Field Device User Registration via Mobile Credential Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The administration of field devices, particularly in industrial installations, faces challenges with simple access data to avoid registration complications and the difficulty in implementing and managing complex, unique passwords, especially in older devices that lack modern access systems.
Innovation Solution
A method for automatically registering users on field devices using a security device that provides user information to a mobile device, which generates field-device-specific registration information for seamless, secure access without manual input, utilizing local communication and cryptographic methods to ensure security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If simple access data are used for field device administration, then the registration process becomes easier and less complicated, but security is reduced
Solution Approach 1:
The system segments the authentication process into two parts: a simple user-facing interface for easy registration, and a separate secure credential management system that handles complex password generation and distribution. The mobile device acts as an intermediary that receives simple user input and automatically retrieves/inputs complex credentials from the field device, thus segmenting the security complexity from the user interaction.
Solution Approach 2:
The mobile device serves as an intermediary between the user and the field device. It receives user information, retrieves complex passwords from the field device's memory, and automatically inputs them for registration. This intermediary approach allows simple user interaction while maintaining high security through automated credential management.
2Reliability
If unique and complex passwords are used for different field devices, then security is increased, but manual input becomes time-consuming and error-prone
Solution Approach 1:
The system implements self-service automation where the mobile device automatically retrieves complex passwords from the field device's memory and inputs them without requiring manual user interaction. The field device provides its own credentials through its communication interface, enabling automatic registration that is both secure and time-efficient.
Solution Approach 2:
The manual mechanical process of typing passwords is replaced with an automated electronic system. The mobile device uses the field device's communication interface (USB, Bluetooth, NFC, or wireless) to automatically retrieve and input credentials, substituting the manual typing process with automated electronic credential exchange.
3Reliability
If complex passwords are implemented in older field devices, then security is improved, but compatibility and ease of implementation become difficult
Solution Approach 1:
The system achieves universality by supporting multiple communication protocols and interfaces (USB, Bluetooth, NFC, wireless connections) to accommodate different field device types and ages. The mobile device can adapt to various field device interfaces and automatically retrieve credentials through the appropriate communication channel, making the solution compatible across diverse devices.
Solution Approach 2:
The system changes the parameter of credential delivery from manual entry to automated electronic transmission. By modifying how credentials are delivered (through communication interfaces rather than manual input), the system can implement complex passwords in older devices that may not have modern authentication interfaces, as long as they have basic communication capabilities.
Data Source
AI summary
Provided is a method for automatically registering a user on a field device for the purpose of administering the field device, including a) providing user information on the basis of an identity of the user and an identity of the field device by a security device; b) transmitting the provided user information to a mobile device of the user; c) generating field-device-specific registration information on the basis of the transmitted user information by the mobile device; and d) registering the user on the field device by the generated registration information. This method has the particular advantage that a highly secure infrastructure can be used for administering access information for administering the field devices without problems arising during the registration process.

