Controlling data access

The method provides secure and transparent data access control in chemical industry networks by separating authentication and operation functions, using identity values and structured networks, ensuring safety and flexibility in updates and access management.

WO2026093092A1PCT designated stage Publication Date: 2026-05-07BASF SE
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BASF SE
Filing Date
2025-10-22
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

There is an increasing demand for safe and transparent data access control in computer networks, particularly in the chemical industry, where existing methods lack effective mechanisms for secure and transparent data access management.

Method used

A method involving separate predefined services for authentication and operation functions, with integrated service access rules, allows for decentralized updates and revisions, using identity values to enhance security, and includes pipeline services for data transfer, deployment services for safe deployment, and operation networks for structured access control, along with a supervisor service for statistical matching of access requests to operation protocols.

Benefits of technology

Ensures secure, transparent, and stable data access by maintaining user identity secrecy, reducing complexity, and preventing unintended interferences, while allowing for flexible and safe updates and revisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025080507_07052026_PF_FP_ABST
    Figure EP2025080507_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A method (M) for controlling data access (114) of a plurality of predefined services (104, 108, 116, 122, 124, 126, 138) of a computer network, in particular a computer network of a process network in chemical industry, the method including: providing (S10) predefined service access rules (102), each service access rule (102) including at least one authentication and / or authorization mechanism; providing (S12) at least one predefined authentication service (108), which is configured to authenticate a user (100) based on at least one of the provided service access rules (102); and providing (S16) at least one predefined operation service (122, 124, 126), which is configured to determine an authorization of a user (100), that is authenticated by the authentication service (108), based on a provided service access rule (102), and is configured to grant to an authorized user (100) data access (114) to data. A computer-program product.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] 230234

[0002] 1

[0003] Controlling data access

[0004] This disclosure relates to a method for controlling data access of a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry. This method further relates to a computer-program product.

[0005] In computer networks, especially in the chemical industry, there is an increasing demand for safe and transparent data access control.

[0006] It is therefore an object of the present disclosure to provide means for granting safe and transparent data access control.

[0007] According to one aspect of this invention, a method for controlling data access of a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry, is suggested. The suggested method includes: providing predefined service access rules, each service access rule including at least one authentication and / or authorization mechanism; providing at least one predefined authentication service, which is configured to authenticate a user based on at least one of the provided service access rules; and providing at least one predefined operation service, which is configured to determine an authorization of a user, that is authenticated by the authentication service, based on a provided service access rule, and is configured to grant to an authorized user data access to data.

[0008] The suggested method may be understood as a combination of a) a separation of function with b) a coordination of rules. First, functions are provided by separate predefined services, where each service is prepared to fulfill its objective function, such as an authentication function and an operation function. Thus, each service may be audited by different people with appropriate different skills, which makes the functions safely implementable. Having different predefined services for different functions can keep a software transparent even through multiple updates I revisions. Second, the service access rules can be integrated and administered together. Thus, the service access rules can be coordinated. This makes the predefined service access rules transparent for an administrator, even through multiple updates I revisions. In this context, it may be important that an update or revision preferably refers to single services, as this method allows to update and / or revise services and / or rules in a decentralized manner.

[0009] Optionally, the / each authentication service may be configured to assign at least one identity value to a / the user if the user is authenticated. Further, the / each operation service may be configured to determine an authorization of a / the user by determining whether an identity value assigned to this user complies with a provided service access rule. In other words, an original user identity is replaced by an identity value assigned to the user. The original user identity is usually related to a login identity, a password, a second factor of a multi-factor authorization, and the like, which are best kept secret. Accordingly, this option keeps these user identity data secret from non-authorization services, which 230234

[0010] 2 increases safety and security. The identity value may be indicative of the authentication service, to increase security of user credentials.

[0011] Optionally, the suggested method may have: providing at least one predefined pipeline service, wherein the at least one operation service and / or the at least one authentication service and / or a supervisor service may preferably be configured to grant data access via a pipeline service. Preferably, the pipeline service is pre-selected and / or it is predefined based on the data access. A pipeline service may preferably mean a service configured for handling data transfer and / or transferring between a user and an operation service, between different operation services, between an operation service and a data storage, and / or between operation services in different operation networks. A pipeline service is preferably configured for repeated and / or data-information-independent and / or data-type-specific data transfer. Having the at least one pipeline service reduces complexity and increases transparency of the provided rules, services, and pipelineZ-s, which may collectively be referred to as a software kit.

