Field Device Secure Access via Mobile Unit Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In process automation, there is a need to prevent unauthorized access to field devices while ensuring secure and authorized access for mobile control units, as unauthorized access can disrupt process control or expose sensitive information.

Innovation Solution

The method involves storing an identification code with the comparison data and transmitting it along with access data from the mobile control unit to the field device, allowing secure access by recognizing authorized mobile control units without needing the access code, and enabling access to multiple field devices using shared access codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access codes are transmitted for every access attempt, then security is maintained, but access time and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by storing the identification code of the mobile control unit in the field device during an initial authorized access. This preliminary action creates a trusted relationship, allowing subsequent accesses to be granted quickly by simply matching the stored identification code without requiring full access code verification each time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The field device creates a copy of the mobile control unit's identification code and stores it locally. This copied identification code is then used for rapid comparison during subsequent access attempts, eliminating the need to transmit and verify full access codes repeatedly while maintaining security through the pre-established trusted relationship.

Inventive Principle:
Principle #26Copying

2Reliability

If multiple field devices require individual access codes, then security is maintained, but operational complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile control unit is designed with universal access capability, storing identification codes that can authenticate it to multiple different field devices. Each field device stores the identification code of the mobile control unit, creating a universal authentication mechanism that works across different devices without requiring the operator to manage multiple separate access codes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If access codes are shared across multiple devices, then ease of access is improved, but security control is reduced

Engineering Contradiction:
Improveease of accessVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system replaces the traditional mechanical approach of sharing static access codes with a digital identification code system. Instead of distributing the same access code to multiple devices, each mobile control unit has its own unique identification code that is stored in each field device it needs to access. This substitution enables easy access through automatic identification while maintaining security through unique device-specific authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3130167B1Method for the secure access to a field device
Publication Date: 2020.09.23 KROHNE MESSTECHNICK GMBH & CO KG
  • EP3130167B1 patent drawingFigure 1
  • EP3130167B1 patent drawingFigure 2~5
  • EP3130167B1 patent drawingFigure 6

AI summary

The invention relates to a method for the secure access of a mobile operating unit (1) to a field device (2). The aim of the invention is to provide a method for the secure access of a mobile operating unit to a field device, wherein the field device is protected from an unauthorized access via a mobile operating unit in particular. This is achieved by the aforementioned method in that a connection for transmitting data is established between the mobile operating unit (1) and the field device (2); access data for an access process is transmitted; a comparison is carried out between the access data and stored comparison data, and a comparison result is generated; and the access of the mobile operating unit (1) to the field device (1) is allowed on the basis of the comparison result.