device 1.
[0045] In step 120, the public key certificate 3a from CA store 3 is used to check whether the received public key certificate 9 was validly signed by the trusted CA. If this is the case (truth value 1), in step 130 the date and / or time 4a in time store 4 is replaced by the date and / or time 9a on which the validity of the received public key certificate 9 begins.
[0046] According to Block 131, in particular, the date and / or time 9a, at which the validity of the received public key certificate 9 begins, can only be written to the time memory 4 if this date or time 9a is later than the date or time 4a already stored in the time memory 4.
[0047] Furthermore, in step 140, it can be checked whether the current time 2a, according to the adjustable clock 2 of the field device 1, fulfills a predefined condition. For example, this condition, according to block 141, can include the requirement that a predefined periodic or randomly selected interval has elapsed since the date or time 4a in the time memory 4.
[0048] If the condition is met (truth value 1 in step 140), in step 150 the current date and / or the current time 2a, according to the adjustable clock 2 of the field device 1, can be stored as new content 4a in the time memory 4.
[0049] In step 160, it is assumed that the non-volatile time memory 4 has been filled with a date and / or time 4a, regardless of the method used. A request 7 for the current date and / or time is then sent to a time server 8 via interface 5, or any other network interface.
[0050] In step 170, a current date and / or time 7a is received from the time server 8.
[0051] In step 180, this current date or time 7a is compared with the date or time 4a in the time memory 4.
[0052] According to Block 181, field device 1 can determine the time zone in which it is located. This can be done, for example, according to Block 181a, using • Location and / or language settings of field device 1, and / or • a position determined by field device 1 via a satellite-based positioning system, and / or • an IP address through which field device 1 gains access to the Internet.
[0053] According to block 182, the determined time zone can then be used when comparing the current date or time 7a with the date or time 4a in the time memory 4.
[0054] In step 190, it is checked whether the current date or time 7a, according to the response from time server 8, is later than the date or time 4a in time memory 4. If this is the case (truth value 1), in step 200 the adjustable clock 2 of field device 1 is set to the current date or time 7a as the new value 2a.
[0055] If, however, the current date or time 7a, according to the response from time server 8, is earlier than the date or time 4a in time memory 4 (truth value 0 in step 190) by more than a predefined tolerance amount, then an abusive backdating attempt can be detected according to block 191. This backdating attempt can then be addressed in any suitable manner.
[0056] For example, according to Block 192, the authentication and / or authorization of at least one user, and / or at least one machine, on field device 1 can be prevented.
[0057] Alternatively or in combination with this, according to Block 193 at least a subset of the total range of functions and / or services provided by field device 1 can be blocked.
[0058] In the example shown in Figure 1, in step 210, the field device 1 receives a user public key certificate 10, which a user and / or a machine uses to request authentication and / or authorization from the field device 1. As part of such a request, the user or machine can, for example, provide proof of possession of the private key corresponding to the public key certificate, such as by submitting a signed response to a challenge. In this way, the user or machine can prove that it is the user or machine named in the user public key certificate 10.
[0059] The user public key certificate 10 contains a date and / or time 10a for the start of its validity and a date and / or time 10b for the end of its validity. In step 220, the field device 1 checks whether the date or time 2a, according to its configurable clock 2, falls within the validity period 10a, 10b of this user public key certificate 10. If this is the case (truth value 1), the user public key certificate 10 is recognized as valid. Therefore, in step 230, the field device 1 then issues the authentication and / or Authorization of the user or machine is free. In this context, according to Block 211, the user public key certificate 10 can additionally contain information about which subset of the total functionality and / or performance provided by the field device 1 is enabled for the user or machine. That is, the field device 1 can then, in response to proof of possession of the private key to the user public key certificate 10 and confirmation that this user public key certificate 10 is valid, grant the user or machine access to precisely this functionality and / or performance.
[0060] In this context, the proposed procedure 100 has in particular the effect of making it more difficult to continue using a temporarily granted, already expired access by resetting the adjustable clock 2 of the field device 1 to a value 2a between the beginning 10a and the end 10b of the validity of the user public key certificate 10.
[0061] Furthermore, in step 240, the field device 1 can log at least one event with a timestamp containing a date and / or time 2a from the adjustable clock 2 of the field device 1.
[0062] In this context, the proposed method 100 has the particular effect of making it more difficult to falsify the timestamps by resetting the adjustable clock 2 of the field device 1 to arbitrary values 2a. As explained previously, such a falsification could, for example, result in a current event being stored as an older event in an event memory configured as a ring buffer, in a position from which it is soon displaced by newly arriving events and thus disappears permanently.
