Field Device Interface Security Using Shared Safety Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field devices in industrial communication networks are vulnerable to impermissible access due to inconsistent activation of safety functions across communication interfaces, which can lead to data integrity issues and security breaches.

Innovation Solution

A method that registers and activates shared safety functions across all communication interfaces in field devices, ensuring that either the same safety functions are activated on all interfaces or none are, thereby securing the communication network against unauthorized access by reconfiguring interfaces to maintain consistent protection goals like integrity and confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If safety functions are activated on individual communication interfaces, then security protection is improved, but inconsistency across interfaces leads to vulnerabilities and data integrity issues

Engineering Contradiction:
Improvesecurity protectionVSAvoidconsistency across interfaces
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent applies equipotentiality by ensuring that all communication interfaces operate at the same security level. The method registers safety functions for each interface, identifies shared safety functions common to all interfaces, and activates these shared functions across all interfaces uniformly. This creates an equipotential security state where no single interface has weaker protection, eliminating security vulnerabilities caused by inconsistent activation states across different communication interfaces.

Inventive Principle:
Principle #12Equipotentiality

2Adaptability or versatility

If different safety functions are activated on different communication interfaces, then interface-specific security needs are met, but system complexity and configuration difficulty increase

Engineering Contradiction:
Improveinterface-specific securityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by identifying and activating shared safety functions that can be universally applied across all communication interfaces. Instead of configuring each interface independently with potentially different safety functions, the method finds the intersection of safety functions available on all interfaces and activates them system-wide. This universal approach simplifies configuration while still providing adequate security for all interfaces through the shared protective functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the security configuration of multiple communication interfaces into a unified approach. By registering safety functions for each interface, identifying shared functions, and activating them across all interfaces simultaneously, the method combines what would be separate configuration tasks into a single coordinated process. This merging reduces overall system complexity while maintaining the ability to address security needs across all interfaces through the shared safety function set.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If safety functions are activated on all communication interfaces, then data integrity is improved, but communication compatibility issues may arise when interfaces have different activatable functions

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by activating safety functions at the appropriate level - specifically, shared safety functions are activated on all interfaces, while interface-specific functions remain localized to their respective interfaces. This selective activation ensures data integrity through consistent safety functions where needed, while preserving communication compatibility by allowing interfaces to maintain their unique capabilities through locally-activated functions. The method thus achieves local quality optimization without sacrificing overall system adaptability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11481516B2Method for preventing impermissible access to software applications in field devices
Publication Date: 2022.10.25 ENDRESS HAUSER PROCESS SOLUTIONS AG
  • US11481516B2 patent drawing
  • US11481516B2 patent drawing

AI summary

The invention includes a method and a communication network for preventing impermissible access to software applications implemented in field devices, wherein the field devices are integrated in a communication network of automation technology and wherein each software application exchanges information within the communication network via at least one communication interface. The method includes registering currently activated safety functions of each of the communication interfaces; registering all activatable safety functions of each communication interface; ascertaining at least one shared safety function, which is activatable in each of the communication interfaces; displaying the shared safety functions and selecting at least one displayed, shared safety function; and reconfiguring each of the communication interfaces, wherein currently set safety functions are replaced by the at least one selected, shared safety function, and when no shared safety function was ascertained, each of the communication interfaces is so reconfigured that no safety function is activated.