Field Device Order Ticket Authorization via M2M Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current practices in industrial automation often grant permanent access rights to field devices, leading to unnecessary risks of unauthorized changes and lack of transparency in device status, especially since high authorizations are frequently granted even for tasks that only require lower-level permissions.

Innovation Solution

A method utilizing machine-to-machine communication to create and manage order tickets that contain authorization for specific tasks on field devices, with temporal validity, ensuring that only necessary permissions are granted for the duration of the task.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If permanent access rights are granted to field devices, then ease of operation is improved, but security and reliability deteriorate due to unnecessary risks of unauthorized changes

Engineering Contradiction:
Improveaccess to field deviceVSAvoidsecurity against unauthorized changes
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access rights that automatically expire after a predetermined period. The authorization is not static but changes over time, transitioning from active to expired state, thereby providing both ease of operation during the valid period and security after expiration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the temporal parameter of access authorization by introducing a validity period. The access rights are granted for a specific duration and automatically revoke after that time, transforming the permanent access model into a time-limited one that balances usability and security.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If high authorizations are granted for tasks, then adaptability is improved, but security deteriorates due to excessive permissions beyond task requirements

Engineering Contradiction:
Improveauthorization scopeVSAvoidrisk of unauthorized changes
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies partial action by granting only the specific authorization needed for a particular task rather than comprehensive high-level permissions. The access rights are tailored to the minimum necessary scope, avoiding excessive permissions while maintaining task adaptability.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If access rights are permanently granted, then ease of operation is improved, but transparency deteriorates due to lack of visibility on device status

Engineering Contradiction:
Improvecontinuous accessVSAvoidtransparency of device status
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements periodic authorization renewal by requiring new order tickets for each task period. This creates natural checkpoints where access is re-evaluated, maintaining transparency about device status and current authorized operations while preserving ease of operation within each valid period.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250139222A1Method and system for operating an automation technology field device via machine-to-machine communication between an operating unit and the field device
Publication Date: 2025.05.01 ENDRESS HAUSER CONDUCTA GMBH CO KG
  • US20250139222A1 patent drawing

AI summary

A method for operating a field device between an operating unit and the field device includes creating an order ticket using a ticket server. The order ticket contains an authorization for the operating unit to carry out defined tasks on the field device and information on the temporal validity. The method also includes transferring the order ticket to an operating unit and to the field device. The operating unit is registered with the field device if the field device verifies the order ticket is valid. If the order ticket is successfully verified, execution of the tasks defined in the order ticket on the field device is authorized for a predetermined period of time, which has an end point that is determined by the information on time validity contained in the order ticket. The authorization is automatically terminated by the field device after the predetermined period of time has elapsed.