Method for the access control to an automation unit
Abstract
Procedure for access control to an automation installation, in which the access rights prescribed by the access control depend on the service status of the automation installation (01), characterized in that at least in an emergency case, independently of access rights in normal operation, extended access rights are granted.

Term
1.9 yearsto projected expiry
Projected expiry 28 August 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
27 claims: 8 independent, 19 dependent
- 1ES 2 368 670 T3 ES 2 368 670 T3 CLAIMS REIVINDICACIONES 1. Procedure for controlling access to an automation installation, in which the access rights prescribed by the access control depend on the operating state of the automation installation (01), characterized in that at least in an emergency case, independently of the access rights in normal operation, extended access rights are granted. 1. Procedimiento para el control de accesos a una instalación de automatización, en el que los derechos de acceso prescritos por el control de acceso dependen del estado de servicio de la instalación de automatización (01), caracterizado porque al menos en un caso de emergencia, independientemente de los derechos de acceso en funcionamiento normal, se otorgan derechos de acceso ampliados.
- 5Method according to one of the preceding claims, characterized in that an emergency is triggered automatically as soon as certain process variables of the automation system (01) exceed the prescribed limit values. 5. Procedimiento según una de las reivindicaciones precedentes, caracterizado porque se activa automáticamente un caso de emergencia tan pronto como determinadas magnitudes de proceso de la instalación de automatización (01) sobrepasan los valores límite prescritos.
- 7Method according to one of the preceding claims, characterized in that the access rights are strictly fixed in the normal case, in order to avoid incorrect operations and unauthorized access. 7. Procedimiento según una de las reivindicaciones precedentes, caracterizado porque los derechos de acceso se fijan de manera estricta en caso normal, para evitar operaciones incorrectas y accesos no autorizados.
- 8Method according to one of the preceding claims, characterized in that the access rights are set in normal role-based operation. 8. Procedimiento según una de las reivindicaciones precedentes, caracterizado porque los derechos de acceso se fijan en funcionamiento normal basados en roles.
- 9Method according to one of the preceding claims, characterized in that in normal operation, to obtain access rights and / or to obtain additional access rights and / or other access rights, an identification of the person accessing or an authentication is carried out. 9. Procedimiento según una de las reivindicaciones precedentes, caracterizado porque en funcionamiento normal, para lograr derechos de acceso y/o para lograr derechos de acceso adicionales y/u otros derechos de acceso, se realiza una identificación de la persona que accede o bien una autentificación.
- 10Method according to one of the preceding claims, characterized in that when an emergency occurs, an alarm is activated to automatically raise the alarm and activate emergency measures. 10. Procedimiento según una de las reivindicaciones precedentes, caracterizado porque al presentarse un caso de emergencia se activa una alarma para dar automáticamente la alarma y activar medidas de emergencia.
- 11Procedimiento según una de las reivindicaciones precedentes, caracterizado porque al menos en un caso de emergencia se registran y/o protocolizan las acciones y accesos realizados por un personal de operación y mantenimiento (12). eleven. Method according to one of the preceding claims, characterized in that at least in an emergency case the actions and accesses carried out by an operation and maintenance personnel (12) are recorded and / or logged.
- 12Method according to one of the preceding claims, characterized in that at least in an emergency case a special security mode is provided for emergencies, in which the harsh control and granting of access rights provided for normal operation are replaced by measures softer, which can be evaluated or evaluated a posteriori. 12. Procedimiento según una de las reivindicaciones precedentes, caracterizado porque al menos en un caso de emergencia está previsto un modo de seguridad especial para casos de emergencia, en el que se sustituyen el duro control y otorgamiento de derechos de acceso previsto para el funcionamiento normal por medidas más suaves, que pueden evaluarse o bien se evalúan a posteriori.
Independent claims8
60 paragraphs in 5 sections, as filed
ES 2 368 670 T3
DESCRIPTION
Procedure for controlling access to an automation installation
With the introduction of information technology (IT) in automation and with the increasing integration with office environments, the need for security solutions for automation environments also increases. Access control is therefore an essential security functionality, by means of which it is established and imposed who can perform what operations. Thus, for example, it can be determined which accesses the operating personnel can make to operate and observe a process or a manufacturing process or a continuous or manufacturing process.
