Secure Multi-Protocol Field Device Architecture for Direct Client Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing process control systems face complexity in integrating advanced communication protocols like Ethernet and IP-based systems with traditional field devices, leading to inefficiencies and security concerns due to the need for multiple I/O devices and protocols, which hinders seamless communication and effective use of field devices in process control and factory automation.

Innovation Solution

A highly versatile field device capable of operating as a data server, supporting multiple applications and communication protocols, including IP-based protocols, with advanced security features, enabling direct communication with various client devices and systems while performing standard process control functions, and integrating with mixed physical layers and protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple I/O devices are used to support different communication protocols, then compatibility with various field devices is improved, but device complexity increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidnumber of I/O devices
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The field device is designed with multi-functionality to perform both traditional control functions and data server functions. It can simultaneously support multiple communication protocols (HART, Fieldbus, Profibus, Ethernet/IP, Profinet) and serve multiple applications (process control, asset management, predictive maintenance) through a single integrated device architecture, eliminating the need for separate I/O devices for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The field device acts as an intermediary between the process control system and external systems. It includes a data server component that mediates communication between multiple clients (process controllers, asset management systems, predictive maintenance systems) and the field device itself, enabling protocol conversion and data exchange without requiring multiple dedicated I/O devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If field devices communicate directly with multiple client devices, then communication efficiency is improved, but security risks increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The data server component acts as a secure intermediary between the field device and multiple external clients. It implements authentication mechanisms, encrypted communication channels, and access control policies that allow efficient direct communication with multiple clients while maintaining security. The data server mediates all communications, validating client identities and controlling data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different security measures are applied to different communication interfaces and data types. The field device implements protocol-specific security configurations, with tailored authentication and encryption methods for each communication protocol and client type, allowing optimized security for each communication channel while maintaining overall system security.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If field devices perform multiple functions, then system versatility is improved, but device complexity increases

Engineering Contradiction:
Improvefunctional versatilityVSAvoiddevice architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The field device architecture is segmented into distinct functional modules: a control module for traditional process control functions, a data server module for hosting multiple applications, and a communication module for handling multiple protocols. This segmentation allows each module to be independently designed and managed, reducing overall device complexity while maintaining functional versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The field device is designed as a universal platform that can perform multiple functions through software configuration rather than hardware duplication. The same physical device can be configured to serve as a process controller, data server, or combination thereof, depending on the application requirements, reducing complexity by avoiding dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If traditional process controllers handle all communications, then system security is improved, but communication load on controllers increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcontroller performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The data server functionality is extracted from the traditional process controller and embedded directly into the field device. This extraction moves the communication burden from the process controller to the field device's dedicated data server component, reducing the controller's processing load while maintaining security through the field device's built-in authentication and encryption capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11824934B2Security systems for use in implementing highly-versatile field devices and communication networks in control and automation systems
Publication Date: 2023.11.21 FISHER ROSEMOUNT SYST INC
  • US11824934B2 patent drawing
  • US11824934B2 patent drawing
  • US11824934B2 patent drawing

AI summary

A highly versatile process control or factory automation field device is configured with an interface and communication connection structure and security features that enable the field device to operate as a data server that communicates with and supports multiple different applications or clients, either directly or indirectly, while simultaneously performing standard process and factory automation control functions in a highly secure manner. The security features include a root of trust component, a secure boot component, secure memory components, secure communication components, security audit components, secure provisioning components and endpoint identity components, making the field device communications and operations secure and trustworthy. Moreover, various different process control and factory automation network architectures and, in particular, communication architectures, support the versatile field device to enable the versatile field device to simultaneously communicate with multiple different client devices or applications (each associated with a different system) via a common communication network infrastructure in a very secure manner, using the same or different communication protocols.