Field Device Security Module with Selective IT Function Activation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing field devices for process automation lack the ability to efficiently implement varying IT security levels, leading to increased device variants, high hardware costs, and unnecessary energy consumption, while existing solutions compromise operating convenience and efficiency.

Innovation Solution

A field device with a security module that includes functional units for multiple IT security levels, allowing a one-time selection and irreversible activation/deactivation of necessary units based on the selected level, ensuring energy efficiency and tailored security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple device variants are provided for different IT security levels, then IT security requirements are met, but device complexity and manufacturing costs increase

Engineering Contradiction:
ImproveIT security levelVSAvoiddevice variants
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The field device is designed with a universal architecture that can operate at multiple IT security levels (SL1-SL4) without requiring separate device variants. The device incorporates functional units that can be selectively activated or deactivated based on the required security level, allowing a single device type to serve multiple security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The device employs dynamic configuration capabilities where functional units can be activated or deactivated based on the selected IT security level. This dynamic adaptation allows the device to adjust its security posture and resource consumption according to the operational requirements, rather than being fixed at a single security level.

Inventive Principle:
Principle #15Dynamics

2Reliability

If highest IT security level is implemented in all devices, then security requirements are met, but energy consumption increases

Engineering Contradiction:
ImproveIT security levelVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The device implements only the security measures necessary for the selected IT security level, rather than always implementing the highest level (SL4). When operating at lower security levels (SL1-SL3), certain security functional units are deactivated, reducing energy consumption while still meeting the required security requirements for that operational context.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The device changes its operational parameters by selectively activating or deactivating functional units based on the selected IT security level. This parameter adjustment allows the device to optimize energy consumption according to the security level, matching resource usage to the actual security requirements of the application scenario.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If IT security level can be changed frequently, then flexibility is improved, but system stability and security consistency deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The device requires the IT security level to be selected and configured in advance during the commissioning phase, before the device enters normal operation. This preliminary configuration ensures that the security level is determined based on a thorough assessment of the application requirements, and prevents frequent changes during operation that could compromise security consistency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device incorporates mechanisms that prevent unauthorized or inappropriate changes to the IT security level after commissioning. By establishing security boundaries and access controls during the preliminary commissioning phase, the system protects against subsequent attempts to downgrade security or make unauthorized changes, thereby maintaining security consistency throughout the device's operational life.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3907569B1Field device with a security module, retrofit module for a field device, method for setting an it security level and computer program code
Publication Date: 2025.07.02 VEGA GRIESHABER GMBH & CO
  • EP3907569B1 patent drawingFigure 1
  • EP3907569B1 patent drawingFigure 2~3
  • EP3907569B1 patent drawingFigure 4

AI summary

The present application relates to a field device for process automation technology with field device electronics having at least one communication interface and a security module with a plurality of functional units for implementing a plurality of predefined IT security levels of different levels, wherein the security module has a selection element for selecting an IT security level, wherein, based on the selection, the functional units necessary for implementing the selected IT security level are activated and/or unnecessary functional units are deactivated.