Role-Based Variable Publication for Secure External Control Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing development support devices allow unrestricted access to published variables, compromising security in the exchange of data between control devices and external devices.
Innovation Solution
A support device that provides a user interface for specifying roles and settings to control the publication of variables to external devices, allowing users to set read and execute permissions based on roles, and prioritizing settings using instance or function block identification information to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If publication setting is allowed for all variables in a namespace, then data accessibility is improved, but security is worsened
Solution Approach 1:
The patent segments the namespace into multiple groups, where each group contains a subset of variables. Users can selectively publish specific groups to external devices rather than publishing all variables in the namespace. This segmentation allows fine-grained control over data accessibility while maintaining security by limiting exposure to only necessary variables.
Solution Approach 2:
The patent applies different publication settings to different groups within the namespace. Each group can have its own publication status and access permissions, allowing local customization of data accessibility. This enables security-sensitive variables to be excluded from publication while allowing other variables to be accessed freely.
2Object-affected harmful factors
If publication setting is conducted for each variable individually, then security control is improved, but setting complexity is worsened
Solution Approach 1:
The patent merges multiple variables into groups, allowing users to set publication permissions at the group level rather than individually for each variable. This combining approach significantly reduces the number of setting operations required while maintaining fine-grained security control through selective group publication.
Solution Approach 2:
The patent creates publication setting groups that can serve multiple purposes: they can contain variables with similar security requirements, represent functional modules, or group variables by access priority. This multi-functionality allows a single group setting to control access to multiple variables simultaneously, simplifying the overall configuration process.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A support device (100) provides a user interface for allowing a user to conduct a publication setting of a variable to an external device (300), the variable being generated during execution of a user program (230), and generates publication setting information (260) based on the publication setting conducted by the user using the user interface. A control device (200) manages publication of a variable to the external device (300) based on the publication setting information (260), the variable being generated during execution of the user program (230). The publication setting information (260) includes at least one of: information for setting whether or not to permit the external device to read at least one variable according to at least one role; and information for setting whether or not to permit the external device to execute the at least one variable according to the at least one role. The user interface is configured to allow the user to specify one of the at least one role to conduct the publication setting.