Field Security Module With Fixed IT Security Level Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing field devices face challenges in efficiently implementing varying IT security levels without increasing hardware costs, energy consumption, or compromising operational ergonomics, especially in the context of evolving cybersecurity standards and networked industrial systems.

Innovation Solution

A field device with a security module that includes a selection element for choosing and irreversibly setting an IT security level, activating necessary functional units, and deactivating unnecessary ones, allowing adaptation to specific security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security levels are implemented with separate hardware components, then IT security level is improved, but device complexity and cost increase

Engineering Contradiction:
ImproveIT security levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a single security module that can operate at multiple predetermined IT security levels (SL1-SL4) by activating different functional units based on a selection element setting, rather than requiring separate hardware components for each security level. This universal approach allows one module to serve multiple security functions across different protection levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the operational parameters of the security module by activating or deactivating specific functional units based on the selected security level. The selection element determines which functional units are activated, effectively changing the module's security parameters without altering its physical structure or adding hardware components.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If high IT security levels are implemented, then cybersecurity protection is improved, but energy consumption increases

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent dynamically changes the energy consumption parameters by activating only the functional units necessary for the selected security level. Lower security levels activate fewer functional units, reducing energy consumption, while higher security levels activate additional units as needed, optimizing the balance between security and energy usage.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If security level selection is made changeable, then adaptability is improved, but security reliability deteriorates due to unauthorized changes

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs the security level selection action preliminarily during device commissioning or initialization, before the device enters normal operation. The selection element is configured to allow changes only during specific commissioning phases, and once selected, the security level becomes fixed for the operational lifetime of the device, preventing unauthorized changes while maintaining initial adaptability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the device lifecycle into distinct phases: a commissioning phase where security level selection is permitted, and an operational phase where the selection is locked. This temporal segmentation allows adaptability during setup while ensuring reliability during operation, separating the functions of configuration and execution.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12493284B2Field device having a security module, retrofitting module for a field device, method for setting an IT security level and a computer program code
Publication Date: 2025.12.09 VEGA GRIESHABER GMBH & CO
  • US12493284B2 patent drawing
  • US12493284B2 patent drawing
  • US12493284B2 patent drawing

AI summary

A process automation field device having field device electronics with at least one communication interface and a security module with a plurality of functional units for implementing a plurality of predetermined IT security levels of different severity, the security module having a selection element for selecting an IT security level, the functional units necessary for implementing the selected IT security level being activated and/or the unnecessary functional units being deactivated on the basis of the selection.