Three main columns of IT security are confidentiality, integrity, and availability. Referring to typical office environments, most of the time the confidentiality and integrity of the data play the main role. In the automation environment, however, availability is more important than data confidentiality. Usually it is not about very secret data, but mainly about the transmission of control and status orders through the network.
Due to the application environment, special marginal conditions must be taken into account there. For example, in an automation environment in continuous process technology, a manufacturing process should not be stopped in such a simple way / in the process industry a physical process, such as heating and stirring an adhesive in a case of security emergency in the control of the facility. Similarly, the reverse should not be prevented in an emergency, for example in an overheating of the adhesive, an intervention by the service personnel by means of IT security measures. Strictly enforced access rights, as is desirable from an IT security point of view, should not result in the necessary manual interventions being prevented or unnecessarily hindered in such an emergency.
Role Based Access Control (RBAC) is well known. In practice, this is often only understood as role-based access rights management. Groups are then defined based on the tasks presented. Access rights are assigned to different groups. The various collaborators are assigned to the groups corresponding to their tasks and thus receive the necessary access rights for their task.
Considered from the theoretical point of view, RBAC means that a certain collaborator assumes different tasks at different times and correspondingly at different times assumes different roles. If the collaborator's tasks vary between several moments, he executes a change of role in each case, to receive the access rights associated with the role assumed at all times.
From EP 1621 944 A2 a method for controlling access to an automation installation is known, in which the access rights prescribed by the access control depend on the operating state of the automation installation.
By Covington et al. Securing Context-Aware Applications Using Environment Roles ”, Proceedings of the 6th ACM Symposium on Access Control Models and Technologies, Chantilly, Virginia, United States, pp. 10-20, 2001, ISBN: 1-58113-350-2 is also known an access control based on the context in the care and surveillance of the elderly at home, in which access rights depend on information from context also called environment information. This context information refers to the time of day, day of the week, place of stay, or the current status of a job stream. Access rights are assigned to certain environment roles. The different environment roles can be activated by context information. An environment role activation can automatically activate an action. For example, when there is an activation of the violation environment role, an emergency call is automatically established.
It can be considered as a task of the invention to provide an access control better adapted to an automation environment.
The task is solved according to the invention by the features of claim 1.
A method corresponding to the invention for access control in an automation installation provides that the access rights prescribed by the access control depend on the operating state of the automation installation, being granted at least in an emergency, regardless of access rights in normal operation, access rights broader than those in normal operation.
By granting at least emergency access with extended access rights, fast and flexible operation is enabled, which is not unnecessarily impeded or hampered by IT security measures.
ES 2 368 670 T3
The invention has advantages over the state of the art in particular since, for the regular operating service of the automation installation, restrictive access rights can be established according to the needs of regular operation. For special operating states, in particular in an emergency, correspondingly extended access rights are granted.
Roles are basically defined that correspond to the different operating states of an automation installation. A change of roles is not carried out freely as in RBAC, but the access rights depend on the state of service. In normal operation a high level of security is achieved and restrictive access rights can be set, since only in a special operating state, such as in maintenance work or in an emergency, are extended access rights granted, which they are then necessary. This can also be seen as a certain mode of override functionality, in which under certain circumstances the control of access rights can be taken out of service.
In addition, the management of access rights is simplified, as only the access rights have to be set exactly and strictly for normal operation. In special situations, extended access rights are granted under the assumption that the qualified and trusted personnel who perform the operation and maintenance do not abuse access rights under such circumstances. This confidence is based on the fact that in any case there is a high responsibility of the operation and maintenance personnel, since they must carry out maintenance tasks, such as changing tools or calibration or a controlled stop of a continuous process, which does not is it automated or not fully automated.
An advantageous embodiment of the invention provides that the automation installation is monitored in order to detect the operating state. Monitoring can be done by suitable sensors or by operation and maintenance personnel.
An emergency case is preferably triggered automatically as soon as certain process variables of the automation system exceed specified limit values. Likewise, it is possible to think about manually activating an emergency case by the operation and surveillance personnel.
An advantageous configuration of the invention provides that access rights are strictly set for normal operation, to avoid incorrect operations and unauthorized access.
Another advantageous embodiment of the invention provides that access rights are determined for normal operation based on roles.
Another advantageous configuration of the invention provides that for normal operation, to obtain access rights and / or to obtain additional access rights and / or other access rights, an identification of the person accessing or an authentication is carried out, for example through a log-in (access) protocol. The log-in protocol can have any configuration, for example by entering the user's name and / or password, by means of an authentication token (validator), such as by means of a chip card or wirelessly, or by means of a fingerprint. or any other biometric identification.
