Two-Factor Authentication for Process Plant User Interface Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In process control systems, especially in chemical and petroleum plants, there is a lack of authentication mechanisms for handheld or portable computing devices used to configure and operate plant assets, allowing unauthorized personnel to access and modify critical equipment.

Innovation Solution

Implementing a two-factor authentication system on user interface devices that receive both physical identification information, such as RFID tags, and knowledge-based information, like usernames and passwords, to verify user identity and authorize access to plant assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication mechanisms are implemented on handheld computing devices, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two distinct factors: something the user possesses (identification device such as RFID card, smartphone, or key fob) and something the user knows (password or PIN). This segmentation allows the system to distribute authentication requirements across separate components, improving security without requiring a single complex authentication mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication module that mediates between the user's identification device and the handheld computing device. This intermediary layer verifies both the possession-based identifier and knowledge-based password, then grants or denies access accordingly. The intermediary simplifies the overall system architecture by centralizing authentication logic in a manageable component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If two-factor authentication is required, then access control reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidauthentication process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary verification of the identification device (possession factor) before prompting for the password (knowledge factor). This preliminary action allows the system to quickly reject unauthorized devices without requiring users to enter passwords, thereby maintaining ease of operation for authorized users while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system is designed to be self-serve through automatic verification processes. Once the user presents their identification device and enters their password, the system automatically verifies both factors and grants access without requiring manual approval or complex user actions. This self-service approach minimizes operational burden while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10554644B2Two-factor authentication for user interface devices in a process plant
Publication Date: 2020.02.04 FISHER ROSEMOUNT SYST INC
  • US10554644B2 patent drawing
  • US10554644B2 patent drawing
  • US10554644B2 patent drawing

AI summary

Techniques for performing two-factor authentication in a process plant include receiving, at a user interface device, a first type of identification information for a user from an identification device or a physical trait of the user. The user interface device also receives a second type of identification information for the user from knowledge-based information provided by the user. The user interface device then determines that each type of identification information corresponds to the same authorized user within the process plant. When both types of identification information are for the same authorized user, the user is granted access to the user interface device. Accordingly, the user may execute functions on the user interface device to perform operations on a plant asset which is connected to the user interface device.