Field Measuring Device Web Server Access with Dual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field measuring devices in process measurement technology face challenges in securing communication through external interfaces, as existing solutions like Captcha functionality are difficult to implement and do not effectively prevent unauthorized access.
Innovation Solution
Implementing a dual authenticity check system that verifies access authorization regardless of whether the external communication means is human or machine, using a combination of individual, material, and biometric identification categories, and employing time-limited or one-time identification methods to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Captcha functionality is implemented to distinguish human from machine access, then some level of access control is achieved, but the functionality cannot be effectively implemented due to limited hardware resources and does not prevent unauthorized access
Solution Approach 1:
The authentication process is divided into multiple sequential challenges (first challenge, second challenge, etc.) rather than attempting to implement a single complex Captcha system. Each challenge can be independently configured with appropriate difficulty levels and resource requirements, making the overall system manageable within limited hardware constraints while maintaining security effectiveness
Solution Approach 2:
The system performs preliminary authentication challenges before granting full access to the field measuring device. By requiring users to complete multiple verification steps in advance (such as solving puzzles or providing specific information), the system establishes security barriers beforehand, preventing unauthorized access before it can occur rather than attempting to detect and block it after penetration
2Ease of operation
If a web server with external communication interface is added to enable modern communication, then easier access and higher transmission rates are achieved, but access security is compromised due to uncontrollable external access
Solution Approach 1:
The system applies preliminary counter-measures by implementing multiple authentication challenges and security verification steps before allowing any external access to the web server. This preemptive approach blocks potential unauthorized access attempts before they can reach critical functions, thereby maintaining security while preserving the ease of legitimate access through the modern communication interface
Solution Approach 2:
The authentication challenge system acts as an intermediary layer between the external communication interface and the field measuring device's internal functions. This mediator verifies and controls all access requests, allowing legitimate users to proceed while blocking unauthorized access, thus reconciling the need for easy external access with the requirement for strong security protection
3Reliability
If multiple authenticity checks are implemented to enhance security, then access security is significantly improved, but the complexity of the authentication system increases
Solution Approach 1:
The authentication system is segmented into multiple independent challenges that can be configured with varying levels of complexity. Each challenge represents a discrete security checkpoint that can be individually managed and adjusted based on security requirements and resource availability, making the overall multi-check system more manageable than a single monolithic authentication mechanism
Solution Approach 2:
The system implements authentication challenges with varying degrees of strictness - some challenges may be relatively simple while others are more demanding. This partial action approach allows the system to achieve enhanced security through multiple checks without requiring every single challenge to be maximally complex, thereby balancing security improvement with acceptable system complexity
Data Source
Figure 1
Figure 2
Figure 3a~3b
AI summary
Described and illustrated is a method (2) for secure communication with a field measuring device (1) of process measurement technology, wherein the field measuring device (1) has a sensor (3), an evaluation unit (4), a fieldbus interface (20) for transmitting the measurement data acquired and provided by the field measuring device (1) to other bus participants (22, 23) and/or to a process control system (24) and a communication unit (5) with a communication interface (6), wherein a web server (7) is implemented on the communication unit (5), wherein the web server (7) can be accessed externally via the communication interface (6) and a corresponding field measuring device (1).Misuse of the field measuring device via the communication interface (6) with a web server (7) is prevented with a high degree of security by the fact that, when contact (100) is made by an external communication means (8) with the web server (7) via the communication interface (6), the field measuring device (1) performs a first authentication check (101) of the external communication means (8) and a second authentication check (102) of the external communication means (8), and after successful completion (103) of the first authentication check (101) and the second authentication check (102), the field measuring device (1) authorizes (105) further communication (104) with the external communication means (8) with the web server (7).