Field Device Access Release for Secure Multi-User Credential Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the process automation and industry, managing access information for field devices across multiple users and devices is cumbersome, especially in large systems, as existing solutions do not facilitate secure sharing of access information between users, such as service employees or employees within a company, leading to increased effort and potential security risks.

Innovation Solution

A method and system that allows users to define, assign, and share access information for field devices through a user's operating device and a server, enabling any user to individually share or lend access information with other users, with options for varying authorization levels and temporary or permanent access, using a server to manage and synchronize access information across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access information is stored locally on each user's operating device, then each user can independently access field devices, but the effort and complexity increase significantly when managing access information across multiple users and devices

Engineering Contradiction:
ImproveIndependent access capabilityVSAvoidAccess information management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines multiple operating devices and users into a unified system managed by a central server. The server consolidates access information for all users and field devices, enabling centralized management while maintaining individual access capabilities. This resolves the contradiction by merging distributed access management into a unified system, reducing overall complexity while preserving independent access.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server implements universal access information management that serves multiple users and multiple field devices simultaneously. A single access information item can be shared across multiple users and devices through the server, eliminating the need for separate local storage on each device. This multi-functional approach reduces management complexity while maintaining independent access capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If access information is shared across multiple operating devices, then user effort is reduced, but security risks increase due to potential unauthorized access

Engineering Contradiction:
ImproveAccess efficiencyVSAvoidSecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The server acts as an intermediary between users and field devices, controlling access information distribution. Instead of direct sharing between devices, the server mediates all access requests, verifying user credentials and managing authorization. This intermediary approach enables efficient access sharing while maintaining security through centralized control and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the server continuously monitors and manages access information distribution. User credentials and authorization levels are verified dynamically, and access rights can be adjusted based on user roles and requirements. This feedback loop ensures secure sharing by maintaining real-time control over access information.

Inventive Principle:
Principle #23Feedback

3Reliability

If each user has separate access information on each device, then security is maintained, but the time and effort for managing access across multiple devices increases

Engineering Contradiction:
ImproveSecurity maintenanceVSAvoidAccess information management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The server performs preliminary action by pre-configuring and storing access information for all users and field devices before actual access is needed. When a user needs to access a field device, the server has already prepared and validated the necessary credentials. This preliminary setup eliminates the need for users to manually configure access information on each device, reducing management time while maintaining security through pre-validated credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The server creates and manages copies of access information that can be distributed to multiple users and devices. Instead of requiring separate original credentials on each device, the server generates and manages secure copies that can be shared across the system. This copying mechanism reduces management time while maintaining security through centralized control of the master copies.

Inventive Principle:
Principle #26Copying

4Device complexity

If access information is centralized on a server, then management complexity is reduced, but the system becomes more vulnerable to centralized attacks

Engineering Contradiction:
ImproveAccess information management complexityVSAvoidCentralized attack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments access information into distinct components stored and managed by the server, with each user having individual credentials and authorization levels. Rather than storing a single master set of credentials, the system divides access information into user-specific segments that can be independently managed and revoked. This segmentation reduces the impact of potential attacks by limiting exposure to individual user credentials rather than a single centralized key.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3647887B1Method and apparatus for the transmission of an access token for access to a field device used in the processing industry
Publication Date: 2022.01.05 VEGA GRIESHABER GMBH & CO
  • EP3647887B1 patent drawingFigure 1A~1C
  • EP3647887B1 patent drawingFigure 2~3
  • EP3647887B1 patent drawingFigure 4~5

AI summary

A method for disseminating access information for accessing a field device (100) of process automation is proposed. The method comprises the steps of defining, on a user's operator panel (10, 10a), at least one access information granted to the user for accessing at least one field device (100) via the operator panel (10, 10a); assigning, on the user's operator panel (10, 10a), another user to the defined at least one access information; and sending an access release that includes information regarding the defined at least one access information and regarding the other user assigned to the defined access information, such that the at least one access information is provided to the other user based on the access release.