Segment Access Verification Across Distributed Field Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed systems, the need for individual access codes for each field device in a process plant poses a security hurdle and complicates access management.
Innovation Solution
A verification apparatus and method that allows access data verification across multiple field devices within a segment, enabling secure and simplified access by checking the correctness of access data for all devices in the segment, with a security server providing centralized access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual access codes are assigned to each field device, then security level is improved, but access complexity and time required for operation increases
Solution Approach 1:
The system segments field devices into groups called segments. Each segment is assigned a segment access code that provides access to all field devices within that segment. This segmentation approach maintains security by requiring access codes while simplifying operation by allowing one code to access multiple devices rather than requiring individual codes for each device.
2Reliability
If individual access codes are assigned to each field device, then security level is improved, but time required for access increases
Solution Approach 1:
By organizing field devices into segments and assigning one access code per segment, the time required for access is significantly reduced. Instead of entering individual access codes for multiple devices, a user enters a single segment access code to access all devices in that segment, thereby reducing access time while maintaining security through the segment verification process.
3Reliability
If access verification is performed by all field devices in a segment, then security is improved, but system complexity increases
Solution Approach 1:
The system introduces a segment verification mechanism that acts as an intermediary between the access code and individual field devices. When access is requested, the segment verification process checks the access code against the segment's authorized codes. This intermediary approach maintains security through verification while reducing system complexity by avoiding the need for complex individual device verification for each access attempt.
Data Source
AI summary
An apparatus for protecting access to a segment in distributed systems is provided, the apparatus including: an input device configured to acquire access data for a first field device; and a verification device configured to verify the acquired access data from a second field device, the first field device and the second field device being coupled to the segment. A computer network segment comprising at least two apparatuses, a method of protecting access to a segment in distributed systems, and a nontransitory computer-readable storage medium are also provided.


