Fieldbus Segment Aggregation for Centralized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fieldbus systems with multiple network segments require separate access permission configurations for each segment, leading to significant administrative overhead and security challenges.

Innovation Solution

An aggregator device establishes centralized data connections to multiple network segments, allowing unified access and management of fieldbus components through a single firewall, reducing the need for individual configurations on each segment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate access permission configurations are implemented for each network segment, then system security is improved, but administrative overhead and device complexity increase significantly

Engineering Contradiction:
Improvesystem securityVSAvoidaccess permission configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an aggregator device as an intermediary between host computers and multiple network segments. The aggregator centralizes access permission management by maintaining a single configuration that controls access to all network segments, eliminating the need for separate firewall configurations on each segment while maintaining security through centralized authorization control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If separate access permission configurations are implemented for each network segment, then access control precision is improved, but administrative effort and time consumption increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidadministrative effort
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges multiple separate access permission configurations into a single unified configuration stored in the aggregator device. This consolidation maintains precise access control for each network segment while reducing administrative effort, as technicians only need to manage one centralized configuration instead of multiple distributed configurations across different segments

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3861412B1Aggregator apparatus for standardized access to a plurality of network segments of a field bus system
Publication Date: 2026.03.25 ENDRESS HAUSER PROCESS SOLUTIONS AG
  • EP3861412B1 patent drawingFigure 1
  • EP3861412B1 patent drawingFigure 2
  • EP3861412B1 patent drawingFigure 3

AI summary

A description is given of an aggregator apparatus which is designed to form a plurality of first data connections to a plurality of field access devices, wherein the field access devices are connected to a plurality of different network segments of a field bus system. The aggregator apparatus is designed to form at least one second data connection to at least one host computer. The aggregator apparatus is designed to receive first data traffic from the at least one host computer via at least one of the second data connections and to forward the first data traffic, via at least one of the first data connections, to a field access device of that network segment in which the particular field bus component, to which the first data traffic is directed, is situated. The aggregator apparatus is also designed to receive second data traffic from a field bus component in one of the network segments via at least one of the first data connections and to forward the second data traffic to at least one of the host computers via at least one of the second data connections.