[0012] Optionally, if the operation service is a deployment service, then the provided service access rule associated to this deployment service may be configured to require a presence of a release indicator authenticated by a different user. A deployment service may mean an operation service that is configured to grant data access to data, which data includes a service. In short: a deployment service is configured to overwrite data of an existing service. Thus, a new service and / or an updated service may be deployed by use of the deployment service. This option ensures a 4-eye principle via the service access rule. Optionally, the deployment service may be configured to perform a pre-deploy- ment scan and to deploy a service only if the pre-deployment scan is successfully terminated. This increases safety and stability of the provided services. The scan may be or include an automated code execution stability scan to ensure execution stability. The scan may be or include an automated code vulnerability scan to ensure resilience against hacking. The scan may be or include an automated code standard conformity scan to ensure readability and / or reusability of a code underlying the respective service.

[0013] Optionally, at least one role indicator may be assigned to the user and / or to the identity value, when the authentication service authenticates the user. Further, at least one provided service access rule may assign at least one data access to said role indicator. Having user roles implemented in the service access rules increases transparency, which in turn increases safety of the services provided.

[0014] Optionally, there may be provided a plurality of operation services. Further, a first operation service may be configured to grant to an authorized user an operation access and / or data access to a second operation service. In other words, the first operation service may be configured to forward the user to the second operation service during operation of this first operation service, if the first operation service determines that the user is authorized based on a / the provided service access rule. Thus, the safe and transparent authorization and access according to this suggested method is expanded to more complex sets of services, such as software environments for multiple use cases within the chemical industry. 230234

[0015] 3

[0016] Optionally, there may be provided a plurality of operation networks, wherein each operation service may be assigned to one operation network, and wherein each operation service is configured to grant to an authorized user an operation access to another operation service only if both operation services share an operation network. Two operation services share an operation network preferably if they are both assigned to this operation network or to a child network thereof. This preferably includes the case where a second operation network is nested into a first operation network. Having operation networks according to this option improves executional safety in two stages. First, by limiting access to services, especially operation services and / or pipeline services outside of the own operation network. This can limit unintended interferences or exploitations of vulnerabilities. Second, by structuring and packaging services into networks, which increases transparency, which in turn increases safety. An operation network may mean a technically separated network, such as a network separated by a so-called firewall from other networks. An operation network may mean a group of one or more services, which is logically separated from other groups of services, such as a software-defined network. More generally, a network may mean a group of services, which group is technically, electronically, and / or logically separated from at least on further group of services, wherein this separation is configured to at least restrict and preferably block inter-group communication.

[0017] Optionally, the suggested method may include: appending for each granted access an access indicator indicative of the respective granted access to data and / or to a service to an operation protocol. This may be further expanded, such that the suggested method may include: appending for each operation performed by an operation service, including when access to data and / or to a service is granted, an operation indicator indicative of the respective operation to an operation protocol. This option prepares the method to create the operation protocol. Then, the operation protocol can be used for improvements. For example, the method may include: providing a supervisor service which is configured to determine whether a request for data access by an operation service statistically matches the operation protocol, and to prevent the requested access when a statistical match is not determined. Thus, an exploitation of a vulnerability and / or a malfunction may be automatically detected and prevented. A statistical match may mean that a pattern of the requested data access and of the operation indicators related to this request does not match to a pattern of operation indicators statistically determined from the operation protocol.

