EP4295201A1 - Steuerungsgerät für ein automatisierungssystem, automatisierungssystem und verfahren zum betreiben eines steuerungsgerät - Google Patents
Steuerungsgerät für ein automatisierungssystem, automatisierungssystem und verfahren zum betreiben eines steuerungsgerätInfo
- Publication number
- EP4295201A1 EP4295201A1 EP22702240.7A EP22702240A EP4295201A1 EP 4295201 A1 EP4295201 A1 EP 4295201A1 EP 22702240 A EP22702240 A EP 22702240A EP 4295201 A1 EP4295201 A1 EP 4295201A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- unit
- data
- control device
- control unit
- system bus
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B19/00—Program-control systems
- G05B19/02—Program-control systems electric
- G05B19/04—Program control other than numerical control, i.e. in sequence controllers or logic controllers
- G05B19/042—Program control other than numerical control, i.e. in sequence controllers or logic controllers using digital processors
- G05B19/0426—Programming the control sequence
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B2219/00—Program-control systems
- G05B2219/20—Pc systems
- G05B2219/24—Pc safety
- G05B2219/24165—Use codes to activate features of controller
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B2219/00—Program-control systems
- G05B2219/20—Pc systems
- G05B2219/25—Pc structure of the system
- G05B2219/25166—USB, firewire, ieee-1394
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B2219/00—Program-control systems
- G05B2219/20—Pc systems
- G05B2219/25—Pc structure of the system
- G05B2219/25346—Several operating systems in one device
Definitions
- Control device for an automation system, automation system and method for operating a control device
- the invention relates to a control device for an automation system, comprising a system bus interface for communication via a system bus with at least one field device and a control unit for controlling the at least one field device.
- the invention also relates to an automation system and a method for operating a control device.
- a system of automation components and an associated operating method are known from DE 102017 005768 A1.
- the system has a control unit that includes a memory area that contains a parameter data set.
- EP 3215899 B1 discloses a method for operating an industrial plant which includes a control system.
- the control system has a controller and a converter connected to the controller for data exchange.
- the document DE 102011 086726 B4 discloses an automation system which includes a control system server, a control device and a field device.
- the control device and the field device communicate via a fieldbus network, the control system server and the control device communicate via a control network.
- a device and a method for providing at least one secure cryptographic key for the cryptographic protection of data initiated by a control unit are known from EP 3525390 A1.
- the device has a configuration unit.
- DE 202016 105474 U1 discloses a device for the tamper-proof registration of measured values of one or more physical and/or chemical variables.
- the device includes, among other things, a data memory and a program memory.
- DE 102018211 597 A1 discloses a method for setting up a proof of authorization for a first device Configuration data, which is transferred from a detachably connected to the first device (FD1) configuration module to the first device (FD1), is configured.
- the invention is based on the object of further developing a control device for an automation system, an automation system and a method for operating a control device.
- the object is achieved according to the invention by a control device having the features specified in claim 1 .
- Advantageous refinements and developments are the subject of the dependent claims.
- the object is also achieved by an automation system having the features specified in claim 9 and by a method for operating a control device having the features specified in claim 10 .
- a control device for an automation system includes a system bus interface for communication via a system bus with at least one field device and a control unit for controlling the at least one field device.
- the control unit is set up to send configuration data to the field device via the system bus interface.
- the control device includes a data memory interface for connecting a data memory and a verification unit.
- the verification unit is set up to check whether a data memory is connected to the data memory interface, whether a key file is stored on the data memory, and whether the key file contains a valid key.
- the verification unit is also set up to prevent configuration data from being sent via the system bus interface to the field device and/or to prevent access to configuration data in the control unit if the check is unsuccessful.
- Configuration of the control unit and the field devices of the automation system is only possible if a data memory with a key file with a valid key is connected to the data memory interface.
- the control device according to the invention thus prevents unauthorized configuration of the control unit and the field devices of the automation system. For example, to start up the control unit or a field device, a user connects the data memory and carries out the start-up by entering configuration data in the control unit and by sending configuration data to the field device. After the control unit or the field device has been started up, the user removes the data memory again.
