Field Device Integration via Ticket Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for connecting field devices to control systems with user management are cumbersome and require significant administrative effort, especially when dealing with a large number of devices.

Innovation Solution

A method that integrates a field device into an automation system's operating system by using a ticket server and transport medium, where the field device and ticket server create and process cryptographically secured tickets for authentication and authorization, allowing for pre-registration of field devices at production time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If field devices are connected to control systems with user management using existing methods, then authentication and authorization are achieved, but administrative effort increases significantly

Engineering Contradiction:
Improveauthentication and authorizationVSAvoidadministrative effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-registering field devices at the time of production before delivery to the customer. The device identifier and cryptographic information are stored in advance in the ticket server, so that when the device is first operated, authentication can occur automatically without requiring manual administrative setup. This eliminates the need for time-consuming on-site device registration and reduces administrative burden while maintaining secure authentication.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If field devices are pre-registered at production time, then integration into the operating system is simplified, but device complexity increases

Engineering Contradiction:
Improveintegration processVSAvoidregistration system
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent introduces a ticket server as an intermediary between field devices and the operating system. The ticket server stores device identifiers and cryptographic information, and issues authenticated tickets to authorized users. This intermediary handles the complexity of device registration and authentication centrally, keeping the field devices themselves simple while enabling streamlined integration into the operating system through the ticket-based access mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic information is stored in the ticket server, then security is enhanced, but data transmission requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoiddata transmission
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential device identifier and cryptographic verification information into the ticket server, rather than transmitting or storing complete device configurations or large amounts of data. The ticket server stores compact authentication credentials that enable secure verification with minimal data transmission. When authentication is needed, only small authenticated tickets are transmitted, not large datasets, thus enhancing security while keeping data transmission requirements low.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250131349A1Method for integrating a field device into an operating system of an automation system
Publication Date: 2025.04.24 ENDRESS HAUSER CONDUCTA GMBH CO KG
  • US20250131349A1 patent drawing

AI summary

A method for integrating a field device into an operating system is provided. The operating system includes a ticket server communicating with a transport medium. The ticket server and existing field devices process tickets, which contain a cryptographically secured item of information and transmit the created tickets to the transport medium, where the transport medium transmits the tickets to the recipient(s) and the recipient(s) check(s) the authenticity and integrity of the tickets. The method includes placing an order for the field device and generating registration data by a manufacturer's server. The registration data comprise identification information of the field device and a first cryptographically relevant item of information. The method also includes registering the field device as an existing field device on the ticket server. The registration data are transmitted to the ticket server and a second cryptographically relevant information of the ticket server is stored in the field device.