Field Device Security Setting Checks for Unauthorized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of field devices in industrial settings face challenges in setting and maintaining the required security levels to prevent unauthorized access, as they lack the necessary knowledge and expertise, leading to potential cyber threats and operational disruptions.

Innovation Solution

A method that determines the required security level, authenticates the user, queries and compares the actual security settings with the target settings, and provides an electronic report with suggestions for adjustment, allowing users to easily align settings with the stipulated security levels without requiring special knowledge.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multiple communication interfaces and functions are added to field devices to improve flexibility and user access, then ease of operation is improved, but device complexity and vulnerability to cyber attacks increase

Engineering Contradiction:
Improveuser access flexibilityVSAvoidcommunication interface complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments security management into predefined security functions that can be independently configured and checked. Each security function (access control, authentication, encryption) is separated and can be individually verified against target settings, allowing complex security configurations to be managed through modular, checkable units rather than as a monolithic system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary checking mechanism that mediates between the user and the complex security settings. This intermediary automatically compares actual security function settings with target settings defined by security levels, shielding users from the complexity of direct security configuration while ensuring proper security posture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security functions are made more accessible and easier to configure, then ease of operation is improved, but the risk of incorrect settings and security vulnerabilities increases

Engineering Contradiction:
Improvesecurity configuration easeVSAvoidsecurity setting accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the actual settings of security functions are automatically compared with target settings defined by required security levels. This feedback loop provides users with immediate information about whether their configurations meet security requirements, allowing them to correct deviations and ensure proper security posture without needing expert knowledge

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes target settings for security functions in advance based on defined security levels. These preliminary target configurations serve as reference points against which actual settings are compared, guiding users toward correct security configurations before potential security incidents occur

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11774953B2Method for checking the setting of predefined security functions of a field device in process and automation engineering
Publication Date: 2023.10.03 ENDRESS & HAUSER GMBH & CO KG
  • US11774953B2 patent drawing

AI summary

Disclosed is a method for checking the setting of predefined security functions of a field device of process and automation technology, wherein the predefined security functions relate to an access to a function of the field device by an unauthorized person. The method includes: identifying a user; starting by the user a query about the actual setting of the security functions predefined at the measuring point; comparing actual setting of the predefined security functions with a target setting of the predefined security functions defined by the stipulated security level; and outputting an electronic report about the matching or deviation of the actual setting from the target setting of the predefined security functions. Depending on the matching or deviation of the actual setting from the target setting of the predefined security functions, different steps are carried out.