[0063] Figure 2 illustrates, by way of example, the communication paths between a field device 1 connected to a network e on the one hand and the other entities connected to this network e on the other.
[0064] The adjustable clock 2 of the field device 1 displays the current time 2a. At least one public-key certificate 3a from a trusted CA is stored in the CA memory 3, which can be used to verify the validity of incoming certificates 9 and 10. For clarity, the details of this verification are not shown in Figure 2. The field device 1 has a time memory 4 containing a date and time 4a that has demonstrably already occurred (passed). This means that the claim that an earlier date and time than the one stored in the time memory 4 is the current date and time can be immediately refuted.
[0065] In the exemplary situation shown in Figure 2, the field device 1 transmits a request 7 for a current date or time to the time server 8 connected to the network e via a network interface 5. The time server 8 responds with a current date or time 7a. Only if this "current" date or time 7a is actually later than the date or time 4a stored in the time memory 4, is the "current" date or time 7a adopted as the new value 2a of the adjustable clock 2.
[0066] The date or time 4a in the time memory 4 can now be updated in various ways to make it more difficult to reset the adjustable clock 2 of the field device 1.
[0067] Whenever a public key certificate 9 with a start 9a encoded as a date and / or time and an end 9b encoded as a date and / or time is presented to the field device 1, the start 9a can be adopted as a new date or new time 4a into the time memory 4, provided that it is later in time than the date or time previously stored there.
[0068] Additionally, the current date or time 2a can be updated at regular or irregular intervals according to the adjustable clock 2 of the field device 1. The date, or new time 4a, is transferred to the time memory 4. The frequency with which this occurs determines the maximum amount by which the adjustable clock 2 of the field device can be adjusted. 1 can be reset without this being noticed.
[0069] By allowing the adjustable clock 2 of the field device 1 to be reset only by small amounts, it is ensured that a user public key certificate 10 with a start date 10a of validity before the current value 2a of the adjustable clock 2 and an end date 10b of validity after this current value 2a of the adjustable clock 2 is actually valid, and has not expired due to manipulation of the adjustable clock. 2 is presented again as supposedly valid. REFERENCE MARK LIST 1 field device 2 adjustable clocks on field device 1 2a Value (date and / or time) of the adjustable clock 2 3 CA memory of field device 1 3a Public key certificate from a trusted CA 4 Time memory of the field device 1 4a Date and / or time in time memory 4 5 Interface, such as network interface, of the field device 1 6 Network for connecting field device 1 7 Request to time server 8 7a Date and / or time as per response from the time server 8 8 Time server network 6 9 Public Key Certificate 9a Start (date and / or time) of the validity of the public key certificate 9 9b End (date and / or time) of the validity of the public key certificate 9 10 User Public Key Certificate 10a Start date (date and / or time) of the validity of the user public key certificate 10 10b End (date and / or time) of the validity of the user public key certificate 10 100 Procedures for Operating the Field Device 1 110 Receiving the public key certificate 9 111 Choosing a public key certificate 9 for special purposes 120 Checking the validity of the public key certificate 9 130 Saving the start of validity 9a as a new value 4a in the time memory 4 131 Save only if validity start 9a is later than current value 4a in time memory 4 140 Checking a condition for current date / time 2a of the adjustable clock 2 141 Expiration of a time interval as a condition 150 Updating the value 4a with date / time 2a from adjustable clock 2 160 Sending request 7 to the time server 8 170 Receiving the date / time 7a from the time server 8 180 Comparing response 7a from time server 8 with value 4a in time memory 4 181 Determining the time zone of the field device 1 181 a special information sources for determining the time zone 182 Taking the determined time zone into account when comparing 190 Check if date / time 7a is later than value 4a in time memory 4 191 Determining an abusive backdating attempt 192 Preventing authentication and / or authorization 193 Blocking at least part of the functionality and / or performance scope 200 Adopting the date / time 7a as the new value 2a of the adjustable clock 2 210 Receiving a user public key certificate 10 211 Selection of a certificate 10 with specification of activated functions / services 220 Check if user public key certificate 10 is valid for the specified time 230 Granting authentication and / or authorization 240 Logging events with timestamps
Claims
REQUIREMENTS 1. Method (100) for operating a field device (1) comprising an adjustable clock (2), at least one non-volatile CA memory (3) containing a public key certificate (3a) of a trusted certification authority, CA, at least one non-volatile time memory (4) for recording a date and / or time (4a) and at least one interface (5), comprising the steps: • A current date and / or time (7a) is received via the interface (5) (170); • this current date or time (7a) is compared with the date or time (4a) in the time memory (4) (180); and • In response to the fact that the current date or time (7a) is later (190) than the date or time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set to the current date or time (7a) (200).
