Method for transmitting a device report of a field device, and system
The method employs cryptographic keys for secure encryption and decryption of device reports, addressing the cost and authenticity issues in existing methods, ensuring efficient and reliable device report generation and storage.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2026-04-02
AI Technical Summary
Existing methods for creating device reports from field devices are costly and lack assurance of authenticity.
A method involving a system with a field device and a computing unit, utilizing cryptographic keys for secure encryption and decryption of device reports, enabling secure, automated transmission and storage without human interaction.
Ensures secure, authentic, and efficient generation and storage of device reports, reducing workload and preventing misuse or falsification, especially in systems with multiple field devices.
Smart Images

Figure EP2025074315_02042026_PF_FP_ABST
Abstract
Description
[0001] Method for transmitting a device report from a field device and system
[0002] The invention relates to a method for transmitting a device report from a field device and to a system.
[0003] Field devices are already known from the state of the art and are used in industrial plants. They are widely employed in process automation as well as in manufacturing automation. Field devices are defined as all devices that are used close to the process and that provide or process process-relevant information. Thus, field devices are used to acquire and / or influence process variables. Measuring instruments or sensors are used to acquire process variables. These are used, for example, for measuring pressure and temperature, conductivity, flow rate, pH, level, etc., and acquire the corresponding process variables such as pressure, temperature, conductivity, pH value, level, and flow rate. Actuators are used to influence process variables.These include, for example, pumps or valves that can influence the flow of a liquid in a pipe or the fill level in a container. In addition to the aforementioned measuring devices and actuators, field devices also include remote I / Os, radio adapters, and generally any devices located at the field level.
[0004] A large number of such field devices are produced and distributed by the Endress+Hauser Group.
[0005] In modern industrial plants, field devices are typically connected to higher-level units via communication networks such as fieldbuses (PROFINET, EtherNet / IP, Modbus, Profibus®, Foundation® Fieldbus, HART®, etc.). These higher-level units are usually control systems (DCS) or control units, such as a PLC (programmable logic controller). The higher-level units are used, among other things, for process control, process visualization, process monitoring, and commissioning of the field devices. The measured values acquired by the field devices, especially sensors, are transmitted via the respective bus system to one (or possibly several) higher-level unit(s). Data transmission from the higher-level unit to the field devices via the bus system is also necessary, particularly for configuring and parameterizing field devices and controlling actuators.
[0006] Mobile operating devices are frequently used to operate field devices (e.g., parameterizing or retrieving data). These are connected to a field device either via cable (e.g., a service interface) or wirelessly (e.g., via Bluetooth). Examples of operating devices include laptops, mobile devices such as smartphones or tablets, or a central asset management station. Appropriate operating programs (operating tools) are required to operate the field devices. These programs either run independently on the higher-level units or on the mobile operating devices (Endress+Hauser FieldCare, PACTware, AMS Fisher-Rosemount, Siemens PDM) or are integrated into control room applications (Siemens PCS7, ABB Symphony, Emerson Delta V). The term "operating" encompasses, among other things, parameterizing the field device, updating the field device, and / or querying and visualizing process data and / or diagnostic data from the field device.
[0007] The integration of field devices into such operating programs is achieved via device drivers or device descriptions. These are provided by the device manufacturers so that the higher-level units, or the operating programs running on these higher-level units, can recognize and interpret the meaning of the information supplied by the field devices. Such an operating program, into which the device descriptions or device drivers are loaded, is also referred to as a framework application.
[0008] For comprehensive operation of field devices, special device drivers, so-called DTMs (Device Type Managers), are available that comply with the FDT (Field Device Tool) specifications or correspond to FDI packages in the FDI environment. Many field device manufacturers supply corresponding DTMs for their field devices. The DTMs encapsulate all variables and functions of the respective field device and usually offer a graphical user interface for operating the devices within the framework application.
[0009] The device drivers offer the possibility to evaluate, diagnose, and / or verify certain device functionalities. Many modern field devices, for example, enable a self-test, such as within the framework of so-called "Heartbeat Technology" (a self-test functionality or SIL functionality implemented in the applicant's field devices). The result of these self-tests, evaluations, etc., is output by the device driver in a report. This report contains the relevant report parameters, i.e., test results, device status, etc. The report is then sent directly to a printer and printed out in physical form.
[0010] A method for creating such reports is known, for example, from DE 10 2021 124 249 A1. However, a disadvantage of this method is that creating and storing physical reports is costly. Therefore, the creation of electronic reports is proposed in the prior art. However, a problem here is that the authenticity of the report cannot yet be guaranteed.
[0011] It is therefore an object of the invention to provide a method that enables the secure, authentic, and simple creation of a device report. This object is achieved according to the invention by a method for transmitting a device report from a field device according to claim 1.
