HART Whitelisting in Process Controllers for Secure Diagnostics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity methods in integrated process control and safety systems using the HART communication protocol are inflexible, blocking safe read commands and preventing the use of advanced diagnostic functionalities, thus failing to provide a fine-grained security level that allows for the transmission of essential diagnostic and device information.

Innovation Solution

A whitelist configuration application that securely configures safety logic solvers and process controllers to allow specific messages to be forwarded based on pre-defined whitelists, enabling the transmission of necessary information while blocking unauthorized commands, and an automatic whitelist learning application that builds whitelists based on security levels and command types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity methods block all non-universal HART commands, then security level is improved, but diagnostic functionality is lost

Engineering Contradiction:
Improvecybersecurity levelVSAvoiddiagnostic information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments HART commands into multiple categories (Universal Commands, Common Practice Commands, and Device Specific Commands) and applies different security policies to each category. This segmentation allows the system to permit Universal Commands while blocking or selectively permitting other command types, thereby achieving fine-grained security control that preserves diagnostic functionality through Common Practice Commands while maintaining security through selective blocking of Device Specific Commands.

Inventive Principle:
Principle #1Segmentation

2Reliability

If all HART commands are blocked except universal read commands, then security is improved, but advanced diagnostic functionalities are prevented

Engineering Contradiction:
ImprovesecurityVSAvoiddiagnostic functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies different security qualities to different parts of the command set. Universal Commands receive one security treatment, Common Practice Commands receive another, and Device Specific Commands receive a third. This local differentiation of security policies allows the system to permit diagnostically valuable Common Practice Commands while applying stricter controls to potentially more risky Device Specific Commands, achieving both security and diagnostic functionality.

Inventive Principle:
Principle #3Local quality

3Reliability

If a hardware key is used to set security levels, then security control is improved, but flexibility in command transmission is reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidcommand transmission flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security control where the security level (configured via hardware key) can be changed to alter which command categories are permitted. The system dynamically adjusts its security policy based on the configured level, allowing operators to switch between more restrictive and more permissive modes as needed, thereby maintaining both strong security control and operational flexibility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12160406B2Whitelisting for HART communications in a process control system
Publication Date: 2024.12.03 FISHER ROSEMOUNT SYST INC
  • US12160406B2 patent drawing
  • US12160406B2 patent drawing
  • US12160406B2 patent drawing

AI summary

A cybersecurity system for use in a process plant provides whitelisting of device specific and common practice HART read commands in process controllers and safety controllers to perform communications in a process plant that are very secure, but that still enable the implementation of advanced functionality provided in HART devices. A whitelist implementation application applies one or more whitelists in a security gateway device to determine if messages, such as HART messages, should be allowed or processed. A whitelist learning application automatically creates and configures whitelists, and a whitelist configuration application discovers Device Specific and Common Practice HART commands by issuing device description requests to specific devices, parsing the response, and communicating the whitelist configuration information with the parsed command types to the relevant process controllers and safety controllers for use in the whitelists. A user interface enables users to interact with and guide the configuration process.