HART Command Whitelisting for Secure Process Diagnostics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity methods in integrated process control and safety systems using the HART communication protocol are inflexible, blocking safe read commands and preventing the use of advanced diagnostic functionalities, thus failing to provide a fine-grained security level that allows for the transmission of essential diagnostic and device information.

Innovation Solution

A whitelist configuration application that securely configures safety logic solvers and process controllers to allow specific HART commands by comparing incoming messages against pre-defined whitelists, enabling the forwarding of safe messages while blocking unsafe ones, and an automatic whitelist learning application that builds whitelists based on security levels and device descriptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity methods block all non-universal HART commands, then security is improved, but diagnostic functionality and device information transmission are lost

Engineering Contradiction:
ImprovecybersecurityVSAvoiddiagnostic information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments HART commands into three distinct categories: universal commands (allowed), whitelisted commands (allowed after configuration), and blocked commands (denied). This segmentation enables selective permissioning where diagnostic commands can be placed in the whitelist category, allowing information flow while maintaining security boundaries. The segmentation resolves the contradiction by creating granular control rather than blanket blocking.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts security permissions based on configured whitelists that can be modified through proper authentication. Rather than static blocking, the system allows administrators to dynamically enable specific diagnostic commands by adding them to whitelists, creating a flexible security model that adapts to legitimate diagnostic needs while maintaining protection against unauthorized access.

Inventive Principle:
Principle #15Dynamics

2Reliability

If all HART commands are blocked except universal read commands, then security is improved, but advanced diagnostic functionalities are prevented

Engineering Contradiction:
ImprovecybersecurityVSAvoiddiagnostic functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a three-tier command permission structure: universal commands (always allowed), whitelisted commands (conditionally allowed), and blocked commands (denied). This segmentation enables advanced diagnostic commands to be placed in the whitelisted category, preserving functionality while maintaining security. The tiered structure resolves the contradiction by providing intermediate permission levels between complete blocking and full access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the security parameter from binary (blocked/allowed) to multi-level (universal/whitelisted/blocked) by introducing configurable whitelist mechanisms. This parameter change enables the system to adaptively permit specific diagnostic commands while maintaining overall security posture, resolving the contradiction between security and functionality.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a hardware key is used to set high security level, then security is improved, but message transmission flexibility is reduced

Engineering Contradiction:
Improvesecurity levelVSAvoidmessage transmission
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary configuration actions by pre-defining whitelists of allowed commands before enforcing security restrictions. Administrators can pre-configure which diagnostic commands should be permitted, and these configurations are stored for automatic enforcement. This preliminary action resolves the contradiction by establishing security rules in advance that automatically allow legitimate messages without requiring real-time key manipulation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The whitelist configuration acts as an intermediary layer between the hardware key security mechanism and message transmission. Rather than directly blocking all non-universal commands, the system uses whitelist configurations as mediators that selectively permit commands based on pre-established rules, maintaining security while enabling legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If write commands are blocked, then security is improved, but device configuration and control capabilities are lost

Engineering Contradiction:
ImprovecybersecurityVSAvoiddevice control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments commands by operation type and risk level, placing read commands, configuration commands, and control commands into different permission categories. Write commands that are essential for device operation can be added to whitelists, while potentially harmful write commands remain blocked. This segmentation resolves the contradiction by enabling necessary device control while preventing malicious actions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different security qualities to different command types and devices. Rather than uniformly blocking all write commands, the system allows administrators to configure device-specific whitelists that permit necessary write operations for particular devices while maintaining blocking for others. This local quality approach resolves the contradiction by tailoring security to specific operational needs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250097199A1Whitelisting for hart communications in a process control system
Publication Date: 2025.03.20 FISHER ROSEMOUNT SYST INC
  • US20250097199A1 patent drawing
  • US20250097199A1 patent drawing
  • US20250097199A1 patent drawing

AI summary

A cybersecurity system for use in a process plant provides whitelisting of device specific and common practice HART read commands in process controllers and safety controllers to perform communications in a process plant that are very secure, but that still enable the implementation of advanced functionality provided in HART devices. A whitelist implementation application applies one or more whitelists in a security gateway device to determine if messages, such as HART messages, should be allowed or processed. A whitelist learning application automatically creates and configures whitelists through the use of a lock/learn mode, and a whitelist configuration application discovers Device Specific and Common Practice HART commands by issuing device description requests to specific devices, parsing the response, and communicating the whitelist configuration information with the parsed command types to the relevant process controllers and safety controllers for use in the whitelists. A user interface enables users to interact with and guide the configuration process to provide for a highly secure system that still enables the diagnostic and other high level functionality of field devices in a process plant.