Field Device Parameter Validation via Data-Diverse Interfaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Safety-critical field devices in automation systems face challenges with insecure communication interfaces during parameterization, leading to potential falsification of parameters and difficulties in validation, especially in environments requiring functional safety like IEC 61508 SIL 3 standards.
Innovation Solution
The method involves using data diversity across logical interfaces for parameter transmission and calculation of test indicators within the field device, ensuring secure remote parameterization by comparing test indicators between the field device and engineering system, with write protection and state machine management to enforce compliance and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If field devices are parameterized through standard communication interfaces (HART, PROFIBUS, FF, PROFINET), then ease of operation is improved, but security against parameter falsification deteriorates
Solution Approach 1:
A secure communication interface is introduced as an intermediary between the engineering system and the field device. This interface acts as a mediator that enables parameterization while ensuring security through encrypted data transmission and authentication mechanisms, thus resolving the contradiction between ease of operation and parameter integrity
Solution Approach 2:
The system implements feedback mechanisms where the field device sends back confirmation signals and status information to the engineering system. This feedback loop allows for verification of parameter integrity and detection of any unauthorized modifications, maintaining reliability while enabling remote parameterization
2Reliability
If visual inspection of parameters is performed on site using the field device display, then reliability of parameter validation is improved, but ease of operation deteriorates due to complex parameter lists and difficult device access
Solution Approach 1:
The parameter list is copied and displayed on the engineering system's user interface alongside the parameterization process. This eliminates the need for physical on-site inspection by allowing operators to view and validate parameters remotely through the engineering system, thus improving ease of operation while maintaining validation reliability
Solution Approach 2:
The manual visual inspection process is replaced by automated comparison functions within the engineering system. The system automatically compares transmitted parameters with the parameter list and validates integrity through cryptographic verification, substituting manual mechanical inspection with automated electronic verification
3Productivity
If multiple users access the same field device simultaneously for commissioning, then productivity is improved, but reliability deteriorates due to competing access and potential conflicts
Solution Approach 1:
The secure communication interface maintains continuous authenticated connections with the field device, establishing persistent secure sessions for multiple users. This allows simultaneous access without breaking the security chain, enabling parallel commissioning activities while maintaining parameter integrity through continuous cryptographic verification
Solution Approach 2:
Access to the field device is segmented into multiple independent secure sessions, each with its own authentication and encryption context. This segmentation allows multiple users to work simultaneously on different aspects of commissioning without interfering with each other, while the field device manages multiple secure connections independently
Data Source
Figure 1~2
Figure 3~4
AI summary
The invention relates to a method for parameterizing a field device (Fx) by means of at least one parameter (SCUP) and to a field device for carrying out the method. For validation, a first checking characteristic (P1) is calculated by the field device (Fx) on the basis of the parameter (SCUP) and a device ID (SN), is stored in a memory (21) of the field device (Fx), and is transferred to an engineering system (4) via a logical interface. In addition, the parameter to be validated and the device ID are transferred to the engineering system (4) via a logical interface that is data-diverse with respect to the aforementioned interface and are output on a display (6) there. In order to confirm correct parameterization, a user can input the read first checking characteristic (P1) at an operating unit (6) of the engineering system (4), which first checking characteristic is then transferred back to the field device (Fx) via the data-diverse interface. The received checking characteristic (P1') is compared with the calculated checking characteristic (P1) by the field device in order to validate the parameter. Thus, a calculation of checking characteristics outside of the field device is advantageously not required and it is ensured that the validation relates to the correct field device.