Field Device Data Separation for Secure Wireless Diagnostics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed control systems, connecting field devices to the Internet via IoT or IIoT poses security risks due to potential unauthorized access, as information used for process control is exchanged between controllers and field devices, and existing solutions fail to adequately separate and secure self-diagnosis information from process control data.
Innovation Solution
A field device with a security unit that permits or rejects requests from a wireless processor based on predefined rules, ensuring that sensitive information is protected, and separate paths for transmitting process control and self-diagnosis data, allowing secure connection to public lines like the Internet.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If field device is connected to public line such as Internet using IoT or IIoT, then information collection capability is improved, but security risk increases due to potential unauthorized access
Solution Approach 1:
The patent segments information into two categories: first information (process control data) and second information (self-diagnosis data). It also segments communication paths, allowing wireless communication to access only self-diagnosis information while process control information remains protected through controlled communication paths. This segmentation enables Internet connectivity for information collection while maintaining security isolation for sensitive process data.
Solution Approach 2:
The patent introduces a communication path segmentation mechanism that acts as an intermediary between the wireless communication unit and the processor. This intermediary controls and restricts access, allowing the wireless unit to retrieve only self-diagnosis information while preventing direct access to process control information, thus enabling secure Internet connectivity.
2Loss of information
If wireless communication unit can access all information in field device, then information collection is improved, but security is compromised due to potential unauthorized access to process control data
Solution Approach 1:
The patent divides information storage and access rights by segmenting data into process control information and self-diagnosis information. The wireless communication unit is granted access only to self-diagnosis information, while process control information remains accessible only through controlled communication paths. This segmentation achieves both complete information collection within security boundaries and protection of sensitive data.
Solution Approach 2:
The patent applies local quality by assigning different access permissions to different information types. Self-diagnosis information is made accessible to the wireless communication unit with appropriate wireless security, while process control information maintains restricted access through controlled communication paths. This localized access control enables comprehensive information collection while maintaining security through differentiated permission structures.
3Reliability
If separate communication paths are established for process control and self-diagnosis, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements multi-functionality by enabling the wireless communication unit to perform dual roles: maintaining wireless connectivity for Internet access and self-diagnosis information retrieval, while the controlled communication path simultaneously handles both process control data transmission and security enforcement. This multi-functional design achieves security through path separation without proportionally increasing device complexity.
Data Source
AI summary
A field device according to one aspect of the present invention may include a first processor configured to perform a process of communicating first information used for process control and a process of generating second information including a diagnosis result obtained by performing self-diagnosis of the field device, a second processor including a first wireless unit configured to perform wireless communication, the second processor being configured to request the first processor to read at least the second information and to perform a process of transmitting, from the first wireless unit, the second information obtained through the read request as a wireless signal, and a security unit configured to permit or reject a request made to the first processor by the second processor in accordance with a rule which is specified in advance.


