Biometric Two-User Validation for Process Control Write Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing process control systems are vulnerable to security breaches due to laxness or sabotage, as standard username and password credentials can be easily guessed or hacked, and two-user verification systems may be prone to redundancy and password sharing, especially when relying on network directory services that do not capture direct user relationships.

Innovation Solution

A process control system that intercepts write commands for validation, using biometric inputs and user profiles to establish relationships between users, where a second user must biometrically authenticate to validate a write command initiated by a first user, ensuring that only authorized users with valid relationships can execute changes on process control devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard username and password credentials are used for authentication, then ease of operation is improved, but security is worsened due to susceptibility to guessing and hacking

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with biometric authentication (fingerprint, iris, facial recognition). This substitution eliminates the vulnerability of password guessing and hacking while maintaining ease of operation, as biometric authentication requires no memorization and is performed automatically through sensors.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a relationship validation intermediary that checks the connection between the first user (initiator) and second user (verifier). This intermediary layer prevents credential sharing abuse by ensuring that only legitimately related users can validate each other's commands, adding security without complicating the authentication process for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a second user verification system is implemented, then security is improved, but device complexity is worsened due to additional validation steps

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity of validation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex password-based second verification with biometric authentication. The biometric system automatically captures and verifies user identity through sensors, eliminating the need for manual password entry and reducing the perceived complexity for users while maintaining strong security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system automatically manages the relationship validation between users. Once relationships are established in the database, the system self-service checks these relationships during validation without requiring manual configuration or complex user actions, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Productivity

If credential sharing is allowed to expedite change requests, then productivity is improved, but security is worsened due to inability to track actual user identity

Engineering Contradiction:
Improvespeed of change requestsVSAvoiduser identification accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces credential-based identification with biometric identification. Since biometric data is inherently tied to the physical user and cannot be shared, this substitution maintains user identification accuracy while still allowing multiple users to perform change requests efficiently through their own biometric authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The relationship validation intermediary enables authorized users to validate commands from related users without sharing credentials. The intermediary checks the relationship database to verify that the validating user is legitimately connected to the initiating user, allowing expedited processing while maintaining security and tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11658966B2Personnel profiles and fingerprint authentication for configuration engineering and runtime applications
Publication Date: 2023.05.23 FISHER ROSEMOUNT SYST INC
  • US11658966B2 patent drawing
  • US11658966B2 patent drawing
  • US11658966B2 patent drawing

AI summary

A system for validating a write command to a device in a process control system using biometric credentials and relationship attributes. A two user validation process may use biometric inputs of the two users to authenticate the two users and to query for associated profiles to determine whether the two users have a relationship required to release an intercepted write command to the device.