Field Device Tamper Attempt Reporting via ATAR

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional write protect mechanisms for field devices in industrial plants do not provide tamper attempt reporting, which is crucial for identifying unauthorized changes and potential security breaches, such as hacker activities or malicious configuration changes.

Innovation Solution

The implementation of Automatic Tamper Attempt Reporting (ATAR) algorithms that detect and report attempts to change field device configuration data, even when the device is configured for write protection, by sending alerts to remote host systems via standard communication protocols like HART, WirelessHART, or PROFINET, enabling early warning systems for unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If write protection mechanisms are implemented to block unauthorized changes to field device configuration data, then configuration data security is improved, but the ability to detect and report tamper attempts is lost

Engineering Contradiction:
Improveconfiguration data securityVSAvoidtamper attempt detection capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent divides the protection mechanism into two independent components: write protection logic that blocks unauthorized configuration changes, and tamper detection logic that monitors and reports attempt indicators. This segmentation allows both functions to operate independently without interfering with each other, resolving the contradiction between blocking changes and detecting attempts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary indicator (tamper flag or status bit) that mediates between the write protection mechanism and the host system. This indicator serves as a communication channel that reports tamper attempts without requiring the host system to have write access, thus maintaining security while enabling detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If standard operating procedures and access control are used to prevent unauthorized changes, then configuration security is maintained, but real-time awareness of tamper attempts is lost

Engineering Contradiction:
Improveconfiguration securityVSAvoidresponse time to tamper attempts
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the field device automatically detect and record tamper attempt indicators in real-time, before any actual configuration changes can occur. This allows the host system to be alerted proactively and take preventive measures, reducing the time lag between tamper attempt and response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism where the field device continuously monitors for tamper attempts and automatically reports indicators to the host system via the fieldbus communication interface. This real-time feedback loop eliminates the time delay associated with manual monitoring and enables immediate response to security threats.

Inventive Principle:
Principle #23Feedback

3Reliability

If write protection software or hardware jumpers are used to block unauthorized changes, then configuration data is protected, but information about tamper attempts remains hidden from operations personnel

Engineering Contradiction:
Improveconfiguration data protectionVSAvoidtamper attempt visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent uses an intermediary indicator (such as a tamper flag or status bit) that is automatically set by the field device when a tamper attempt is detected. This indicator serves as a visible signal to operations personnel and the host system, making tamper attempt information visible without compromising the write protection mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service by enabling the field device to automatically detect, record, and report tamper attempt indicators without requiring external monitoring or manual inspection. The device serves itself by generating and communicating the tamper information through the existing fieldbus interface, making hidden information visible to operations personnel.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2907102B1Field device having tamper attempt reporting
Publication Date: 2020.03.04 HONEYWELL INTERNATIONAL INC
  • EP2907102B1 patent drawingFigure 1
  • EP2907102B1 patent drawingFigure 2A~2B
  • EP2907102B1 patent drawingFigure 3

AI summary

A method (100) of tamper attempt reporting includes receiving (101) a write attempt to configuration data stored within a field device in an industrial plant configured to run a process involving a plurality of physical process parameters including a network server, a plurality of processing units, and a plurality of field devices. The plurality of field devices include (i) a sensor for measuring at least one of the plurality of physical process parameters or (ii) an instrument for performing control output actions for at least one of the plurality of processing units. The plurality of field devices are in communication with at least one remote host system or device. The write attempt is automatically detected (102). An alert of the write attempt is automatically sent (103) to at least the remote host system or device.