[0018] According to a preferred aspect, the suggested method is a method for controlling data access in security monitoring services of a computer network, in particular a computer network of a process network in chemical industries, including: providing service access rules based on role policies, comprising authentication and authorization mechanisms, for controlling access to predefined services; providing a first predefined service, the service being configured to authenticate to at least one further predefined service, comprising data read and / or write access; based on a user request enabling access to the first predefined service; upon enabling access to the first service: performing an authentication step between the first service and the at least on further service comprising data read and / or write access; and based on the result of the authentication process between the first and the a least one further service: granting read and / or write access. 230234

[0019] 4

[0020] According to another aspect of the invention, there is suggested to a computer-program product or controlling data access to a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry, the computer-program product comprising a program code for executing the suggested method or controlling data access to a plurality of predefined services of a computer network by a computerized device when run on at least one computerized device. A computer program product, such as a computer program means, may be embodied as a memory card, USB stick, CD-ROM, DVD or as a file which may be downloaded from a server in a network. For example, such a file may be provided by transferring the file comprising the computer program product from a wireless communication network.

[0021] According to a further aspect, a computer-readable medium storing computer program instructions, wherein the computer program instructions, when executed by a computerized device, cause the computerized device to perform operations comprising the suggested method or controlling data access to a plurality of predefined services of a computer network. The computer-readable medium is, in particular, a non-transitory computer-readable medium.

[0022] Further possible implementations or alternative solutions of the invention also encompass combinations - that are not explicitly mentioned herein - of features described above or below in regard to the embodiments. The person skilled in the art may also add individual or isolated aspects and features to the most basic form of the invention.

[0023] Further embodiments, features and advantages of the present invention will become apparent from the subsequent description and dependent claims, taken in conjunction with the accompanying drawings, in which:

[0024] Fig. 1 shows schematically an interaction diagram illustrating an interaction between a user and service access rules, services, and operation networks which are provided by performing a method for controlling data access to a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry, according to an embodiment of the invention; and

[0025] Fig. 2 shows schematically a flow diagram of the method for controlling data access to a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry, according to the embodiment of the invention.

[0026] In the Figures, like reference numerals designate like or functionally equivalent elements, unless otherwise indicated.

[0027] Fig. 1 shows interactions between a user 100, predefined service access rules 102, predefined services 104, and predefined operation networks 106. The service access rules 102, services 104, and operation networks 106 are provided by performing a method M for controlling data access 114 of a plurality of predefined services 104, 108, 116, 122, 124, 126, 138 of a computer network (not illustrated). 230234

[0028] 5

[0029] Each service access rule 102 includes an authentication and / or authorization mechanism. Each of these mechanisms is configured to control an authentication request 110 of a user 100 at a service 104 and / or an authorization of a request of the user 100 at the service 104.

[0030] One of the provided services 104 is an authentication service 108. The user 100 authenticates his / her original identity at the authentication service 108 during an authorization request 110.

[0031] The authentication service 108 performs a lookup 112 to one of the service access rules 102. Then, the authentication service 108 performs a data access 114 via a pipeline service 116 to a data base 118. The pipeline service 116 is also a service 104 provided by performing the method M.

[0032] The authentication of the user 100 is assumed to be successful here. The data base 118 then provides the authentication service 108 with an identity value 120. The identity value 120 may for example indicate the individual user 100. The identity value 120 may for example indicate a role of the user 100. The identity value may for example indicate a successful authentication of any user 100 with the authentication service 108.

[0033] Then, the user 100 performs another authentication request 110 via a pipeline service 116 at a first operation service 122. This request 110 is authenticated by the identity value 120 from the authentication service 108. This authentication request 110 is implicit, as it is performed for example by calling the first operation service 122 from the authentication service 108. That is, the services provided by the suggested method M ensure communicatively a safe propagation of a single authentication by the user 100.

[0034] The first operation service 122 performs another lookup 112 to one of the service access rules 102. Then, the first operation service 122 performs a data access 114 via a pipeline service 116 to a data base 118.

[0035] Preferably, all data bases 118 described here are one single data base 118. In this case, the pipeline services 116 are the same single pipeline service 116. However, even if it is one single data base 118, the user 100 accesses different data on this data base 118 depending on the service 104, at which the data access 114 is requested. Which data is accessible within the respective data base 118 is preferably governed by the service access rule 102 of this service 104 and / or of the data access 114.

