Field Device Authentication via Access Codes and Server Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field devices in automation technology lack secure communication mechanisms to prevent illicit access via end device communication interfaces, especially in large-scale industrial systems where numerous field devices and end devices interact, posing risks to operational safety and security.
Innovation Solution
Implementing an authentication system where an individual access code is stored in the end device and transmitted to an authentication server for verification, ensuring only authorized end devices can access field device resources, with cryptographic means for secure data exchange and scope of rights management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If an end device communication interface is added to enable modern communication technologies and higher transmission rates, then communication capability and transmission rate are improved, but security risk and vulnerability to illicit access increase
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the end device and field device. The authentication server verifies access codes and manages authentication, preventing direct unauthorized access to the field device while enabling modern communication interfaces. This mediator resolves the contradiction by allowing high-speed communication infrastructure while maintaining security through centralized authentication control.
Solution Approach 2:
The patent implements preliminary authentication before allowing communication access. The end device must present an access code that is verified by the authentication server before the field device will communicate. This preliminary security check prevents illicit access while allowing the modern communication interface to function at high speeds for authorized devices.
2Reliability
If access control mechanisms are implemented to prevent illicit access, then security is improved, but device complexity and system overhead increase
Solution Approach 1:
The patent extracts the authentication functionality from the field device itself and places it in a separate authentication server. The field device only needs to communicate access codes and receive authentication results, while the complex authentication logic and access code management reside in the external authentication server. This extraction reduces the complexity burden on individual field devices while maintaining strong security.
Solution Approach 2:
The authentication server provides universal authentication services to multiple field devices and end devices. Instead of each field device having its own authentication mechanism, a single multi-functional authentication server handles security for the entire system, reducing overall complexity while maintaining comprehensive security coverage.
3Reliability
If authentication systems are deployed across large-scale industrial systems with numerous field devices, then security coverage is improved, but implementation complexity and management overhead increase
Solution Approach 1:
The authentication server is designed to handle multiple field devices and end devices universally. It manages access codes for numerous devices through a single centralized system, providing broad security coverage across large-scale industrial systems without requiring separate authentication implementations for each device. This universality scales efficiently to handle large numbers of devices.
Solution Approach 2:
The authentication system enables automated authentication processes where end devices present access codes and receive verification results without manual intervention. The authentication server automatically manages access code verification and communicates authentication results to field devices, reducing the need for manual security management despite the large scale of the system.
Data Source
AI summary
A method for secure communication between a field device and an end device is disclosed. The method includes: storing an individual access code in the end device, transmitting an access code of the end device to the field device, connecting the field device to an authentication server via a server communication link, using the field device to transmit the access code or an access code derived from the access code to the authentication server, storing authentication data on the authentication server, checking the authenticity of the access code on the authentication server using the authentication data, transmitting the resulting authentication result from the authentication server via the server communication link to the field device, and, depending on the authentication result transmitted to the field device, making resources of the field device available to the end device.


