Field Device User Access via Ticket-Based Transport Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing field devices in industrial installations lack central user management capabilities, making it difficult to implement secure and efficient user access control, especially for older devices that do not have the necessary communications interfaces or resources.
Innovation Solution
A method that enables central user management for existing field devices by using a transport medium to create and transmit a ticket with cryptographically secured information, allowing authentication and authorization without modifying the field devices' software or hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If central user management is implemented for field devices, then user access security and administrative efficiency are improved, but device complexity and implementation difficulty increase for existing field devices
Solution Approach 1:
A transport medium acts as an intermediary between the user database and existing field devices. The transport medium receives user data from the user database, converts it into device-specific user data formats, and transmits it to the field device. This intermediary approach enables central user management for existing field devices without requiring modifications to the devices themselves, thus improving security while avoiding increased device complexity
Solution Approach 2:
The system changes the format of user data parameters to be compatible with different field devices. User data is stored in a standardized format in the user database, then transformed into device-specific formats (such as different authentication protocols or data structures) during transmission through the transport medium. This parameter transformation enables universal user management across diverse existing devices without modifying the devices
2Ease of manufacture
If existing field devices are used without modification, then deployment cost and time are reduced, but user management capability and security are insufficient
Solution Approach 1:
The transport medium serves as an external intermediary that bridges the gap between modern user management requirements and legacy field devices. It implements the user management logic externally, allowing existing field devices to be used as-is while still providing enhanced user management capabilities through the intermediary layer
Solution Approach 2:
The user management functionality is segmented from the field devices and placed in external components (user database and transport medium). This segmentation allows the field devices to remain unchanged and easily deployable, while the user management capability is implemented separately in the transport medium, which can be updated and configured independently
3Adaptability or versatility
If transport medium converts user data to device-specific formats, then compatibility with existing field devices is improved, but data processing complexity increases
Solution Approach 1:
The transport medium is designed with universal functionality to handle multiple device-specific data formats. It implements a library of conversion routines that can transform standardized user data into various device-specific formats as needed. This multi-functional approach enables broad device compatibility while centralizing the data processing complexity in the transport medium rather than in each individual field device
Data Source
AI summary
Managing field device users includes establishing a first communications link between a transport medium and user database and sending a ticket from the database to the transport medium via the first communications link. The ticket includes first user data, field device identification information, and second user data. The first user data cannot be processed by the field device and the second user data can be processed by the field device. The user is authenticated to the transport medium based upon the first user data. A field device specific operating telegram is created using the transport medium if the user has been authenticated, wherein the operating telegram contains the second user data. The operating telegram is sent to the field device via a second communications link, verifying the second user data, and granting access from the transport medium to the field device based upon valid second user data.
