Field Security Module With Selectable IT Security Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing field devices face challenges in efficiently implementing varying IT security levels without increasing hardware costs, energy consumption, and maintaining operational ergonomics, particularly in the context of Industry 4.0 and critical infrastructure systems, due to varying regulatory requirements.

Innovation Solution

A field device with a security module that includes a selection element for choosing an IT security level, activating necessary functional units, and deactivating unnecessary ones, allowing irreversible selection during commissioning, and optionally using a retrofitting module for enhanced security features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple hardware variants are provided for different IT security levels, then IT security requirements are met, but hardware costs and device complexity increase

Engineering Contradiction:
ImproveIT security levelVSAvoidhardware variants
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A single field device is designed to support multiple IT security levels through a selection element that activates different functional units. The device includes a plurality of functional units for implementing different IT security levels, with a selection element that selects which level to activate, making one device universal for multiple security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If all security functional units are activated, then highest IT security level is achieved, but energy consumption increases

Engineering Contradiction:
ImproveIT security levelVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security functional units are dynamically activated or deactivated based on the selected IT security level. The selection element controls which functional units are active, allowing the device to adapt its energy consumption to the actual security requirements rather than always operating at maximum security level

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The operational state of functional units is changed based on the selected security level parameter. Different combinations of functional units are activated depending on which IT security level is selected, optimizing energy usage according to the required security posture

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If security settings are changeable, then adaptability is improved, but security against unauthorized changes deteriorates

Engineering Contradiction:
Improvesecurity level selectionVSAvoidprotection against unauthorized changes
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The selection element is configured to be changeable only during commissioning phase, which is a preliminary action before normal operation. This preliminary time-limited accessibility allows security level adaptation when needed, while preventing unauthorized changes during operational phase

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260064104A1Field device having a security module, retrofitting module for a field device, method for setting an IT security level and a computer program code
Publication Date: 2026.03.05 VEGA GRIESHABER GMBH & CO
  • US20260064104A1 patent drawing
  • US20260064104A1 patent drawing
  • US20260064104A1 patent drawing

AI summary

A process automation field device having field device electronics with at least one communication interface and a security module with a plurality of functional units for implementing a plurality of predetermined IT security levels of different severity, the security module having a selection element for selecting an IT security level, the functional units necessary for implementing the selected IT security level being activated and/or the unnecessary functional units being deactivated on the basis of the selection.