Gateway Authorization Assignment for Field Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for assigning access authorizations to mobile operating devices for field devices are cumbersome and lack automation, leading to potential unauthorized access.

Innovation Solution

A gateway system that automatically transmits access authorizations from a central authorization unit to mobile operating devices via wireless communication, with interfaces for short-range and long-range communication, ensuring secure and flexible access management based on location, time, and device-specific permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual authorization assignment methods are used, then security control is maintained, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improveauthorization assignment processVSAvoidauthorization assignment time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring authorization rules and user profiles in the authorization server before field operations. When a mobile device approaches a field device, the gateway automatically retrieves and transmits the appropriate authorization tokens without requiring manual intervention, thus simplifying the process and saving time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing mobile devices to automatically receive and manage their own authorization credentials through the gateway. The authorization assignment unit autonomously handles credential distribution based on pre-defined rules, eliminating the need for manual authorization management and reducing time loss.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated authorization transmission is implemented, then process simplification is achieved, but security risks may increase

Engineering Contradiction:
Improveauthorization management efficiencyVSAvoidaccess security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the gateway continuously monitors the presence and status of mobile devices near field devices. Authorization credentials are dynamically transmitted or revoked based on real-time feedback about device proximity and operational context, maintaining security while enabling automated high-efficiency authorization management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authorization system is made dynamic by allowing credentials to be automatically granted, modified, or revoked based on changing conditions such as device proximity, time of day, and operational requirements. This dynamic approach maintains security through conditional authorization while achieving productivity gains through automation.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If access authorization is granted broadly, then ease of access is improved, but unauthorized access risk increases

Engineering Contradiction:
Improvefield device accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by granting different authorization levels to different mobile devices based on their specific needs, roles, and proximity to field devices. Instead of broad uniform access, each device receives precisely the authorization level required for its specific operational context, facilitating ease of access while preventing unauthorized access through granular control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11553341B2Authorization assignment on field devices
Publication Date: 2023.01.10 VEGA GRIESHABER GMBH & CO
  • US11553341B2 patent drawing

AI summary

A gateway for assigning an access authorization for a mobile operating device to a field device, including a first interface that wirelessly communicates with the mobile operating device, a second interface that communicates with an authorization assignment device, a memory device that stores an access authorization of the mobile operating device transmitted by the authorization assignment device, authorization assignment circuitry that reads the access authorization of the mobile operating device from the memory device and transmits the access authorization to the mobile operating device via the first interface.