Field Device Interface Security Using Shared Safety Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field devices in industrial communication networks are vulnerable to impermissible access due to inconsistent activation of safety functions across communication interfaces, which can lead to data integrity issues and security breaches.
Innovation Solution
A method that registers and activates shared safety functions across all communication interfaces in field devices, ensuring that either the same safety functions are activated on all interfaces or none are, thereby securing the communication network against unauthorized access by reconfiguring interfaces to maintain consistent protection goals like integrity and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If safety functions are activated on individual communication interfaces, then security protection is improved, but inconsistency across interfaces leads to vulnerabilities and data integrity issues
Solution Approach 1:
The patent applies equipotentiality by ensuring that all communication interfaces operate at the same security level. The method registers safety functions for each interface, identifies shared safety functions common to all interfaces, and activates these shared functions across all interfaces uniformly. This creates an equipotential security state where no single interface has weaker protection, eliminating security vulnerabilities caused by inconsistent activation states across different communication interfaces.
2Adaptability or versatility
If different safety functions are activated on different communication interfaces, then interface-specific security needs are met, but system complexity and configuration difficulty increase
Solution Approach 1:
The patent applies universality by identifying and activating shared safety functions that can be universally applied across all communication interfaces. Instead of configuring each interface independently with potentially different safety functions, the method finds the intersection of safety functions available on all interfaces and activates them system-wide. This universal approach simplifies configuration while still providing adequate security for all interfaces through the shared protective functions.
Solution Approach 2:
The patent merges the security configuration of multiple communication interfaces into a unified approach. By registering safety functions for each interface, identifying shared functions, and activating them across all interfaces simultaneously, the method combines what would be separate configuration tasks into a single coordinated process. This merging reduces overall system complexity while maintaining the ability to address security needs across all interfaces through the shared safety function set.
3Reliability
If safety functions are activated on all communication interfaces, then data integrity is improved, but communication compatibility issues may arise when interfaces have different activatable functions
Solution Approach 1:
The patent applies local quality by activating safety functions at the appropriate level - specifically, shared safety functions are activated on all interfaces, while interface-specific functions remain localized to their respective interfaces. This selective activation ensures data integrity through consistent safety functions where needed, while preserving communication compatibility by allowing interfaces to maintain their unique capabilities through locally-activated functions. The method thus achieves local quality optimization without sacrificing overall system adaptability.
Data Source
AI summary
The invention includes a method and a communication network for preventing impermissible access to software applications implemented in field devices, wherein the field devices are integrated in a communication network of automation technology and wherein each software application exchanges information within the communication network via at least one communication interface. The method includes registering currently activated safety functions of each of the communication interfaces; registering all activatable safety functions of each communication interface; ascertaining at least one shared safety function, which is activatable in each of the communication interfaces; displaying the shared safety functions and selecting at least one displayed, shared safety function; and reconfiguring each of the communication interfaces, wherein currently set safety functions are replaced by the at least one selected, shared safety function, and when no shared safety function was ascertained, each of the communication interfaces is so reconfigured that no safety function is activated.