[0012] The method according to the invention comprises:
[0013] Providing a system comprising a field device, a local network, and a computing unit, wherein the field device includes a first communication unit and the computing unit includes a second communication unit and software, wherein the computing unit further comprises a first cryptographic key and a second cryptographic key complementary to the first cryptographic key, or is capable of generating the first cryptographic key and the second cryptographic key, wherein the first communication unit and the second communication unit are interconnected via the local network.
[0014] Generating a device report by the field device,
[0015] Inform the computing unit about the availability of a device report via the local network,
[0016] The software transmits the first cryptographic key to the field device via the local network.
[0017] Encrypting the device report by the field device,
[0018] Transmitting the encrypted device report over the local network, decrypting the encrypted device report with the second cryptographic key using the software.
[0019] The method according to the invention enables device reports to be transmitted and stored securely and automatically, i.e., without human interaction. This provides a convenient and reliable way to generate proof of the current device status of a field device. In a system with a large number of field devices, this significantly reduces the workload. Furthermore, the encrypted transmission of the device report prevents misuse or falsification.
[0020] According to one embodiment of the invention, a public key is transmitted when transferring the cryptographic key, and a private key of the computing unit that is complementary to the public key is used when decrypting the encrypted device report.
[0021] According to a further embodiment of the invention, the method further comprises storing the decrypted device report in a local memory of the processing unit. According to another embodiment of the invention, a serial number of the field device is transmitted when informing the processing unit.
[0022] According to one embodiment of the invention, the local memory has a folder exclusively assigned to the field device, and storing the decrypted device report includes storing the decrypted device report in the folder exclusively assigned to the field device.
[0023] According to one embodiment of the invention, the computing unit further comprises a communication channel and the communication channel is connected to a storage device external to the local network, the method further comprising storing the decrypted device report in the external storage device.
[0024] According to one embodiment of the invention, the device report includes a file in PDF or CVS format.
[0025] According to one embodiment of the invention, the computing unit is a local server.
[0026] According to one embodiment of the invention, the local network is an Ethernet-based wired or wireless network.
[0027] The above-mentioned problem is also solved by a system according to claim 10.
[0028] The system according to the invention comprises: a field device, a computing unit, wherein the field device is connected to the computing unit via a local network, and wherein the system is suitable for carrying out the method according to the invention.
[0029] The invention is explained in more detail with reference to the following description of the figures. Figure 1 shows a schematic representation of the system according to the invention.
[0030] The system 100 according to the invention comprises at least one field device 10, a local network 20, and a computing unit 30. The field device 10 is communicatively connected to the computing unit 30 via the local network 20. Optionally, the system 100 includes an external memory 40 capable of communicating with the computing unit 30.
[0031] The field device 10 comprises a first communication unit 11. The field device 10 is capable of generating a device report 12. The device report 12 is, for example, a file in PDF or CSV format, or another format. The field device 10 also preferably comprises a field device memory 14 and a user interface 15. The device report 12 is generated automatically by the field device 10 at regular intervals. The times for generating the device report 12 are communicated to the field device 10 by a user, for example. Of course, spontaneous generation of a device report 12 is also possible by entering a user command at the user interface 15 on the field device 10. Alternatively, the user command is transmitted, for example, via the local network 20 from the processing unit 30.
[0032] Field device memory 14 contains data about field device 10, such as serial number and other data.
[0033] The user interface 15 is, for example, a touch display or another input unit.
[0034] Local area network 20, for example, is an Ethernet-based wired or wireless network.
[0035] The computing unit 30 comprises a second communication unit 31 and software 32. The computing unit 30 is preferably a local server. The computing unit 30 further comprises a first cryptographic key 33 and a second cryptographic key 36 complementary to the first cryptographic key 33 and / or is capable of generating the first cryptographic key 33 and the second cryptographic key 36.
[0036] The computing unit 30 further preferably comprises a local memory 35 and a communication channel 37. The local memory 35 is, for example, volatile or persistent memory. The local memory 35 preferably comprises a folder exclusively assigned to the field device 10.
[0037] Communication channel 37, for example, is a wireless communication interface suitable for connecting to external storage 40. External storage 40 is, for example, cloud storage, such as Endress+Hauser's cloud-based IoT ecosystem "Netilion".
[0038] The method according to the invention is described below.
[0039] In a first step, the system 100 described above is deployed. Subsequently, a device report 12 is generated by the field device 10. The device report 12 is generated either automatically by the field device 10 or by a specific user command.
[0040] Then, the computing unit 30 is informed of the availability of a device report 12 via the local network 20. Preferably, the target URL or the IP address of the computing unit 30 is stored in the field device 10. For this purpose, a message is sent, for example, from the first communication unit 11 to the second communication unit 31. The message includes, for example, a unique identifier, such as the serial number, of the field device 10.
[0041] If a first cryptographic key 33 and a second cryptographic key 36 are already stored in the computing unit 30, for example in local memory 35, then the first cryptographic key 33 is transferred by the software 32 to the field device 10 via the local network 20.
[0042] Alternatively, the first cryptographic key 33 and the second cryptographic key 36 are first generated by the software 32 and stored, for example, in local memory 35. The transfer of the first cryptographic key 33 then takes place as described above.