A further advantageous configuration of the invention provides that when an emergency occurs an alarm is activated, to automatically give the alarm and activate emergency measures, for example so that the intervention forces can confirm the emergency case.
A particularly advantageous configuration of the invention provides that, at least during an emergency case or in a service case for which extended access rights are granted, the actions and accesses carried out by the operation and maintenance personnel are recorded by for example by a video camera and / or protocolized for example in a logging or access server. Access rights can thus be exceeded if necessary, to a certain extent as desired. But this is evident both through the recording and logging of the accesses carried out and also through the activation of video surveillance and it can thus be subsequently verified whether this actually took place on a justified basis.
An advantageous configuration of the invention provides that at least in an emergency case a special security mode is provided for emergencies, in which the harsh and strict controls and granting of access rights provided for normal operation are replaced by measures softer, which can nevertheless be evaluated or evaluated later. The replacement of harsh security measures in force during normal operation by softer security measures in an emergency makes it possible for the operation and surveillance personnel to carry out all the necessary measures, nevertheless avoiding abuse, since the fact of the activation of the emergency case, as well as the actions carried out and the accesses carried out, can be reproduced later.
ES 2 368 670 T3
Preferably the softer measures include the granting of extended access rights and / or, if necessary, a deactivation of the control and granting of access rights, thus allowing all operations and accesses.
Alternatively, softer measures can be considered to include a waiver of authentication, for example by log-in, whereby anyone can use an operation and surveillance team that controls the automation installation.
For the subsequent evaluation of the gentler measures, a registration and protocolization of the accesses carried out is preferably carried out. This can be done on the operation and surveillance equipment itself or on a logging server expressly provided for this, for example housed in an emergency resistant room, for example safe against fire and / or explosion.
For the subsequent evaluation of the gentlest measures, for example, an activation of a video surveillance or an activation of a video recording can be carried out, thus detecting based on the recorded video material who has activated the emergency security mode and who has made what accesses or actions.
The emergency security mode preferably includes several levels with different access rights, which can be activated or activated step by step. Since possibly minimally increased access rights are already sufficient to protect yourself practically as a first aid from the worst case in an emergency, the emergency security mode preferably includes several steps. These can be activated step by step. In a first step of activation for emergencies, for example, only the most necessary rights can be granted, for example to delay an imminent emergency and to be able to initiate simple countermeasures. In the event that more extensive measures are required to prevent the emergency event, then a second emergency trigger stage must also be additionally activated, which grants a wider, eg unlimited access. For example, it can be envisaged that durable configuration modifications can then also be carried out. The activation of such a second emergency activation stage can then be protected more costly than the first emergency activation stage. Thus, for example, it is possible to activate the first activation stage for emergencies by means of a mouse click at the user level of the operating and monitoring equipment and the second activation stage for emergencies only by means of a physical safety switch. which, for example, can only be activated after breaking a protective glass.
Activation of the safety mode for emergencies can be done manually, for example by pressing a special button on a graphical operating level. To prevent the activation of the emergency safety mode for convenience during regular operational service, a special button is provided for this on a graphic operating level, by means of which a manual change to the emergency safety mode is performed. The manual change in the emergency security mode can then be accessible to all collaborators, or only to certain authenticated collaborators, for example only to the supervisor (s).
Alternatively, a manual activation of the emergency safety mode can be performed by actuating a physical safety switch. Such a physical safety switch can be, for example, a key switch, or a push-button with a break glass, as is known, for example, in fire alarms, or two switches that are spatially far apart, which should preferably be actuated by at least two people at the same time. In the latter case, both switches can be housed in the automation installation, but at such a distance that they cannot be operated by a single person at the same time. Both switches can also be arranged spatially separated such that one switch is housed, for example, in the automation installation itself and the second switch in a remote security center.
The physical switch may be coupled with a fire or alarm button, whereby when additionally actuated an alarm is issued, for example to factory firefighters.
In addition, it can be considered that a manual activation of the security mode for emergency cases is carried out by means of a special log-in protocol, for example the introduction of a special password for emergency cases or the use of a special token (validator) authentication for emergencies, such as a chip card for emergencies.
