Field Device Security Settings Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for transferring security settings between field devices in automation technology require manual installation and definition of operator accounts and authorization groups, which is time-consuming and insecure, as sensitive security settings cannot be easily transmitted between devices.
Innovation Solution
A method for securely transmitting security settings between field devices by authenticating operators, assigning authorization groups, encrypting sensitive data, and decrypting it for import into the target device, with administrator authorization ensuring secure export and decryption processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security settings are manually installed and defined at each field device, then security is maintained, but time consumption and labor effort increase significantly
Solution Approach 1:
The patent enables copying of security settings from a first field device to a second field device through automated transmission. The security settings including operator accounts and authorization groups are exported from the source device and imported to the target device, eliminating manual installation while maintaining security integrity through cryptographic protection.
Solution Approach 2:
The patent performs preliminary authentication and authorization checks before transmitting security settings. The system verifies operator credentials and authorization levels in advance, ensuring that only authorized administrators can export and import security settings, thus maintaining security while automating the process.
2Productivity
If security settings are transmitted between field devices, then configuration efficiency improves, but security risks increase due to potential unauthorized access
Solution Approach 1:
The patent implements different security measures for different authorization levels. Administrator authorization triggers encryption with administrator password, while service authorization uses service password. This differentiated approach ensures appropriate security protection for each transmission scenario while enabling efficient automated configuration.
Solution Approach 2:
The patent introduces cryptographic mechanisms as intermediaries to protect security settings during transmission. Encryption algorithms and cryptographic protocols act as mediators between the source and target devices, ensuring that security settings are transmitted efficiently while maintaining security through protected communication channels.
3Ease of operation
If automated transmission of security settings is implemented, then manual labor is reduced, but system complexity increases due to encryption and authentication requirements
Solution Approach 1:
The patent enables the field devices to perform authentication and encryption operations autonomously. The devices automatically verify operator credentials, determine authorization levels, apply appropriate encryption, and manage the transmission process without requiring external intervention, thus reducing manual labor while managing complexity through self-contained security mechanisms.
Data Source
AI summary
A method for transmitting security settings between a first automation engineering field device and a second automation engineering field device includes: identifying and authenticating an operator by means of a service unit; assigning an authorization group based on the identifying and authenticating of the operator; in the case, in which the operator is assigned the administrator authorization group: encrypting at least one security setting, which is present in cleartext, by the first field device; exporting the encrypted security setting; importing the encrypted security setting into the second field device; decrypting the encrypted security setting; loading the decrypted security setting into the data memory of the second field device and operating the second field device with the loaded security setting of the first field device.
