Field Device Access Key Synchronization for Multi-User Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for changing access keys in field devices in automation technology are inefficient and lack centralized management, especially when multiple authorized users or control units need to access the devices.
Innovation Solution
Implement a key database on a database server that stores field device identifiers, existing access keys, and authorized user or control unit identifiers, enabling centralized management and secure distribution of access keys through encryption and synchronization processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If access keys are managed locally in each field device and control unit, then security is maintained through distributed key storage, but key management becomes inefficient and difficult to synchronize when multiple authorized users need access
Solution Approach 1:
A centralized server acts as an intermediary between field devices and control units for key management. The server stores master key data sets and distributes access keys to authorized control units, coordinating key changes across the distributed system without requiring direct peer-to-peer communication between all devices.
Solution Approach 2:
The system transitions from purely distributed key storage to a hierarchical structure with a centralized management dimension. The centralized server operates at a higher organizational level, managing key lifecycles across multiple field devices and control units, while local devices retain operational autonomy.
2Reliability
If a new access key is changed in one control unit, then security is improved by rotating keys, but other authorized control units with the old key are temporarily excluded from access
Solution Approach 1:
The system performs preliminary distribution of new access keys to the centralized server before actual key rotation occurs. The server prepares and validates new key data sets in advance, ensuring that when keys are rotated across control units, the transition is coordinated and seamless, preventing temporary access exclusions.
Solution Approach 2:
The centralized server implements feedback mechanisms to track which control units have which keys and when key rotations occur. This feedback enables the server to coordinate key changes across the system, ensuring that new keys are distributed to all authorized control units before old keys are invalidated, maintaining continuous access for all authorized users.
3Ease of manufacture
If access keys are transmitted directly between control unit and field device, then communication is simple and direct, but security risks increase during key transmission
Solution Approach 1:
The centralized server serves as a secure intermediary for key transmission. Instead of direct peer-to-peer key exchange between control units and field devices, all key data sets are transmitted through the server, which encrypts and manages the transmission, reducing security risks while maintaining implementation simplicity.
Solution Approach 2:
The system uses encrypted copies of key data sets transmitted through the centralized server. Rather than transmitting actual access keys directly, the server transmits encrypted key data sets that can be securely decrypted only by authorized devices, reducing transmission security risks while maintaining direct communication capabilities.
Data Source
AI summary
A method for changing an existing access key in a field device in automation technology includes the steps of: providing a key database on a database server; generating a key data set for a user authorized to access or a control unit authorized to access from the key database; and transferring the key data set to the control unit of the access-authorized user or the access-authorized control unit, so that the control unit of the access-authorized user or the access-authorized control unit has the existing access keys of the field devices for which an access authorization exists. The key database is for a plurality of field devices and contains at least a field device identifier of a respective field device, the existing access key of the respective field device and the identifier of a user authorized to access and/or a control unit authorized to access the respective field device.


