Field Device Authentication via Server-Mediated Terminal Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field devices in automation technology lack secure communication methods to prevent unauthorized access via terminal communication interfaces, especially in large automated systems where numerous terminals and users need to access field devices without compromising operational reliability.
Innovation Solution
Implementing an authentication system where a terminal device transmits an individual access identifier to a field device, which then connects to an authentication server to verify the authenticity of the terminal, ensuring only authorized devices can access field device resources, using cryptographic means for enhanced security and managing access rights and session attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a terminal communication interface is added to field devices to enable modern communication technologies and higher transmission rates, then communication capability and transmission rate are improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the terminal device and field device. The authentication server verifies the authenticity of terminal devices using stored authentication data before allowing communication with field devices, thus providing security without compromising communication speed
Solution Approach 2:
The patent implements preliminary authentication of terminal devices before they can communicate with field devices. The authentication server checks authentication data in advance and only allows authenticated terminals to access field devices, preventing unauthorized access before it can occur
2Reliability
If access control mechanisms are implemented to prevent unauthorized access, then security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the authentication functionality from the field devices and places it in a separate authentication server. This centralizes the security mechanism, reducing the complexity burden on individual field devices while maintaining comprehensive security across the entire system
Solution Approach 2:
The authentication server serves multiple field devices and multiple terminal devices through a single centralized system. This universal authentication mechanism provides security for the entire field device network without requiring separate authentication systems for each device, reducing overall system complexity
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A method (1) for secure communication between a field device (3) of automation technology and an end device (5) connected to the field device (3) via an end device communication link (4) is presented and described, wherein the field device (3) is operatively related to a physical process (6) and the field device (3) can be connected to other field devices (3a, 3b, 3c, 3d) and/or a process control system (8) via a fieldbus interface (7) for the exchange of process information. Unauthorized access to the field device via the end device communication interface is prevented with a high degree of certainty by the fact that an individual access identifier (10) is stored in the end device (5) and the end device (5) transmits its access identifier (10) to the field device (3) (11).that the field device (3) is connected to an authentication server (13) via a server communication link (12) and the field device (3) transmits the access identifier (10) or an access identifier (10') derived from the access identifier (10) to the authentication server (13) (14), that authentication data (15) is stored on the authentication server (13) by means of which the authenticity of the access identifier (10) is checked on the authentication server (13) (16), and that the resulting authentication result (17) is transmitted from the authentication server (13) to the field device (3) via the server communication link (12) (18), and that, depending on the authentication result (17) transmitted to the field device (3), resources of the field device (3) are made available to the terminal device (5) (19).