[0036] Further, the first operation service 122 is configured to access a second operation service 124. For example, the first operation service 122 may be a control service for controlling a chemical production system while the second operation service 124 may be a control service for controlling a chemical production device within said chemical production system. Thus, the first operation service 122 performs another authentication request 110 via a pipeline service 116 to the second operation service 124. 230234

[0037] 6

[0038] Fig. 1 shows a third operation service 126. The provided operation networks 106 separate the operation services into groups. However, for the sake of comprehensibility, only one operation service 122, 124, 126 is shown per operation network 106. There are three operation networks 106 in this example. A first operation network 128 includes the first operation service 122 and a second operation network 130. The second operation network 130 includes the second operation service 124. That is, the second operation network 130 is nested within the first operation network 128; one may refer to the first operation network 128 as a parent network and to the second operation network 130 as a child network in this regard. A third operation network 132 is independent and / or parallel to the first operation network 128. Thus, a request 110, an operation access 144 and / or a data access 114 is possible between the first operation service 122 and the second operation network 130 and / or the second operation service 124, but it is prevented between the first operation service 122 and the third operation network 132 or the third operation service 126.

[0039] The operation networks 106, 128, 130, and 132 are preferably logic separations and / or communicative separations within an electronically connected computer network.

[0040] An operation protocol 134 is provided. The operation protocol 134 preferably has the form of a data base. An operation indicator 136 is appended to this operation protocol 134 for each operation performed by an operation service 122, 124, 126 indicative of this operation. Preferably, each provided operation service 122, 124, 126 is configured to perform this appending together when performing the indicated operation.

[0041] Further, there is provided a supervisor service 138. When an operation service 122, 124, 126 requests a data access 114, the supervisor service 138 determine whether this request for data access statistically matches the operation protocol 134 by means of a statistical evaluation 140. When the statistical match is not determined, then the supervisor service 138 prevent the requested data access 114 by not issuing a data access grant 142.

[0042] Next will be described a flow diagram of Fig.2 illustrating a performing of the method M for controlling data access to a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry.

[0043] In a first step S10, the plurality of service access rules 102 is provided. Each service access rule includes the at least one authentication and / or authorization mechanism.

[0044] In a next step S12, the at least one an authentication service 108 is provided. The authorization service 108 is configured to authenticate the user 100 based on at least one of the provided service access rules 102.

[0045] In a next step S14, the plurality of operation networks 128, 130, and 132 is provided.

[0046] In a next step S16, the operation services 122, 124, and 126 are provided. Each operation service 122, 124, 126 is configured to determine an authorization of the user 100, who is authenticated by the authentication service 108, 230234

[0047] 7 based on each at least one provided service access rule 102. Further, each operation service 122, 124, 126 is configured to grant to an authorized user 100 access to data at the data base 118. Here, the first operation service 122 is configured to grant operation access to the authorized user 100 to the second operation service 124. Each operation service 122, 124, 126 is assigned to one operation network 128, 130, 132. Each operation service 122, 124, 126 is configured grant operation access to the authorized user 100 only to another operation service 122, 124, 126, if both operation services 124, 126, 128 share an operation network 128, 130, 132.

[0048] In a next step S18, the pipeline services 116 are provided. At least one - preferably: each - operation service 122, 124, 126 is configured to grant to an authorized user 100 access to data at the data base 118 via a provided pipeline service 116.

[0049] In a next step S20, a supervisor service 134 is provided. It is configured to determine, whether a request for data access 114 by an operation service 122, 124, 126 statistically matches the operation protocol 134, and to prevent the requested access 114 when a statistical match is not determined.

[0050] A next step S22 is for example performed during each operation of any operation service 122, 124, 126 and / or it is initiated together with each operation of any operation service 122, 124, 126. In this step S22, the operation indicator 136 indicative of the respective operation is appended to the operation protocol 134.

[0051] Thus, by performing the method M, a secure and transparent data access for at least one predefined operation service is created.