- a malicious attack on the control unit and on the field devices to sabotage the automation system is then prevented by the control device.
- the data storage interface is designed as a USB interface.
- the data memory is then, for example, a USB stick, which is small, light and inexpensive.
- the control unit has a digital processing unit on which a real-time capable operating system is installed.
- the control device is designed as a programmable logic controller.
- a programmable logic controller is also referred to as a programmable logic control or PLC.
- the verification unit is integrated into the control unit.
- the verification unit is set up to prevent configuration data from being sent from the control unit to the system bus interface if the check is unsuccessful.
- the control device includes a data bus interface for communication via a data bus with a server.
- the data bus is designed, for example, as a field bus, in particular as a PROFINET, MODBus, EtherNet/IP or PROFIBUS. It is also conceivable for the data bus to be in the form of an IT network, in particular a LAN, WAN, Ethernet or Internet.
- control device also includes an application unit.
- the application unit is set up to communicate with a server via the data bus interface.
- the application unit is also set up to send configuration data to the control unit. It is thus possible to start up a field device from the server via the data bus.
- the application unit has a digital processing unit on which an operating system is installed.
- the operating system installed in the application unit is Windows, for example or Linux.
- Such an operating system is also referred to as a general purpose operating system or GPOS.
- the verification unit is integrated into the application unit.
- the verification unit is set up to prevent configuration data from being sent from the application unit to the control unit if the check is unsuccessful.
- An automation system comprises at least one control device according to the invention and at least one field device which communicates with the at least one control device via a system bus.
- an unauthorized configuration of the field devices in particular a malicious attack on the field devices to sabotage the automation system, is prevented by the control device.
- a method according to the invention for operating a control device comprises the steps mentioned below.
- the verification unit checks whether a data memory is connected to the data memory interface.
- the verification unit checks whether a key file is stored on the data memory.
- the verification unit checks whether the key file contains a valid key. If the check is unsuccessful, the verification unit prevents configuration data from being sent via the system bus interface to the field device and/or prevents configuration data from being accessed in the control unit.
- the verification unit only allows configuration data to be sent via the system bus interface to the field device and access to configuration data in the control unit if the check in all steps is successful.
- the method according to the invention prevents an unauthorized configuration of the control unit and the field devices, in particular a malicious attack on the control unit and on the field devices to sabotage the automation system.
- Figure 1 a control device according to a first embodiment
- FIG. 2 a control device according to a second embodiment.
- FIG. 1 shows a control device 10 according to a first embodiment.
- the control device 10 is designed as a programmable logic controller and includes a control unit 20.
- the control unit 20 has a digital processing unit on which a real-time capable operating system is installed.
- the control unit 20 is used to control field devices that are not shown here.
- the field devices are, for example, converters or input/output units.
- the control device 10 includes a system bus interface 21 to which a system bus 12 is connected.
- the system bus 12 is implemented as EtherCAT®/SBusPLUS, for example.
- the field devices not shown here are also connected to the system bus 12 .
- the system bus interface 21 enables communication with the field devices via the system bus 12 .
- the control unit 20 has a configuration unit 25 which contains configuration data for the field devices.
- the configuration data can be entered by a user, for example.
- the control unit 20 is set up to send said configuration data to the field devices via the system bus interface 21 and the system bus 12 .
- the control unit 20 sends the configuration data to a field device for commissioning, for example.
- the control device 10 includes a data memory interface 51 for connecting a data memory 50.
- the data memory interface 51 is presently designed as a USB interface.
- a data memory 50 in the form of a USB stick is connected to the data memory interface 51 .
- a key file 55 is stored on the data memory 50; which contains a digital key.
- the control device 10 includes a verification unit 30.
- the verification unit 30 is set up to permit and prevent data transmission from the configuration unit 25 to the system bus interface 21. This is represented symbolically by a switch 35 which can be controlled by the verification unit 30 .
- the verification unit 30 is also set up to permit and prevent access to configuration data in the control unit 20 .
- the verification unit 30 is integrated into the control unit 20 .
- the verification unit 30 checks whether a data memory 50 is connected to the data memory interface 51 . If no data memory 50 is connected to the data memory interface 51, the verification unit 30 opens the switch 35 and thus prevents data transmission from the configuration unit 25 to the system bus interface 21 and access to configuration data in the control unit 20.
