Segment Access Verification for Distributed Field Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require individual access codes for each field device in distributed systems, leading to security hurdles and inefficient access management.

Innovation Solution

A device and method for verifying access data across multiple field devices within a segment, allowing secure and easy access by checking the access data of all devices in the segment, with the option for temporary access and centralized verification using a security server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual access codes are assigned to each field device, then security level is improved, but ease of operation deteriorates due to the need to enter codes for each device

Engineering Contradiction:
Improvesecurity levelVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the access control functions of multiple field devices into a segment-level access mechanism. Instead of requiring separate access codes for each field device, a single access code at the segment level grants access to all field devices within that segment, thereby improving ease of operation while maintaining security through collective verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a segment controller as an intermediary between the user and multiple field devices. The segment controller manages access control for the entire segment, verifying access codes collectively and mediating access requests to individual field devices, thus eliminating the need for users to enter codes for each device separately.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If segment-level access verification is implemented, then ease of operation is improved, but device complexity increases due to the verification mechanism

Engineering Contradiction:
Improveease of accessVSAvoidverification mechanism complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The segment controller performs self-service by automatically verifying access codes against the segment's access control list without requiring manual intervention or complex external verification systems. This automates the access verification process, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The segment controller is designed with multi-functionality, handling access control for multiple field devices within a single device. This universal approach consolidates what would otherwise require multiple separate access control mechanisms, reducing overall system complexity while providing segment-level access management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access data is verified by all field devices in a segment, then security is improved, but loss of time increases due to multiple verification steps

Engineering Contradiction:
Improvesecurity verificationVSAvoidaccess establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring access control lists at the segment level, storing access codes and associated field device identifiers in advance. When access is requested, the segment controller quickly verifies the access code against this pre-configured data, eliminating the need for real-time complex verification across all field devices and reducing access establishment time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4002038B1Device for protecting access for segments in distributed systems
Publication Date: 2025.09.17 VEGA GRIESHABER GMBH & CO
  • EP4002038B1 patent drawingFigure 1
  • EP4002038B1 patent drawingFigure 2
  • EP4002038B1 patent drawingFigure 3

AI summary

The present invention relates to a device for protecting access to a segment in distributed systems, wherein the device comprises: an input device (10) configured to capture access data for a first field device; a verification device (20) configured to verify the captured access data from a second field device, wherein the first field device and the second field device are coupled to the segment.