Field Measuring Device Web Server Access with Dual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field measuring devices in process measurement technology face challenges in securing communication through external interfaces, as existing solutions like Captcha functionality are difficult to implement and do not effectively prevent unauthorized access.

Innovation Solution

Implementing a dual authenticity check system that verifies access authorization regardless of whether the external communication means is human or machine, using a combination of individual, material, and biometric identification categories, and employing time-limited or one-time identification methods to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Captcha functionality is implemented to distinguish human from machine access, then some level of access control is achieved, but the functionality cannot be effectively implemented due to limited hardware resources and does not prevent unauthorized access

Engineering Contradiction:
Improveaccess securityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is divided into multiple sequential challenges (first challenge, second challenge, etc.) rather than attempting to implement a single complex Captcha system. Each challenge can be independently configured with appropriate difficulty levels and resource requirements, making the overall system manageable within limited hardware constraints while maintaining security effectiveness

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication challenges before granting full access to the field measuring device. By requiring users to complete multiple verification steps in advance (such as solving puzzles or providing specific information), the system establishes security barriers beforehand, preventing unauthorized access before it can occur rather than attempting to detect and block it after penetration

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If a web server with external communication interface is added to enable modern communication, then easier access and higher transmission rates are achieved, but access security is compromised due to uncontrollable external access

Engineering Contradiction:
Improveaccess easeVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies preliminary counter-measures by implementing multiple authentication challenges and security verification steps before allowing any external access to the web server. This preemptive approach blocks potential unauthorized access attempts before they can reach critical functions, thereby maintaining security while preserving the ease of legitimate access through the modern communication interface

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The authentication challenge system acts as an intermediary layer between the external communication interface and the field measuring device's internal functions. This mediator verifies and controls all access requests, allowing legitimate users to proceed while blocking unauthorized access, thus reconciling the need for easy external access with the requirement for strong security protection

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple authenticity checks are implemented to enhance security, then access security is significantly improved, but the complexity of the authentication system increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent challenges that can be configured with varying levels of complexity. Each challenge represents a discrete security checkpoint that can be individually managed and adjusted based on security requirements and resource availability, making the overall multi-check system more manageable than a single monolithic authentication mechanism

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements authentication challenges with varying degrees of strictness - some challenges may be relatively simple while others are more demanding. This partial action approach allows the system to achieve enhanced security through multiple checks without requiring every single challenge to be maximally complex, thereby balancing security improvement with acceptable system complexity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3410241B1Method for secure communications with a field measuring device used for process technology and corresponding field measuring instrument
Publication Date: 2023.10.25 KROHNE MESSTECHNICK GMBH & CO KG
  • EP3410241B1 patent drawingFigure 1
  • EP3410241B1 patent drawingFigure 2
  • EP3410241B1 patent drawingFigure 3a~3b

AI summary

Described and illustrated is a method (2) for secure communication with a field measuring device (1) of process measurement technology, wherein the field measuring device (1) has a sensor (3), an evaluation unit (4), a fieldbus interface (20) for transmitting the measurement data acquired and provided by the field measuring device (1) to other bus participants (22, 23) and/or to a process control system (24) and a communication unit (5) with a communication interface (6), wherein a web server (7) is implemented on the communication unit (5), wherein the web server (7) can be accessed externally via the communication interface (6) and a corresponding field measuring device (1).Misuse of the field measuring device via the communication interface (6) with a web server (7) is prevented with a high degree of security by the fact that, when contact (100) is made by an external communication means (8) with the web server (7) via the communication interface (6), the field measuring device (1) performs a first authentication check (101) of the external communication means (8) and a second authentication check (102) of the external communication means (8), and after successful completion (103) of the first authentication check (101) and the second authentication check (102), the field measuring device (1) authorizes (105) further communication (104) with the external communication means (8) with the web server (7).