[0043] Of course, it is also possible to upload the first cryptographic key 33 and the second cryptographic key 36 to the computing unit 30, i.e., to transmit them from a secure external source, for example via the communication channel 37. However, this would pose a security risk if the transmission were not "eavesdropping-proof".
[0044] The first cryptographic key 33, which is transmitted to the field device 10, is preferably a so-called public key and the second cryptographic key 36 is preferably a so-called private key.
[0045] Furthermore, the field device 10 encrypts the device report 12. The field device 10 uses the first cryptographic key 33 received from the computing unit 30.
[0046] Next, the encrypted device report 13 is transmitted via the local network 20. For this purpose, the first communication unit 11 of the field device 10 sends the encrypted device report 13 to the second communication unit 31 of the computing unit 30. Thanks to this encrypted transmission, it is not possible for a so-called "man-in-the-middle" to read the original device report 12, even if he were to "eavesdrop" on the communication.
[0047] During transmission, the encrypted device report 13 is preferably received by the software 32 and stored in the local memory 35 of the processing unit 30. The software 32 then decrypts the encrypted device report 13. For this purpose, the software 32 uses the second cryptographic key 36, which is complementary to the first cryptographic key 33. After decryption, the decrypted device report 34 is preferably stored in local memory 35 of the processing unit 30. The decrypted device report 34 is preferably stored directly in the folder exclusively assigned to the field device 10. This has the advantage that, with multiple field devices in the system 100, the respective device reports 12 can be easily located. Optionally, decryption can also be performed only upon user request, and the encrypted device report 13 is stored directly.
[0048] According to the embodiment of the invention shown in Figure 1, the system 100 optionally also includes the external memory 40. In this case, an optional further step of storing the decrypted device report 34 in the external memory 40 takes place.
[0049] Reference symbol list
[0050] 10 field devices
[0051] 11 first communication unit
[0052] 12 devices report
[0053] 13 encrypted device report
[0054] 14 field device storage
[0055] 20 local network
[0056] 30 computing units
[0057] 31 second communication unit
[0058] 32 Software
[0059] 33 cryptographic keys
[0060] 34 decoded device report
[0061] 35 local storage
[0062] 36 private cryptographic keys
[0063] 37 Communication channel
[0064] 40 external storage
[0065] 100 System
Claims
Patent claims 1. A method for transmitting a device report (12) from a field device (10) comprising: providing a system (100) with a field device (10), a local network (20) and a computing unit (30), wherein the field device (10) has a first communication unit (11) and the computing unit (30) has a second communication unit (31) and software (32), wherein the computing unit (30) further comprises a first cryptographic key (33) and a second cryptographic key (36) complementary to the first cryptographic key (33) or is capable of generating the first cryptographic key (33) and the second cryptographic key (36), wherein the first communication unit (11) and the second communication unit (31) are connected to each other via the local network (20), generating a device report (12) by the field device (10), Informing the computing unit (30) about the availability of a device report (12) via the local network (20), Transfer of the first cryptographic key (33) by the software (32) to the field device (10) via the local network (20), Encrypting the device report (12) by the field device (10), Transmitting the encrypted device report (13) over the local network (20), decrypting the encrypted device report (13) with the second cryptographic key (36) by the software (32).
2. Method according to claim 1, wherein a public key is transmitted when transferring the cryptographic key (33) and a private key (36) of the computing unit (30) complementary to the public key is used when decrypting the encrypted device report (13).
3. Method according to one of the preceding claims, wherein the method further comprises storing the decrypted device report (34) in a local memory (35) of the computing unit (30).
4. Method according to claim 3, wherein a serial number of the field device (10) is transmitted when informing the computing unit (30).
5. Method according to claim 4, wherein the local memory (35) has a folder exclusively assigned to the field device (10) and the storage of the decrypted Device report (34) includes storing the decrypted device report (34) in the folder exclusively assigned to the field device (10).
6. Method according to one of the preceding claims, wherein the computing unit (30) further comprises a communication channel (37) and the communication channel (37) is connected to a storage device (40) external to the local network (20), wherein the method further comprises storing the decrypted device report (34) in the external storage device (40).
7. Method according to one of the preceding claims, wherein the device report (12) comprises a file in PDF or CVS format.
8. Method according to any of the preceding claims, wherein the computing unit (30) is a local server.
9. Method according to any of the preceding claims, wherein the local network is an Ethernet-based wired or wireless network.
10. System (100) comprising: a field device (10), a computing unit (30), wherein the field device (10) is connected to the computing unit (30) via a local network (20), wherein the system (100) is suitable for performing the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method for recording the results of an evaluation, diagnosis and / or verification of at least one device functionality of a field device
DE102021124249A1
Method and system for documenting logbook data from one or more first field devices
DE102022130426A1
Device specific cryptographic content protection
US20170302456A1
Method for authenticating a field device of automation technology
US20180234249A1