Field Device Interface Security Synchronization Against Unauthorized Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field devices in industrial communication networks face challenges in ensuring uniform security function activation across communication interfaces, leading to potential unauthorized access and misinterpretation of information due to inconsistent security settings.

Innovation Solution

A method that detects and synchronizes security features across all communication interfaces in a communication network, ensuring that either all security functions are activated uniformly or none are activated, thereby preventing unauthorized access by reconfiguring interfaces to maintain consistent security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security functions are activated on individual communication interfaces independently, then each interface can be secured according to its specific requirements, but inconsistent security settings lead to unauthorized access and misinterpretation of information

Engineering Contradiction:
Improvesecurity consistencyVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security configuration of multiple communication interfaces into a unified security concept at the field device level. The security manager centrally manages security settings and applies them consistently across all communication interfaces (KS1, KS2, etc.), ensuring that security functions are activated uniformly throughout the device rather than being configured independently at each interface level.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security concept that can be applied across different communication interfaces with varying security requirements. The unified security manager provides multi-functional security management, adapting a single security configuration framework to work across multiple interfaces while maintaining consistency, thus resolving the contradiction between individual interface security needs and overall security consistency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If different security functions are activated on different communication interfaces, then each interface can be optimized for its specific security needs, but information may be misinterpreted by receiving interfaces that have different security settings

Engineering Contradiction:
Improveinformation integrityVSAvoidsecurity function flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines security management into a unified system where the security manager ensures that the same security functions are activated on all communication interfaces that exchange information. This merging approach guarantees that information sent from one interface with specific security functions will be correctly received and interpreted by another interface with identical security settings, thus maintaining information integrity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies homogeneity by ensuring that security settings are uniform across all communication interfaces within the field device. The unified security concept enforces consistent security function activation, so that interfaces communicating with each other have matching security configurations, preventing misinterpretation of information while maintaining appropriate security levels.

Inventive Principle:
Principle #33Homogeneity

3Reliability

If security functions are activated on communication interfaces, then unauthorized access is prevented, but the configuration and maintenance of security settings becomes more complex

Engineering Contradiction:
Improveaccess securityVSAvoidsecurity configuration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service through the unified security manager, which automatically manages security configurations across all communication interfaces. The system can automatically detect, configure, and maintain consistent security settings without requiring manual intervention at each interface level, thereby simplifying operation while maintaining robust security. The security manager handles the complexity internally while presenting a simplified interface to users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The unified security manager acts as an intermediary between the user and the multiple communication interfaces. Instead of requiring users to configure security settings on each interface individually, the security manager mediates the configuration process, applying security settings centrally and ensuring consistency across all interfaces, thus making security configuration easier while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3469429B1Method for preventing an unauthorised access to software applications in field devices, and communication network
Publication Date: 2021.03.31 ENDRESS HAUSER PROCESS SOLUTIONS AG
  • EP3469429B1 patent drawingFigure 1
  • EP3469429B1 patent drawingFigure 2

AI summary

The invention relates to a method and a communications network for preventing an unauthorised access to software applications (SF1, SF2, SF3, SF4, SG) implemented in field devices (F1, F2, F3, F4, G), wherein the field devices (F1, F2, F3, F4, G) are integrated in a communications network (KN, KN') of automation technology, and wherein every software application (SF1, SF2, SF3, SF4, SG) exchanges information within the communications network (KN, KN') via a respective at least one communications interface (KS, KS'), comprising the following steps: detecting current activated security functions, based on security and/or functional characteristics, of every communications interface (KS, KS') of the software applications(SF1, SF2, SF3, SF4, SG); detecting all activateable security functions of every communications interface (KS, KS'); determining at least one common security function that can be activated at every communications interface (KS, KS'); displaying the at least one common security function and selecting at least one displayed common security function; and reconfiguring every communications interface (KS, KS'), wherein the respective currently installed security functions are replaced by the at least one selected common security function, and wherein, in the event that no common security function was determined, every communications interface (KS, KS') is reconfigured in such a way that no security function is activated.