Automation Configuration Access Control Using Electronic Tags

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The configuration of automation apparatuses in large and distributed industrial sites poses challenges due to technical implementation, usability, and data security complexities, with existing access control methods lacking sophistication for effective management.

Innovation Solution

An access control apparatus with a user interface, communication interfaces, and a processor that uses electronic tags for authentication, enabling secure configuration control of automation apparatuses through a networked service, allowing local and remote user access with defined access rights and period-based permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used for automation apparatus configuration, then implementation is simpler, but data security and usability are insufficient

Engineering Contradiction:
Improvedata securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an access control apparatus as an intermediary between users and the automation apparatus configuration process. This intermediary component manages authentication credentials, validates access rights, and controls configuration operations, thereby enhancing data security without requiring fundamental changes to the underlying automation system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is segmented into distinct functional components: a user interface for credential input, a processor for authentication logic and access right validation, and communication interfaces for interacting with both users and the automation apparatus. This segmentation allows each component to be optimized independently while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If sophisticated access control is implemented, then data security improves, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidconfiguration usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access control apparatus automatically performs authentication verification and access right validation without requiring manual intervention from administrators. The system self-manages credential verification, determines appropriate access levels, and enforces configuration restrictions, thereby maintaining security while reducing operational burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access credentials and access rights are configured and validated in advance before configuration operations are performed. The system pre-establishes authentication mechanisms and defines permitted operations, so that when users attempt configuration tasks, the security checks are already in place and do not impede the workflow.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If period-based access rights are implemented, then control precision improves, but device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidpermission management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The access control system dynamically adjusts permissions based on time periods and operational contexts. Access rights are not static but change according to predefined time windows, user roles, and configuration stages, allowing precise control over when and how users can perform operations without requiring complex manual permission management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system controls access precision by changing parameters such as time periods, user roles, and operation types. By varying these parameters, the system can grant or restrict access to specific configuration functions at specific times, achieving fine-grained control through parameter management rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3734479B1Access control apparatus and method for controlling configuration of automation apparatus
Publication Date: 2022.10.19 ABB (SCHWEIZ) AG
  • EP3734479B1 patent drawingFigure 1
  • EP3734479B1 patent drawingFigure 2
  • EP3734479B1 patent drawingFigure 3

AI summary

An access control apparatus and method for controlling a configuration of an automation apparatus. The method includes: reading (202) authentication information from an electronic tag; transmitting (204) the authentication information to a networked service; receiving (206) access rights from the networked service; and controlling (208) the configuration of the automation apparatus according to the access rights.