WO2014094983A1

Commissioning system and method for a secure exchange of sensitive information for the commissioning and configuring of technical equipment

Abstract

The invention relates to a commissioning system and a method for a secure exchange of sensitive information of technical equipment, in particular field devices, comprising at least two components and/or devices, in particular field devices, communicating wirelessly, thereby using communication means to secure the wireless communication without the need to use higher protocol layers, like in particular authentication or encryption functionalities, wherein the communication means provide and ensure near-range communication, in particular by restricting communication signals to a secure area and determining if a device is within a certain area and allow communication if it is or refuse to communicate if it is not within said area.

WO2014094983A1, drawing sheet 1
Sheet 1 of 1

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

28 claims: 24 independent, 4 dependent

  1. 1
    Claims 1. Commissioning system for a secure exchange of sensitive information for the commissioning and configuring of technical equipment comprising at least two components and/or devices, in particular field devices, communicating wirelessly, thereby using communication means to secure the wireless communication, in particular without the need to use higher protocol layers, like in particular authentication or encryption functionalities, wherein the communication means provide and ensure near-range communication, in particular by restricting communication signals to a secure area and determining if a device is within a certain area and allow communication if it is or refuse to communicate if it is not within said area.
  2. 3
    System according to one of the preceding claims, characterized in that the communication means to secure wireless communication comprise properties of a physical layer and/or link layer and/or measurements.
  3. 4
    System according to one of the preceding claims, characterized in that identification means are provided, which use device identification information to determine the trustworthiness of a communication partner.
  4. 5
    System according to one of the preceding claims, characterized in that verification means are provided, which introduce a verification step executed by a human to yet increase the attained level of security.
  5. 6
    System according to one of the preceding claims, characterized in that the radio transmissions in the physical layer are influenced without any modification to the field device to restrict the transmissions to a secure area by various means and at least one of setting transmission power to a level sufficiently high for local communication but low enough so communication cannot be overheard from outside of the commissioning area;encasing at least the antenna, if not the entire device, of device and gateway in a common, shielded housing;restricting the radio direction of device and gateway by shields/reflectors which are not part of the device but for the gateway may be part of a static gateway setup.
  6. 7
    System according to one of the preceding claims characterized in that at least one wireless connection comprises communication means which provide or include a commissioning network, in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multi-drop wired modem, wherein said dedicated commissioning network, in particular a WirelessHART Network, uses a well-known Network ID and a shared Join Key and which network is not used for any production purpose, and wherein the devices joined in this network are visible to the integration component for the wireless network implemented by the gateway, for example an FDT communication DTM or an FDI communication device or server, in the same manner as devices connected to an FSK modem, thus any such device may be assigned to the target network and/or to secure this process, the identification information, in particular the device type, the manufacturer, the serial number or the like, or the device proximity to the commissioning network is used by man or machine to check the legitimacy of the device, wherein the latter is achieved by evaluating receive signal levels and used transmission energy.
  7. 8
    System according to one of the preceding claims, characterized in that the commissioning network is shared between all Communication DTMs, wherein device assignment is a manual task and accordingly not more than one such DTM might be opened at a time and communicates with the gateway.
  8. 9
    System according to one of the preceding claims, characterized in that the commissioning network comprises at least one gateway, wherein the at least one gateway comprises an antenna, which is enclosed in a radio-shielded tube, in particular made of plastic with embedded metal mesh, and/or connected via cable and/or a wired connection to the gateway.
  9. 11
    System according to one of the preceding claims, characterized in that infrared connections and/or radio frequency identification connections and near- range communication is supported and provided, wherein a handheld or an engineering client is equipped with a corresponding interface and accordingly information can be exchanged securely.
  10. 12
    System according to one of the preceding claims, characterized in that a RFID key storage is provided, wherein an RFID chip stores the join key, which may be read from the chip but only from about half a meter of distance, what is very secure in view of the risk of being tapped or intercepted, wherein device exchange on location is possible without any connection to the device management system because the handheld can read the key from the old device and download it into the replacement device.
  11. 13
    System according to one of the preceding claims, characterized in that identification means are provided, which uses device identification information to determine the trustworthiness of a communication device and/or communication partner.
  12. 14
    System according to one of the preceding claims, characterized in that a verification step executable by a human is provided and introduced to yet increase the attained level of security.
  13. 15
    System according to one of the preceding claims, characterized in that the radio transmissions and/or the physical layer are influenced without any modification to the respective field device to restrict the transmissions to a secure area.
