Persistent HMI Authentication for Mobile Visualization Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional human machine interfaces (HMIs) in industrial automation lack enhanced functionality, ease of use, and efficient data sharing, particularly in mobile and thin client environments, requiring improved solutions for user authentication and visualization management.

Innovation Solution

A system comprising a visualization manager that communicates with thin client HMIs to provide secure and adaptive access to industrial automation visualizations, utilizing multi-factor authentication and event-driven delivery of visualizations based on user roles, locations, and event triggers, enabling persistent authentication and data sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional HMI authentication is used, then initial security is provided, but users must re-authenticate frequently causing loss of time and reduced ease of operation

Engineering Contradiction:
Improveease of access to visualizationsVSAvoidtime spent on re-authentication
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by capturing user biometric data (fingerprint, facial recognition, or iris scan) during initial login. This authentication result is then stored and reused for subsequent access requests to the same visualization content, eliminating the need for repeated authentication procedures and reducing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the user's biometric authentication data and stores it in the visualization manager. This copied authentication information is then used to verify subsequent access requests without requiring the user to physically present their biometric data again, enabling fast re-authentication while maintaining security.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If thin client devices are used, then flexibility and mobility are improved, but functionality and data processing capability are reduced

Engineering Contradiction:
Improvedevice flexibilityVSAvoidinterface functionality
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The visualization manager acts as an intermediary between the thin client device and the automation controller. It receives authentication data from the thin client, processes the authentication logic, retrieves visualization content from the automation controller, and delivers it to the thin client. This mediator approach allows thin clients to access complex automation visualizations without needing local processing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The visualization manager provides universal access to automation visualizations from multiple sources (automation controllers, workstations, servers) through a single platform. It supports various authentication methods (biometric, password, token) and delivers content to different device types (thin clients, mobile devices, traditional HMIs), making the system universally accessible across diverse devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple authentication methods are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements different authentication methods (biometric, password, token) based on the specific security requirements and context of each access request. The visualization manager selects and applies the appropriate authentication method locally for each user and device combination, rather than requiring all authentication methods for every access attempt, thus maintaining security while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11181892B2Persistent authentication in dynamic automation visualization content delivery
Publication Date: 2021.11.23 ROCKWELL AUTOMATION TECH INC
  • US11181892B2 patent drawing
  • US11181892B2 patent drawing
  • US11181892B2 patent drawing

AI summary

A human interface technique is disclosed for industrial automation systems. The technique allows for visualizations to be distributed to interfaces, such as thin client interfaces, from automation components. For access to the content, a user may be initially authenticated in a first manner, such as by multi-factor authentication. Thereafter, or for a certain time or location, the user may be authenticated by a reduced number of factors, such as single-factor authentication. The authentication may be used to deliver the visualizations based on policies of a visualization manager, such as the user identification, the user role, the user location, and so forth. The reduced factor authentication allow for users to freely move and view visualizations on any available device, or at different locations, and so forth, but still based on the policies.