The activation of the emergency safety mode is preferably carried out automatically depending on the operating status of the automation system. To do this, certain parameters of the automation system are monitored and it is decided, for example automatically by comparison with prescribed limit values for these parameters, whether there is a normal operating state or an emergency. In systems for automation of continuous processes, for example pressure and temperature can be measured using suitable sensors, preferably arranged redundantly, and monitored automatically by comparison with set limit values, such as a maximum permissible temperature, a maximum permissible pressure, a
ES 2 368 670 T3 minimum temperature, a minimum pressure and determining whether the measured values for pressure and temperature in the automation installation meet when a certain continuous process is carried out within a certain permissible operating range, i.e. if there is a case of normal service or not, that is, an emergency case. Alternatively, the rotational speed of the motor can also be monitored and compared with fixed setpoints.
The emergency safety mode can remain after activation until it is manually deactivated again, for example by flipping a switch or the like.
Alternatively, it can be envisaged that the emergency security mode is automatically deactivated again after being activated after a predetermined period of time.
Likewise, the emergency safety mode can be automatically deactivated after activation after the emergency has ended, for example when the measured values captured by sensors are again within a permissible service area.
In addition, it can be considered that the security mode for emergencies only remains active as long as the corresponding activation switch or the like is activated or kept activated.
The invention will be described below on the basis of an exemplary embodiment represented in the drawing. Shown in:
Figure 1 a schematic representation of an automation installation.
An automation installation 01 represented in FIG. 1 includes an agitator 02 that is driven by a motor 03. The agitator 02 agitates a substance in a container 04. In the container 04 there is a heater 05 and a temperature sensor 06, being both linked with a process computer 07. The pipes for transporting the substance to and from the container 04 are not shown. The process computer 07 is connected to an operation and monitoring equipment 08. The operation and monitoring equipment 08 is connected to an emergency switch 09, a video camera 10 as well as a logging server 11. The operation and maintenance personnel 12 monitor and control the continuous process of stirring the substance in the container. 04 through the operation and surveillance team 08. In the event of an incident or emergency, the operation and maintenance personnel 12 actuate the emergency switch 09, following which the operation and maintenance personnel 12 are given unlimited access rights and thus unlimited access. However, at the same time, the actions taken by the operation and maintenance personnel 12 and the accesses by the video camera 10 are recorded and recorded on the logging server 11.
Within the framework of the invention, a strict access control is implemented for the regular operation of an automation installation with an operation and surveillance team, in which the operating personnel must be authenticated, for example by log-in and can only be make access to the operation and surveillance equipment that is also allowed based on a defined access control policy. The object is then less to achieve high confidentiality of the transmitted automation data than to avoid incorrect operations and unauthorized access. The log-in protocol can be configured in any way, for example by entering the user number and / or the password, by means of an automation token or validator, such as by means of a chip card, or wirelessly, or by means of a fingerprint or any other biometric identification.
In order to be able to react appropriately in emergencies, which can naturally include unforeseeable aspects, extended access rights are necessary there. Within the framework of the invention, extended access rights are granted in emergencies. A fast and flexible handling is thus possible, which is not impeded or unnecessarily hampered by IT security measures.
A special security mode for emergencies / a special security configuration for emergencies is provided for this.
The access control provided for normal operation or regular service is then replaced by softer measures, which can nevertheless be evaluated a posteriori:
Granting extended access rights and / or, where appropriate, deactivation of access control, thereby allowing all access.
It renounces to the authentication for example by means of log-in, with what anyone can use the equipment of operation and monitoring.
Registration and protocolization of the accesses made, the so-called logging. This can be done on the operating and monitoring equipment itself or on a logging server specially provided for this, for example housed in an emergency-resistant room, for example fire-safe and / or explosion-safe.
ES 2 368 670 T3
Activation of a video surveillance or activation of a video record, to thus detect, based on the recorded video material, who has activated the security mode for emergencies and who has made what accesses or actions.
Activation of an alarm, so that the intervention forces can confirm the case of emergency.
The replacement of strict security measures valid during normal operation with softer security measures in an emergency, enables the operation and surveillance personnel to take all the necessary measures. However, abuse is prevented, since the act of activating the emergency case, as well as the actions taken and the accesses made, can be reproduced a posteriori.
Access rights can thus be exceeded if necessary, to a certain extent as desired. However, this is detected, both through the recording and protocolization of the accesses made, as well as by activating a video surveillance and it can thus be verified a posteriori whether this was actually carried out on a justified basis.
