Portable Terminal Access Control for Automation Field Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control methods for field devices in automation systems are cumbersome, especially for older devices lacking necessary interfaces, and require physical authentication tools like USB sticks or smart cards, which can be inconvenient and prone to errors.

Innovation Solution

A method utilizing a portable communication device, such as a smartphone, to authenticate users by photographing QR codes or one-dimensional barcodes, which sends identifying information to a server for access authorization, eliminating the need for physical interfaces and enabling central management of access data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If USB sticks or smart cards are used for authentication, then access control is enabled, but physical interfaces are required and users must carry additional tools

Engineering Contradiction:
Improveaccess controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The portable communication device serves multiple functions: it acts as both the authentication credential holder and the communication interface. The device uses its existing communication capabilities (SMS, email, instant messaging) to transmit authentication codes, eliminating the need for separate physical authentication tools and interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces physical mechanical interfaces (USB ports, smart card readers) with wireless communication channels. Authentication codes are transmitted electronically through communication networks, substituting the mechanical insertion and connection processes with remote digital communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical interfaces are required for authentication, then secure access is achieved, but older field devices without suitable interfaces cannot be accessed

Engineering Contradiction:
Improveaccess securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system utilizes communication functions that are universally available on portable devices, making it compatible with field devices regardless of their physical interface capabilities. The method works across different device generations by relying on communication protocols rather than specific hardware interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Wireless communication channels replace physical mechanical interfaces, enabling authentication on field devices that lack USB ports or smart card readers. The substitution allows older devices to be accessed without requiring physical interface upgrades or modifications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2859705B1Authorising a user by means of a portable communications terminal
Publication Date: 2019.09.04 SIEMENS AG
  • EP2859705B1 patent drawingFigure 1~2
  • EP2859705B1 patent drawingFigure 3

AI summary

The invention relates to a method and an access control system for user authorisation by means of a portable communications terminal on a field device. By acquiring information via the field device and the portable communications terminal, access information is determined for the user and access is granted to said field device if the access information matches. This method for authorising a user with the aid of a portable communications terminal represents a simplified method for role-based access control in the context of automation installations which makes use of the advantages of mobile communication technology such as, for example, the adoption of QR codes and short messages by SMS. At the same time, secured access information is determined using one-way functions, and security is therefore increased within the context of installation or energy automation.