  14. 16
    System according to one of the preceding claims, characterized in that a security information device is provided that stores security information for one or more field devices according to a standardized fieldbus protocol, with standardized or proprietary interfaces toward the field-devices and toward a DCS, only revealing security information only to the at least one device or DCS but not to one or more users.
  15. 18
    System according to one of the preceding claims 16 or 17, characterized in that the security information device is capable to generate the security information when connected to the engineering station or engineering client.
  16. 19
    System according to one of the preceding claims 5 to 7, characterized in that the security information device is capable to generate the security information when connected to a field-device.
  17. 20
    System according to one of the preceding claims characterized in that the secure connection or communication is realized by at least one of a. at least one IR connection and/or a RFID connection, wherein the respective RFID chip or tag is integrated into the same packaging as the antenna wire, making it reachable without opening the device and at the same time allowing for a connection to the device electronics to exchange information for use in Ex-zones, b. restriction of i. signal strength of an access point ii. signal strength of a handheld iii. signal expansion from an antenna c. measuring/reading of i. signal strength ii. device type iii. device manufacturer iv. device serial number v. device join time d. a decision component and/or device deciding on the authenticity of the device and the security of the connection by means of i. using any combination of the measured/read data items ii. visualizing the measured/read data items to a user iii. allowing the user to influence the decision and/or making that decision the single mandatory interaction needed to regard a connection as secure.
  18. 21
    Commissioning method for a secure exchange of sensitive information for the commissioning and configuring of technical equipment, in particular of field devices of a process automation system, by use of a system according to one of the preceding claims 1 to 20, whereas a secure wireless communication between at least two components and/or devices, in particular field devices, is provided and established by using communication means to ensure a secure near-range communication by restricting communication signals to a secure area and determining if a device is within a certain area and allow communication if it is or refuse to communicate if it is not, in particular without the need to use higher protocol layers like in particular authentication or encryption functionalities.
  19. 23
    Method according to one of the preceding claims 21 or 22, characterized in that device identification information is used to determine the trustworthiness of a communication partner.
  20. 24
    Method according to one of the preceding claims 21 to 23, characterized in that a verification step is executed, in particular rule-based, to increase the attained level of security.
  21. 25
    Method according to one of the preceding claims 21 to 24, characterized in that the radio transmissions in the physical layer are influenced without any modification to the field device to restrict the transmissions to a secure area by at least one of setting transmission power to a level sufficiently high for local communication but low enough so communication cannot be overheard from outside of the commissioning area;encasing at least the antenna, if not the entire device, of device and gateway in a common, shielded housing and restricting the radio direction of device and gateway by shields/reflectors which are not part of the device but for the gateway may be part of a static gateway setup.
  22. 26
    Method according to one of the preceding claims 21 to 25, characterized in that its applicable to a commissioning network with a wireless gateway and uses a well-known Network ID and a shared Join Key, wherein the devices joined in this network are visible to the respective Communication DTM for the wireless gateway in the same manner as devices connected to an FSK modem, thus any such device may be assigned to the target network and/or to secure this process, the identification information, in particular the device type, the manufacturer, the serial number or the like, or the device proximity to the commissioning network can be used to automatically check the legitimacy of the device, in particular by evaluating receive signal levels and used transmission energy.
  23. 27
    Method according to one of the preceding claims 21 to 26, characterized in that the commissioning network is shared between all Communication DTMs, wherein device assignment is a manual task and accordingly not more than one such DTM might be opened at a time and communicates with the gateway.
  24. 28
    Method according to one of the preceding claims 21 to 27, characterized in that the secure connection or communication is realized and/or carried out by at least one of a. at least one IR connection and/or a RFID connection, wherein the respective RFID chip or tag is integrated into the same packaging as the antenna wire, making it reachable without opening the device and at the same time allowing for a connection to the device electronics to exchange information for use in Ex-zones, b. restriction of i. signal strength of an access point ii. signal strength of a handheld iii. signal expansion from an antenna c. measuring and/or reading of and/or accessing and processing i. signal strength ii. device type iii. device manufacturer iv. device serial number v. device join time d. an automated decision on the authenticity of the device and the security of the connection by means of i. using any combination of the measured/read /accessed and processed data and information items ii. visualizing the measured/read/accessed and/or processed data and information items to a user iii. allowing the user to influence the decision and/or making that decision the single mandatory interaction needed to regard a connection as secure. 9. Process automation system comprising a commissioning system according to one of the preceding claims 1 to 20.
Independent claims24