Segment Access Verification Across Distributed Field Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed systems, the need for individual access codes for each field device in a process plant poses a security hurdle and complicates access management.

Innovation Solution

A verification apparatus and method that allows access data verification across multiple field devices within a segment, enabling secure and simplified access by checking the correctness of access data for all devices in the segment, with a security server providing centralized access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual access codes are assigned to each field device, then security level is improved, but access complexity and time required for operation increases

Engineering Contradiction:
Improvesecurity levelVSAvoidaccess complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments field devices into groups called segments. Each segment is assigned a segment access code that provides access to all field devices within that segment. This segmentation approach maintains security by requiring access codes while simplifying operation by allowing one code to access multiple devices rather than requiring individual codes for each device.

Inventive Principle:
Principle #1Segmentation

2Reliability

If individual access codes are assigned to each field device, then security level is improved, but time required for access increases

Engineering Contradiction:
Improvesecurity levelVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By organizing field devices into segments and assigning one access code per segment, the time required for access is significantly reduced. Instead of entering individual access codes for multiple devices, a user enters a single segment access code to access all devices in that segment, thereby reducing access time while maintaining security through the segment verification process.

Inventive Principle:
Principle #1Segmentation

3Reliability

If access verification is performed by all field devices in a segment, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces a segment verification mechanism that acts as an intermediary between the access code and individual field devices. When access is requested, the segment verification process checks the access code against the segment's authorized codes. This intermediary approach maintains security through verification while reducing system complexity by avoiding the need for complex individual device verification for each access attempt.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12407690B2Apparatus for protecting access to segments in distributed systems
Publication Date: 2025.09.02 VEGA GRIESHABER GMBH & CO
  • US12407690B2 patent drawing
  • US12407690B2 patent drawing
  • US12407690B2 patent drawing

AI summary

An apparatus for protecting access to a segment in distributed systems is provided, the apparatus including: an input device configured to acquire access data for a first field device; and a verification device configured to verify the acquired access data from a second field device, the first field device and the second field device being coupled to the segment. A computer network segment comprising at least two apparatuses, a method of protecting access to a segment in distributed systems, and a nontransitory computer-readable storage medium are also provided.