Two-Factor Authentication UI Device for Process Plant Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In process control systems, there is a lack of effective authentication and authorization mechanisms for users accessing plant assets, allowing unauthorized personnel to modify or control critical equipment within a process plant.

Innovation Solution

Implementing a UI device that performs two-factor authentication using RFID tags or NFC signals for physical identification and user login information, such as usernames and passwords, to verify user identity and determine authorization levels, ensuring only authorized users can access and operate plant assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication is implemented using RFID tags and user login information, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication mechanism is segmented into two distinct factors: (1) possession factor using RFID tags or NFC signals for physical identification, and (2) knowledge factor using user login information such as usernames and passwords. This segmentation allows each factor to be independently implemented and verified, enhancing security while maintaining manageable complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The UI device acts as an intermediary that receives and verifies both the RFID/NFC signal from the identification device and the user login information. This intermediary role enables the system to enforce two-factor authentication without requiring direct complex interactions between the identification device and the process control device, thereby improving security while managing complexity through the UI device's mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authorization levels are assigned to control access to different plant assets, then system security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidaccess control operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Authorization levels are assigned to users and UI devices in advance before they attempt to access plant assets. The server device pre-configures which users have access to which assets based on their roles and responsibilities. This preliminary action eliminates the need for complex real-time authorization decisions during operation, thereby maintaining high security while preserving ease of operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically determines authorization levels by comparing the user's assigned permissions with the required access rights for each plant asset. This self-service mechanism eliminates the need for manual authorization checks or complex user interventions, allowing the system to enforce security policies automatically while maintaining simple and intuitive operation for users

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by preventing unauthorized access to process control devices and plant assets, allowing only authenticated and authorized personnel to perform operations, thus maintaining the integrity and safety of the process plant operations.

Implementation Method 1

The UI device may receive a Radio Frequency Identification (RFID) tag, such as a near field communications (NFC) signal, from an electronic ID card which belongs to the user

Methodology Applied
Scientific EffectRFID (Radio Frequency Identification): Electromagnetic Induction

Implementation Method 2

The UI device may receive a Radio Frequency Identification (RFID) tag, such as a near field communications (NFC) signal, from an electronic ID card which belongs to the user

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Data Source

PatentUS9805528B1Authentication and authorization to control access to process control devices in a process plant
Publication Date: 2017.10.31 FISHER ROSEMOUNT SYST INC
  • US9805528B1 patent drawing
  • US9805528B1 patent drawing
  • US9805528B1 patent drawing

AI summary

Techniques for controlling plant assets in a process plant include assigning permissions to users and user interface devices within the process plant, where the permissions specify a level of access to a plant asset. The permissions are then provided to the user interface devices. When a user connects a user interface device to a plant asset, the user interface device determines which operations the user may perform on the connected plant asset based on the permissions granted to the user.