Field Device Access Sharing Through Centralized Permission Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the process automation and industry, managing access information for multiple field devices across various users and devices becomes complex and inefficient, leading to increased effort and security risks due to the need for manual entry and storage of access details on multiple devices.

Innovation Solution

A method and system that allows users to share and manage access information for field devices through an operating device and a server, enabling users to select, assign, and transmit access permissions to other users, with the server storing and synchronizing access information, thereby simplifying access management and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access information is stored locally on each operating device for all field devices, then users can access field devices independently, but the complexity of managing access information increases significantly with multiple users and devices

Engineering Contradiction:
ImproveIndependent access capabilityVSAvoidAccess information management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the access information management function into a centralized server system. Instead of each operating device storing and managing access information independently, the server consolidates all access information for multiple field devices, allowing multiple users to access through a unified management interface, thereby reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server acts as an intermediary between users and field devices. Rather than direct local storage on each device, the server mediates access information distribution, storing credentials centrally and providing them to authorized users, which simplifies management while maintaining independent access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access information is distributed to multiple operating devices, then users can access field devices from different devices, but security risks increase due to manual entry and storage on multiple devices

Engineering Contradiction:
ImproveMulti-device accessVSAvoidSecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The server serves as a secure intermediary that centralizes access information storage. This eliminates the security vulnerabilities of distributing credentials across multiple devices, as the server can implement centralized security measures including encrypted storage, access logs, and controlled distribution to authorized devices only.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service access management where users can authenticate themselves to the server, which then provides appropriate access information. This automated authentication process reduces manual entry errors and enhances security through consistent verification procedures.

Inventive Principle:
Principle #25Self-service

3Reliability

If each user manages access information for multiple field devices manually, then comprehensive access control is achieved, but the effort and time required increases significantly

Engineering Contradiction:
ImproveAccess controlVSAvoidManagement effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The server merges multiple access control functions into a single centralized system. Instead of users manually managing access information for each field device separately, the consolidated system handles all access control operations through unified interfaces, dramatically reducing the time and effort required while maintaining comprehensive access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server performs preliminary actions by pre-configuring and storing access information for multiple field devices in advance. When users need access, the information is already prepared and can be quickly retrieved and distributed, eliminating the need for manual setup and reducing management effort.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If access information is centralized on a server, then management becomes simplified, but users cannot access field devices without network connection to the server

Engineering Contradiction:
ImproveManagement complexityVSAvoidAccess availability
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by allowing users to download and cache access information from the server to their local operating devices in advance. This enables users to maintain simplified centralized management on the server while also having local copies available for offline access, ensuring continuous availability even without network connection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access information system is segmented into centralized management (server) and local storage (operating devices). The server handles configuration and updates, while local devices store cached credentials for offline use, combining the benefits of simplified management with maintained access availability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11336649B2Method and apparatus for providing access information for an access to a field device for process industry
Publication Date: 2022.05.17 VEGA GRIESHABER GMBH & CO
  • US11336649B2 patent drawing
  • US11336649B2 patent drawing
  • US11336649B2 patent drawing

AI summary

A method for providing access information for access to a field device for process automation is disclosed. The method includes the steps of determining, at a users operating device, at least one access information issued to the user for an access to at least one field device via the operating device, assigning, at the users operating device, a further user to the determined at least one access information, and sending an access permission comprising information relating to the determined at least one access information and to the further user assigned to the determined access information such that the determined at least one access information is provided to the further user based on the access permission.