Process Control Instrument Secure Mode for Authorized Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional process control systems lack comprehensive security measures to protect Level 0 (L0) and Level 1 (L1) field devices, making them vulnerable to attacks despite the presence of hardware and software filters, especially when connected to networks.

Innovation Solution

A process control system that includes a process control instrument, a controller, and an authorization server, where the instrument can be placed in an enhanced secure mode with restricted access, authenticated using a unique secure code, and configured for secure operation by an authorized user, utilizing either a hardware or virtual switch setting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If process control instruments are connected to networks for accessibility and control, then ease of operation and monitoring is improved, but vulnerability to attacks and unauthorized access increases

Engineering Contradiction:
Improveaccessibility of process control instrumentsVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments network access into multiple access modes (normal mode and secure mode) controlled by a mode indicator. This segmentation allows the system to maintain network connectivity while restricting access to sensitive functions, thereby resolving the contradiction between accessibility and security vulnerability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic access control where the process control instrument can switch between normal mode and secure mode based on the state of a mode indicator. This dynamic adjustment of access permissions allows the system to adapt its security level according to operational needs, maintaining both accessibility and protection against attacks.

Inventive Principle:
Principle #15Dynamics

2Reliability

If conventional hardware and software filters are deployed before L0/L1 devices, then protection at higher levels is improved, but L0/L1 field devices remain vulnerable to direct attacks

Engineering Contradiction:
Improveprotection of process control systemVSAvoidvulnerability of L0/L1 devices
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing security measures specifically at the L0/L1 field device level through the mode indicator and access mode mechanisms. Rather than relying solely on higher-level filters, the security functionality is embedded directly in the field devices, providing localized protection where it is most needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The mode indicator acts as an intermediary security mechanism between the network and the process control instrument. It mediates access requests by enforcing mode-dependent access rules, providing an additional layer of protection that complements conventional hardware and software filters at higher levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If access to process control instruments is restricted to authorized users only, then security is improved, but ease of operation and configuration is reduced

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidconfiguration accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent uses dynamic mode switching to balance security and operational ease. The mode indicator enables the system to transition between normal mode (with broader access) and secure mode (with restricted access), allowing authorized users to configure instruments when needed while preventing unauthorized access during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements preliminary action by requiring users to establish authorized access and set appropriate modes before configuring security details. The mode indicator is configured in advance to enforce the desired access restrictions, ensuring that security measures are in place before potential unauthorized access attempts occur.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4390732A1Enhanced security of process control instruments
Publication Date: 2024.06.26 SCHNEIDER ELECTRIC SYSTEMS USA INC
  • EP4390732A1 patent drawingFigure 1
  • EP4390732A1 patent drawingFigure 2
  • EP4390732A1 patent drawingFigure 3

AI summary

System and method of securing a process control instrument of a process control system. An authorization server is configured to authenticate the process control instrument based on a unique secure code provided to the server in response to the process control instrument entering an enhanced secure mode as determined by a switch setting. In response to being authenticated in the enhanced secure mode, the process control instrument is configured to operate in a configuration state in which an authorized user is granted access to configure the security details of the process control instrument.