Field Device Access Control via Electronic Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing field devices lack robust protection against unauthorized access and manipulation, allowing indirect or multi-stage overriding of access restrictions.

Innovation Solution

Incorporating a test module that ensures access is only granted if the access right has a valid electronic signature, preventing unauthorized access by authenticating access rights through a secure electronic signature verification process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access rights are stored in memory without electronic signature verification, then device complexity is reduced and ease of operation is improved, but security against unauthorized access and manipulation deteriorates

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-generating electronic signatures for access rights using a hash algorithm and asymmetric encryption before storing them in memory. The test module then verifies these pre-computed signatures during access control checks, eliminating the need for complex real-time cryptographic operations while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical or software-based access control mechanisms with a cryptographic verification system. Instead of relying on complex permission checking logic, the system uses mathematical cryptography (hash algorithms and asymmetric encryption) to provide provable security, substituting computational mathematics for conventional access control methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If electronic signature verification is implemented for all access rights, then protection against falsified access rights is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveauthenticity of access rightsVSAvoidaccess verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs the computationally intensive cryptographic operations in advance: generating hash values from access right content and encrypting them with private keys before storage. During verification, only the relatively simple decryption and hash comparison operations are performed, significantly reducing real-time processing requirements while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the access right data into a fixed-length hash value, changing the parameter from variable-length access right content to a fixed-size cryptographic digest. This transformation enables efficient verification by comparing fixed-size values rather than processing entire access right datasets during authentication.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If access rights can be manipulated and extended in multiple stages, then adaptability and ease of configuration are improved, but security against indirect unauthorized access deteriorates

Engineering Contradiction:
Improveflexibility of access rights configurationVSAvoidprotection against multi-stage manipulation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by pre-protecting access rights with electronic signatures before any manipulation can occur. The signature verification creates a preventive barrier that blocks multi-stage manipulation attempts, as any modification to signed access rights would invalidate their signatures and prevent unauthorized activation.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces electronic signatures as an intermediary layer between access right configuration and activation. This intermediary mechanism ensures that only properly signed and verified access rights can be activated, preventing indirect unauthorized access even when configuration flexibility is maintained through authorized modification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2235598B1Field device and method of operation thereof
Publication Date: 2013.05.15 SIEMENS AG
  • EP2235598B1 patent drawingFigure 1
  • EP2235598B1 patent drawingFigure 2
  • EP2235598B1 patent drawingFigure 3~4

AI summary

The invention relates inter alia to a field device, particularly to a protective device for protecting, controlling or monitoring an electric switching or energy supply unit having an access control device, controlling an access to the field device, wherein the access control device comprises: a storage with access rights, roles and users stored therein, wherein each access right defines the access to at least one device value, one device parameter or one device function, one or more access rights are associated with each role, and one or more roles are associated with each user, and a control device suitable to prevent an access to a device value, a device parameter or a device function by a user when the respective user is not associated with a role with the access right required for the respective access. According to the invention, the control device comprises a test module that exclusively allows access by a user only if the access right that is required for the respective access and that is stored in the storage is provided with a valid electronic signature.