Wireless Authentication for Industrial Field Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods in industrial process automation lack sufficient security, especially in wireless communication, due to reliance on weak key codes and shared passwords, which compromises security and management efficiency in large-scale industrial settings.
Innovation Solution
A method for unilateral or mutual authentication using a security policy with unlock keys, where the security policy and unlock keys are separated, allowing for flexible and secure user authorization, including generation of hardware-related and user-specific unlock keys, and asymmetric cryptography for enhanced security, enabling secure access without a central administration system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a 4-digit key code is used for authentication in wireless communication, then operating convenience is optimized, but security is compromised
Solution Approach 1:
The authentication system is segmented into multiple independent components: a first unit (mobile device) and a second unit (field device), each performing specific authentication functions. This segmentation allows the mobile device to handle complex authentication operations while the field device maintains simple verification, resolving the contradiction between ease of operation and security.
Solution Approach 2:
The mobile device acts as an intermediary between the user and the field device. It generates and manages unlock keys, performs cryptographic operations, and communicates authentication results to the field device. This intermediary role enables strong security through cryptographic mechanisms while maintaining user convenience through the mobile device's interface.
2Ease of operation
If shared passwords are used for authentication in industrial settings, then ease of access is improved, but security and management efficiency deteriorate
Solution Approach 1:
Each user is assigned a unique unlock key with specific authorization levels tailored to their role and requirements. Instead of uniform shared passwords, the system implements localized authentication credentials that provide appropriate access rights for each user, improving both security and management efficiency while maintaining ease of access through automated verification.
Solution Approach 2:
The authentication system transitions from static shared passwords to dynamic unlock keys that can be generated, modified, and revoked independently for each user. This parameter change enables flexible authorization management where access rights can be adjusted without affecting other users, resolving the contradiction between ease of access and security management.
3Device complexity
If authentication information is stored centrally, then management is simplified, but system availability deteriorates when central control is unavailable
Solution Approach 1:
The mobile device performs preliminary authentication actions by generating unlock keys and verifying authorization before the field device processes requests. This preliminary verification ensures that authentication can proceed without requiring continuous connection to a central control system, maintaining system availability while keeping management simple through pre-configured authorization rules.
Solution Approach 2:
The mobile device serves multiple functions: it acts as an authentication client, generates unlock keys, stores authorization information locally, and communicates with field devices. This multi-functionality eliminates the need for a central control system for basic authentication operations, ensuring system availability while maintaining manageable security through the mobile device's capabilities.
4Adaptability or versatility
If software modification is performed on individual field devices for user authorizations, then customization is improved, but device complexity and maintenance burden increase
Solution Approach 1:
The authentication and authorization logic is extracted from the field devices and relocated to the mobile device. The field devices only need to implement simple verification of unlock keys, while all complex authentication operations, user management, and authorization decisions are performed by the mobile device. This extraction maintains customization capabilities while significantly reducing device complexity and maintenance burden on field devices.
Solution Approach 2:
Instead of modifying field devices to handle complex authentication and user management, the system inverts the approach by making the mobile device the intelligent authentication partner. The mobile device adapts to different field devices and users, providing customization without requiring modifications to the field devices themselves, thus reducing their complexity and maintenance requirements.
Data Source
AI summary
A method for unilaterally or mutually authenticating at least one first unit, especially a mobile device, on at least one second unit, especially a field device, within a plant, especially in the area of process automation technology, with a communication line, preferably a wireless communication line, in place between the first unit and the second unit, comprising the steps of: establishing a security policy, with the security policy including rules for granting access of the first unit on the basis of at least one unlock key, and information to check the unlock key for validity; providing the security policy to the second unit; generating an unlock key for the first unit and providing the unlock key at the first unit; transfer of the unlock key from the first unit to the second unit and verification of the unlock key by the second unit using the security policy and, if applicable, granting access. Furthermore, a computer program product executes the method and a machine-readable data carrier includes the computer program product.