[0052] Reference signs:

[0053] 100 user

[0054] 102 service access rule

[0055] 104 service

[0056] 106 operation network

[0057] 108 authentication service

[0058] 110 authorization request

[0059] 112 lookup

[0060] 114 data access

[0061] 116 pipeline service

[0062] 118 data base

[0063] 120 identity value

[0064] 122 first operation service

[0065] 124 second operation service

[0066] 126 third operation service. 230234

[0067] 8

[0068] 128 first operation network

[0069] 130 second operation network

[0070] 132 third operation network

[0071] 134 operation protocol 136 operation indicator

[0072] 138 supervisor service

[0073] 140 statistical evaluation

[0074] 142 data access grant

[0075] 144 operation access M method for controlling data access to a plurality of predefined services of a computer network

[0076] S10 providing service access rules

[0077] S12 providing at least one authentication service

[0078] S14 providing a plurality of operation networks

[0079] S16 providing a plurality of operation services S18 providing at least one pipeline service

[0080] S20 providing a supervisor service

[0081] S22 appending for each operation an operation indicator to an operation protocol

Claims

2302349Claims1. A method (M) for controlling data access (114) of a plurality of predefined services (104, 108, 116, 122, 124, 126, 138) of a computer network, in particular a computer network of a process network in chemical industry, the method including: providing (S10) predefined service access rules (102), each service access rule (102) including at least one authentication and / or authorization mechanism; providing (S12) at least one predefined authentication service (108), which is configured to authenticate a user (100) based on at least one of the provided service access rules (102); and providing (S16) at least one predefined operation service (122, 124, 126), which is configured to determine an authorization of a user (100), that is authenticated by the authentication service (108), based on a provided service access rule (102), and is configured to grant to an authorized user (100) data access (114) to data.

2. The method of claim 1, wherein the authentication service (108) is configured to assign at least one identity value (120) to the user (100) if the user (100) is authenticated, and wherein the operation service (122, 124, 126) is configured to determine an authorization of a user (100) by determining whether an identity value (120) assigned to this user (100) complies with a provided service access rule (102).

3. The method of claim 1 or 2, further including: providing (S18) at least one pipeline service (116), wherein the at least one operation service (122, 124, 126) is configured to grant data access (114) via a pipeline service (116).

4. The method of any of claims 1 to 3, wherein if the operation service (122, 124, 126) is a deployment service, then the provided service access rule (102) associated to this deployment service is configured to require a presence of a release indicator authenticated by a different user.

5. The method of claim 4, wherein the deployment service is configured to perform a pre-deployment scan, and is configured to deploy a service (104) only if the pre-deployment scan is successfully terminated.

6. The method of any of claims 1 to 5, wherein at least one role indicator is assigned to the user (100) and / or to the identity value (120), when the authentication service (108) authenticates the user (100), and wherein at least one provided service access rule (102) assigns at least one data access (114) to said role indicator.230234107. The method of any of claims 1 to 6, wherein there is provided a plurality of operation services (122, 124, 126), and wherein a first operation service (122) is configured to grant operation access to an authorized user (100) to a second operation service (124).

8. The method of claim 1 to 7, further including: providing (S14) a plurality of operation networks (106, 128, 130, 132), wherein each operation service (122, 124, 126) is assigned to one operation network (106, 128, 130, 132), and wherein each operation service (122, 124, 126) is configured to grant operation access to an authorized user (100) only to another operation service (122, 124, 126), if both operation services (122, 124, 126) share an operation network (106, 128, 130, 132).

9. The method of any of claims 1 to 8, further including: appending (S22) for each operation (114) performed by an operation service (122, 124, 126), including when access (114) to data and / or to a service is granted, an operation indicator (136) indicative of the respective operation to an operation protocol (134).

10. The method of claim 9, further including: providing a supervisor service (138), which is configured to determine whether a request for data access (114) by an operation service (122, 124, 126) statistically matches the operation protocol (134), and to prevent the requested data access (114) when a statistical match is not determined.

11. A computer-program product for controlling data access of a plurality of predefined services of a computer network, in particular a computer network of a process network in chemical industry, the computer-program product comprising a program code for executing the method (M) of any of claims 1 to 10 by a computerized device when run on at least one computerized device.

Citation Information

Patent Citations

  • Industrial production network access control method and system

    CN118646549A

  • Distributed security for industrial networks

    US20040162996A1

  • Automated compliance and artifact generation for regulatory software change management policies

    US20240281248A1