Since slightly higher access rights are eventually sufficient to be able to prevent, practically as a first aid, the worst that can happen in an emergency, the emergency security mode can include several steps. These can be activated step by step. In a first stage of activation for emergencies, for example, only the very necessary rights can be granted, for example to delay an imminent emergency and initiate simple countermeasures. In the event that broader measures are necessary to prevent an emergency, a second emergency activation stage must then be activated, which grants broader, for example, unlimited access. For example, it can be envisaged that long-lasting configuration changes are also made then. The activation of such a second emergency activation stage can then be protected more costly than the first emergency activation stage. For example, it can be thought that the first activation stage for emergencies can be activated by means of a mouse click at the user level of the operation and monitoring device and the second activation stage for emergencies only by means of a safety switch. physical, which for example can only be activated after breaking a protection glass.
Switching to emergency security mode can be done in a number of ways. In this regard it is important that the special meaning is clear and therefore an activation for convenience is avoided during regular operational operation.
A first variant that ensures that an activation of the safety mode for emergencies is avoided for convenience during regular operating operation can be achieved for example on the basis of a special button on a graphical operating level, by means of which activation a manual change is carried out. to safety mode for emergencies. The manual switch to emergency security mode can then be accessible for all collaborators or only for certain authenticated collaborators, for example only for the supervisor (s).
A second variant which ensures that an activation of the emergency safety mode is avoided for convenience during regular operational operation is the use of a physical safety switch to activate the emergency safety mode. Such a physical safety switch can be, for example, a key switch, or a push-button with break glass, as is known for example in fire alarms, or two switches that are spatially far apart, which must be actuated by at least two people preferably at the same time. In the latter case, both switches can be housed in the automation installation, but at such a distance that they cannot be operated by a single person at the same time. Both switches can also be arranged spatially separated such that one switch is housed, for example, in the automation installation itself and the second switch in a remote security center. The physical safety switches described may be coupled with a genuine button for fire or alarm, whereby when actuated an alarm is additionally emitted, for example for factory firefighters.
A third variant which ensures that an activation of the emergency safety mode is avoided for convenience during regular operational operation provides for a special log-in protocol, for example the introduction of a special password for emergency cases or the use of a special authentication token for emergencies, such as an emergency chip card.
A fourth variant which ensures that an activation of the emergency safety mode is avoided for convenience during regular operational operation, automatically depends on the operating state of the automation installation. For this, certain parameters of the automation system are monitored and a decision is made automatically, for example by comparing with prescribed limit values for these parameters, whether there is a normal operating state or an emergency. In systems for automation of continuous processes, for example, pressure and temperature can be measured by suitable sensors, preferably redundantly arranged, monitored and by comparison with set limit values, such as a maximum permissible temperature, a maximum permissible pressure, a minimum, minimum pressure, automatically and
ES 2 368 670 T3 determining whether the measured values for pressure and temperature in the automation installation are found when a certain continuous process is carried out within a certain permissible service area, that is, if there is a normal operating case or not, that is, an emergency case.
The emergency safety mode either remains permanently after activation until it is deactivated manually, for example by actuating a switch or the like, or it is deactivated automatically after a certain prescribed period of time. The emergency safety mode can also be deactivated automatically after the emergency disappears, for example when the measured values captured by sensors are again within the permissible operating range. As an additional possibility, it can be considered that the safety mode for emergencies only remains activated until the corresponding activation switch or the like is activated or remains activated.
Contents5
1 sheet
Sheet 1
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 102007045772 | Germany | A | |
| 102007045772 | Germany | A | |
| 102007045772 | Germany | – | |
| DE20071045772 | – | – | – |
Numbers
- Publication
- 2368670
- Publication, DOCDB
- 2368670
- Publication, EPODOC
- ES2368670T
- Application
- 8803303
- Application, DOCDB
- 08803303
- Application, EPODOC
- ES20080803303T
Titles2
- Spanish
- PROCEDIMIENTO PARA EL CONTROL DEL ACCESO A UNA INSTALACION DE AUTOMATIZACION.
- English
- PROCEDURE FOR CONTROLLING ACCESS TO AN AUTOMATION INSTALLATION.
Classification
- CPC, 2
- G05B19/042
- G05B2219/24159
- IPC, 1
- G05B19 042