Electric Field Unit Security via Sender Identification and Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased risk of unauthorized access to electric field units, particularly with the introduction of remote operation capabilities and network-capable Ethernet interfaces, poses a significant security challenge in automation engineering.

Innovation Solution

A method that ensures high security against unwanted access by using an identification device to determine sender characterization data, which is then checked by a security device to permit or block the execution of protected functions, regardless of the communication link type, through an identity database that allocates sender-specific data to determine user types and access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data interfaces (serial, Ethernet) are provided for remote operation of field units, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveremote operation capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

An identification device is introduced as an intermediary component between the data interface and the protected functions. This device determines sender characterization data from incoming commands and appends it to the command data, creating an intermediate verification step that enables remote operation while preventing unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sender identification and authorization checking are implemented for all command data, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidsecurity verification system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The identification device merges multiple security functions into a single integrated component: determining sender characterization data, appending it to command data, and enabling authorization checking. This consolidation achieves comprehensive security protection while minimizing the increase in device complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8132240B2Electric field unit and method for executing a protected function of an electric field unit
Publication Date: 2012.03.06 SIEMENS AG
  • US8132240B2 patent drawing
  • US8132240B2 patent drawing
  • US8132240B2 patent drawing

AI summary

In order to develop a method for carrying out a protected function of an electrical field device in such a manner that a high degree of security against unauthorized accesses to the electrical field device can be ensured irrespective of the nature of the communication link between a user and the electrical field device, an identification device for the electrical field device and a security device are used to check whether a stated protected function of the electrical field device can be carried out, or should be refused. The invention also relates to an appropriately configured electrical field device.