Persistent HMI Authentication for Mobile Visualization Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional human machine interfaces (HMIs) in industrial automation lack enhanced functionality, ease of use, and efficient data sharing, particularly in mobile and thin client environments, requiring improved solutions for user authentication and visualization management.
Innovation Solution
A system comprising a visualization manager that communicates with thin client HMIs to provide secure and adaptive access to industrial automation visualizations, utilizing multi-factor authentication and event-driven delivery of visualizations based on user roles, locations, and event triggers, enabling persistent authentication and data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional HMI authentication is used, then initial security is provided, but users must re-authenticate frequently causing loss of time and reduced ease of operation
Solution Approach 1:
The system performs preliminary authentication by capturing user biometric data (fingerprint, facial recognition, or iris scan) during initial login. This authentication result is then stored and reused for subsequent access requests to the same visualization content, eliminating the need for repeated authentication procedures and reducing time loss.
Solution Approach 2:
The system creates a copy of the user's biometric authentication data and stores it in the visualization manager. This copied authentication information is then used to verify subsequent access requests without requiring the user to physically present their biometric data again, enabling fast re-authentication while maintaining security.
2Adaptability or versatility
If thin client devices are used, then flexibility and mobility are improved, but functionality and data processing capability are reduced
Solution Approach 1:
The visualization manager acts as an intermediary between the thin client device and the automation controller. It receives authentication data from the thin client, processes the authentication logic, retrieves visualization content from the automation controller, and delivers it to the thin client. This mediator approach allows thin clients to access complex automation visualizations without needing local processing capability.
Solution Approach 2:
The visualization manager provides universal access to automation visualizations from multiple sources (automation controllers, workstations, servers) through a single platform. It supports various authentication methods (biometric, password, token) and delivers content to different device types (thin clients, mobile devices, traditional HMIs), making the system universally accessible across diverse devices.
3Reliability
If multiple authentication methods are implemented, then security is improved, but system complexity increases
Solution Approach 1:
The system implements different authentication methods (biometric, password, token) based on the specific security requirements and context of each access request. The visualization manager selects and applies the appropriate authentication method locally for each user and device combination, rather than requiring all authentication methods for every access attempt, thus maintaining security while reducing overall system complexity.
Data Source
AI summary
A human interface technique is disclosed for industrial automation systems. The technique allows for visualizations to be distributed to interfaces, such as thin client interfaces, from automation components. For access to the content, a user may be initially authenticated in a first manner, such as by multi-factor authentication. Thereafter, or for a certain time or location, the user may be authenticated by a reduced number of factors, such as single-factor authentication. The authentication may be used to deliver the visualizations based on policies of a visualization manager, such as the user identification, the user role, the user location, and so forth. The reduced factor authentication allow for users to freely move and view visualizations on any available device, or at different locations, and so forth, but still based on the policies.


