Temporary Key Access for Hydrocarbon Field Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hydrocarbon site control systems face challenges in securely and efficiently managing access to field devices, particularly in ensuring timely and authorized access for technicians.

Innovation Solution

A hydrocarbon control system that includes a base device, a field device, and a mobile device, where the base device generates a temporary key, and the mobile device communicates with both the base and field devices to provide the key for access, with the access being restricted or allowed based on verification of the key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control systems are used for field devices, then security is maintained through centralized control, but access efficiency and responsiveness are reduced due to communication delays and system complexity

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system divides access control functionality into segments: the base device generates temporary keys, mobile devices hold and present keys, and field devices verify keys. This segmentation allows each component to operate independently with simplified logic, improving access efficiency while maintaining security without requiring complex centralized coordination for every access event.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The base device generates and distributes temporary access keys to mobile devices in advance, before the actual access event occurs. This preliminary action enables technicians to have immediate access capability when approaching field devices, eliminating communication delays with the central system during critical access moments, thus improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If centralized access control is implemented, then security management is simplified, but access time and responsiveness to field operations are increased

Engineering Contradiction:
Improveaccess timeVSAvoidsecurity management
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

Temporary access keys serve as intermediaries between the centralized base device and distributed field devices. The keys encapsulate authorization information locally, enabling field devices to verify access rights without real-time communication with the central system. This reduces access time significantly while maintaining security management reliability through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The base device creates copies of access authorization in the form of temporary keys that are distributed to mobile devices. These key copies contain sufficient information for field devices to verify access rights independently, eliminating the need for continuous centralized verification and thus reducing access time while preserving security through cryptographic design.

Inventive Principle:
Principle #26Copying

3Reliability

If permanent access credentials are used, then authentication is simplified, but security risk from compromised credentials and unauthorized access increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses dynamic temporary keys that are valid only for specific time periods and purposes, replacing static permanent credentials. These keys automatically expire or become invalid after use, limiting the window of opportunity for unauthorized access. This dynamic approach enhances security while the automated key lifecycle management reduces access management complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs disposable temporary keys that are generated for specific access events and discarded after use or expiration. Unlike permanent credentials that remain valid indefinitely, these short-lived keys minimize security risk if compromised, as their utility is limited to a narrow time window. The automated generation and management of these disposable keys simplifies overall access management.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12273716B2Systems and methods for security of a hydrocarbon system
Publication Date: 2025.04.08 ROCKWELL AUTOMATION TECH INC
  • US12273716B2 patent drawing
  • US12273716B2 patent drawing
  • US12273716B2 patent drawing

AI summary

A hydrocarbon control system includes a base device, a field device, and a mobile device. The base device includes a key generator configured to generate a temporary key. The field device is configured to restrict or allow access based on verification of a received key. The mobile device is configured to communicate with the base device to receive the temporary key when in proximity of the base device, communicate with the field device to provide the temporary key to the field device when in proximity of the field device, and exchange data with the field device in response to the field device verifying the temporary key.