2. Method (100) according to claim 1, wherein • a public key certificate (9) is received via the interface (5) (110), wherein this public key certificate (9) contains a date and / or time (9a, 9b) for the beginning and end of its validity; • using the public key certificate (3a) from the CA store (3) to check (120) whether the received public key certificate (9) was validly signed by the trusted CA; and • if this is the case, the date and / or time (4a) in the time memory (4) is replaced by the date and / or time (9a) (130) on which the validity of the received public key certificate (9) begins.
3. Method (100) according to claim 2, wherein the public key certificate (9) received via the interface (5) • a counterpart with which encrypted communication is to be established over a network (6), and / or • is assigned to a user and / or machine that is to authenticate and / or authorise itself on the field device (1) (111).
4. Method (100) according to one of claims 2 to 3, wherein the date and / or time (9a) at which the validity of the received public key certificate (9) begins is written to the time memory (4) only if this date or time (9a) is later than the date or time (4a) already stored in the time memory (4).
5. Method (100) according to any one of claims 1 to 4, wherein during operation of the field device (1) the current date, and / or the current time (2a), according to the clock (2) of the field device (1) is stored in the time memory (4) (150) when a predetermined condition is met (140).
6. Method (100) according to claim 5, wherein the specified condition includes (141) that a a predetermined periodic or randomly selected interval has elapsed since the date or time (4a) in the time memory (4).
7. Method (100) according to any one of claims 1 to 6, wherein • the field device (1) determines the time zone in which it is located (181) and • this time zone when comparing the current date or time (7a) with the date or time (4a) used in the time memory (4) (182).
8. Method (100) according to claim 7, wherein the field device (1) determines the time zone in which it is located based on • Location and / or language settings of the field device (1), and / or • a position determined by the field device (1) via a satellite-based positioning system, and / or • an IP address through which the field device (1) gains access to the Internet (181a).
9. Method (100) according to any one of claims 1 to 8, wherein • the field device (1) receives (210) a user public key certificate (10) with which a user and / or a machine requests authentication and / or authorization at the field device (1), wherein this user public key certificate (10) contains a date and / or time (10a, 10b) for the start and end of its validity; • the field device (1) checks (220) whether the date or time (2a) is within the validity period (10a, 10b) of this user public key certificate (10) according to its adjustable clock (2), and, • if this is the case, the field device (1) releases the authentication and / or authorization of the user or machine (230).
10. Method (100) according to claim 9, wherein the user public key certificate (10) additionally contains information (211) about which subset of the total functionality and / or performance provided by the field device (1) is enabled for the user or for the machine.
11. Method (100) according to any one of claims 1 to 10, wherein the field device (1) records (240) at least one event with a timestamp containing a date and / or time (2a) from the adjustable clock (2) of the field device (1).
12. Method (100) according to one of claims 1 to 11, wherein a field device (1) is selected whose interface (5) is configured as a network interface for communication with a network (6).
13. Method according to claim 12, wherein • via the network interface (5) a request (7) for the current date, and / or the current time, is sent to a time server (8) (160) and • the current date and / or time (7a), via the network interface (5) of is received by the time server (8).
14. Method (100) according to any one of claims 1 to 13, wherein in response to the fact that the current date or time (8a) received via the interface (5) is ahead of the date or time (4a) in the time memory (4) by more than a predetermined tolerance amount, an abusive backdating attempt is detected (191).
15. Method (100) according to claim 14, wherein in response to the detection of an abusive backdating attempt, • the authentication and / or authorization of at least one user, and / or at least one machine, on the field device (1) is prevented (192), and / or • at least a subset of the total functionality and / or performance provided by the field device (1) is blocked (193).
16. Computer program containing machine-readable instructions which, when executed on one or more computers and / or compute instances, cause the computer(s) and / or compute instance(s) to execute the method (100) according to any one of claims 1 to 15.
17. Machine-readable data carrier and / or download product containing the computer program according to claim 16.
Citation Information
Patent Citations
Tamper protection for the clock of a field tool
DE102024122454A1
Methods and systems for secure time synchronization in industrial facilities
CN114667694B
method for receiving reliable time information
DE102006059487A1
Method and apparatus for maintaining trusted time at a client computing device
US20140095887A1