Field Device Login via Mobile-Generated Secure Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for logging into field devices, particularly in industrial systems, face challenges with simple access data security, manual entry of complex passwords, and integration into automated systems, especially in older devices.

Innovation Solution

A method involving a security device that provides user information to a mobile device, which generates device-specific login information for seamless access to field devices, using cryptographic methods and local communication to ensure secure, automated login without manual entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique and complex passwords are used for different field devices, then security is improved, but ease of operation deteriorates due to time-consuming manual entry and input errors

Engineering Contradiction:
ImprovesecurityVSAvoidease of login
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication where the field device automatically retrieves user information from the security device and performs cryptographic verification without requiring manual password entry by the user. The device autonomously completes the login process by establishing secure communication channels and exchanging cryptographic tokens.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security device acts as an intermediary between the user and the field device. Instead of the user directly providing passwords to the field device, the security device mediates the authentication process by storing user information, receiving authentication requests, and providing verified credentials to the field device through secure communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual entry of complex passwords is required, then security is improved, but productivity deteriorates due to time-consuming login processes

Engineering Contradiction:
ImprovesecurityVSAvoidlogin speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

User information is pre-stored in the security device in encrypted form before authentication is needed. When a user needs to access a field device, the preliminary prepared cryptographic credentials are quickly retrieved and exchanged without requiring real-time password generation or manual entry, thus maintaining high security while enabling fast authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The manual mechanical process of typing passwords is replaced with automated electronic cryptographic verification. The system substitutes the manual entry mechanism with automated secure communication protocols, cryptographic token exchange, and automated credential verification between devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If centralized security systems are implemented, then security management is improved, but adaptability deteriorates for older field devices that cannot integrate into automated systems

Engineering Contradiction:
Improvesecurity managementVSAvoidcompatibility with older devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security device is designed with universal communication capabilities that can interface with both modern automated systems and older field devices. It provides multiple authentication methods including cryptographic token exchange for automated systems and alternative verification mechanisms for legacy devices, enabling a single security infrastructure to serve diverse device types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system can dynamically change authentication parameters and communication protocols based on the capabilities of the connected field device. For older devices that cannot support modern cryptographic protocols, the security device adjusts the authentication parameters to use compatible verification methods while maintaining centralized security management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3798754B1Method for automatically logging in a user to a field device and an automation system
Publication Date: 2025.07.23 SIEMENS SCHWEIZ AG
  • EP3798754B1 patent drawingFigure 1~2
  • EP3798754B1 patent drawingFigure 3~4

AI summary

A method for automatically logging a user into a field device for managing the field device, comprising: a) providing user information based on the identity of the user and the identity of the field device via a security device; b) transmitting the provided user information to the user's mobile device; c) generating field-device-specific credentials based on the transmitted user information via the mobile device; and d) logging the user into the field device using the generated credentials. This method has the particular advantage that a highly secure infrastructure for managing access information for field devices can be used without any issues arising during the login process.In particular, manual entry of complex and long passwords often leads to input errors, which is avoided here because a seamless chain from the security device to the login on the field device is provided.