Handheld Terminal Security for Uncommissioned Field Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Un-commissioned field devices, such as smart meters, are vulnerable to attacks due to lack of network connectivity, which prevents authentication using certificate chains, and existing security methods fail to restrict unauthorized tasks performed by handheld terminals (HHTs).
Innovation Solution
The implementation of factory-installed trust anchor certificates and authentication certificates on both un-commissioned devices and HHTs allows for mutual authentication and authorization, enabling secure communication without network access, using a certificate hierarchy that includes a Root Certificate Authority and Supplier Certificate Authority to validate other certificates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate chain authentication is used to secure HHT communications, then security is improved, but un-commissioned devices without network connectivity cannot authenticate HHTs
Solution Approach 1:
The patent pre-provisions trust anchor certificates in un-commissioned devices during manufacturing, before the devices are deployed to field locations. This preliminary action enables the devices to authenticate HHTs without requiring network connectivity or certificate chains, directly resolving the contradiction by providing authentication capability in advance of when it is needed.
Solution Approach 2:
The patent introduces trust anchor certificates as an intermediary element that bridges the gap between un-commissioned devices and HHTs. These trust anchors serve as a substitute for the usual certificate chain authentication mechanism, enabling secure authentication in environments where traditional certificate validation cannot occur due to lack of network connectivity.
2Adaptability or versatility
If HHTs are given full access to perform vital tasks on field devices, then operational versatility is improved, but security risk increases due to potential loss or misuse of HHTs
Solution Approach 1:
The patent implements role-based access control where different HHT users are granted specific authorization levels corresponding to their job functions. Field service technicians receive limited authorization for basic tasks, while more privileged users can perform reconfiguration and maintenance operations. This local quality approach assigns different security permissions to different users based on their specific needs, resolving the contradiction by providing necessary versatility while minimizing security risks.
Solution Approach 2:
The patent segments HHT authorization into multiple hierarchical levels, dividing the broad set of possible tasks into distinct authorized operation categories. This segmentation allows the system to grant minimal necessary permissions to each user rather than full access, enabling operational versatility for authorized tasks while reducing security risk by limiting the impact of potential HHT compromise.
3Reliability
If traditional certificate authentication is required for all devices, then security is improved, but deployment efficiency decreases due to complex commissioning requirements
Solution Approach 1:
The patent employs lightweight trust anchor certificates that can be pre-provisioned in devices during manufacturing without requiring complex commissioning procedures. These trust anchors enable immediate authentication capability upon device deployment, eliminating the need for time-consuming certificate chain installation and validation processes, thus dramatically improving deployment efficiency while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer implemented method and apparatus for authenticating a field tool by a field device comprising: receiving, on a field device, an authentication certificate; verifying the authentication certificate using a trust anchor certificate on the field device; securing communication between the field tool and the field device with a key generated by a key derivation method using exchanged certificates; receiving a field tool task authorization certificate; verifying the authorization certificate using a trust anchor certificate on the field device; receiving a task request to perform a task by the field tool; and determining whether the task is authorized based on the task authorization certificate; and performing the task on the field device when it is determined the task is authorized.