Identity-Based Functional Safety for Hazardous Machinery Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional industrial safety systems do not consider user identity or role when determining safety responses, leading to unnecessary safety actions and limited flexibility in access control, which can impact productivity and safety performance.

Innovation Solution

Integrating user identity and role-based security policies into industrial control and safety systems by leveraging corporate-level employee identity and security data to enforce role-specific access and control actions on the plant floor, using a safety authority system that generates and enforces security tokens based on user credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional industrial safety systems are used that do not consider user identity or role, then safety responses are consistently applied, but false trips occur during maintenance activities and productivity is reduced

Engineering Contradiction:
ImproveproductivityVSAvoidsafety performance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The safety system dynamically adapts its response based on user identity and role. The system transitions from static, uniform safety responses to dynamic, context-aware responses that adjust safety actions according to the authenticated user's credentials, thereby reducing false trips during maintenance while maintaining safety for unauthorized users

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different safety responses are applied to different user roles. The system implements local quality by tailoring safety actions to specific user contexts - for example, allowing maintenance personnel to perform specific actions while preventing unauthorized access, thereby optimizing both productivity and safety performance for each user category

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If role-based access control is implemented, then access flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The safety authority system serves multiple functions: it authenticates users, determines roles, generates security tokens, and enforces access control policies. By consolidating these functions into a single multi-functional system, the patent reduces overall system complexity while maintaining flexible role-based access control

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Security tokens act as intermediaries between user credentials and access control decisions. The tokens encapsulate user identity and role information, simplifying the interaction between authentication and authorization mechanisms while enabling flexible access control without proportionally increasing system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If security tokens are generated based on user credentials, then access control precision is improved, but authentication system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

User credentials are pre-configured in the safety authority system before authentication occurs. The system maintains a database of user identities and roles, allowing for precise access control decisions to be made rapidly during authentication without complex real-time analysis, thereby improving precision while managing complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3920060B1User security credentials as an element of functional safety
Publication Date: 2024.12.04 ROCKWELL AUTOMATION TECH INC
  • EP3920060B1 patent drawingFigure 1
  • EP3920060B1 patent drawingFigure 2
  • EP3920060B1 patent drawingFigure 3a

AI summary

An industrial safety architecture integrates employee identity and enterprise-level security policy into plant-floor functional safety systems, allowing control and safety systems on the plant floor to regulate safe interactions with hazardous controlled machinery based on user identity or role. The architecture leverages existing employee identity and security policy data maintained on the corporate level of an industrial enterprise to manage identity- and/or role-based control and safety on the plant level. Safety authority systems at both the corporate level and the plant level of the industrial enterprise obtain employee and security policy data from corporate-level systems and provides this data in as SIL-rated manner to industrial control and safety systems on the plant floor, where the identity and security policy information is used by functional safety systems to control access to industrial systems as a function of user identity, role, certifications, or other qualifications.