- the verification unit 30 checks in a second step whether a key file 55 is stored on the data memory 50. If no key file 55 is stored on the data memory 50, the verification unit 30 opens the switch 35 and thus prevents data transmission from the configuration unit 25 to the system bus interface 21 and access to configuration data in the control unit 20.
- the verification unit 30 checks in a third step whether the key file 55 contains a valid key. If the key file 55 does not contain a valid key, the verification unit 30 opens the switch 35 and thus prevents data transmission from the configuration unit 25 to the system bus interface 21 and access to configuration data in the control unit 20.
- the verification unit 30 In the event of an unsuccessful check in one of the steps, the verification unit 30 thus prevents configuration data from being sent from the control unit 20 to the system bus interface 21 and access to configuration data in the control unit 20. If the check is unsuccessful, the verification unit 30 thus prevents configuration data from being sent via the system bus interface 21 to the field device. Only in the case of a successful check in all steps does the verification unit 30 close the switch 35 and thus allows configuration data to be sent from the control unit 20 to the system bus interface 21 and access to configuration data in the control unit 20. If the check is successful, the verification unit 30 thus allows sending of configuration data via the system bus interface 21 to the field device.
- FIG. 2 shows a control device 10 according to a second embodiment.
- the control device 10 is designed as a programmable logic controller and includes a control unit 20.
- the control unit 20 has a digital processing unit on which a real-time capable operating system is installed.
- the control unit 20 is used to control field devices that are not shown here.
- the field devices are, for example, converters or input/output units.
- the control device 10 also includes an application unit 40.
- the application unit 40 has a digital processing unit on which an operating system, for example Windows or Linux, is installed.
- the application unit 40 is used to communicate with a server that is not shown here.
- the control device 10 includes a system bus interface 21 to which a system bus 12 is connected.
- the system bus 12 is implemented as EtherCAT®/SBusPLUS, for example.
- the field devices not shown here are also connected to the system bus 12 .
- the system bus interface 21 enables communication with the field devices via the system bus 12 .
- the control device 10 also includes a data bus interface 41 to which a data bus 14 is connected.
- the data bus 14 is designed, for example, as a field bus, in particular as a PROFINET, MODBus, EtherNet/IP or PROFIBUS.
- the data bus is designed as an IT network, in particular a LAN, WAN, Ethernet or Internet.
- the server not shown here, is also connected to the data bus 14 . Communication via the data bus 14 with the server is possible by means of the data bus interface 41 .
- the application unit 40 has an input unit 45 .
- the input unit 45 is in particular a firewall or a router.
- the input unit 45 receives configuration data for the field devices from the server, for example.
- the Input unit 45 is set up to forward the received configuration data to control unit 20 .
- the application unit 40 is therefore set up to send configuration data to the control unit 20 .
- the control unit 20 is set up to send said configuration data to the field devices via the system bus interface 21 and the system bus 12 .
- the control unit 20 sends the configuration data to a field device for commissioning, for example.
- the control device 10 includes a data memory interface 51 for connecting a data memory 50.
- the data memory interface 51 is presently designed as a USB interface.
- a data memory 50 in the form of a USB stick is connected to the data memory interface 51 .
- a key file 55 is stored on the data memory 50; which contains a digital key.
- the control device 10 includes a verification unit 30.
- the verification unit 30 is set up to permit and prevent data transmission from the input unit 45 to the control unit 20. This is represented symbolically by a switch 35 which can be controlled by the verification unit 30 .
- the verification unit 30 is also set up to permit and prevent access to configuration data in the control unit 20 .
- the verification unit 30 is integrated into the application unit 40 .
- the verification unit 30 checks whether a data memory 50 is connected to the data memory interface 51 . If no data memory 50 is connected to the data memory interface 51, the verification unit 30 opens the switch 35 and thus prevents data transmission from the input unit 45 to the control unit 20 and access to configuration data in the control unit 20.
- the verification unit 30 checks in a second step whether a key file 55 is stored on the data memory 50. If no key file 55 is stored on the data memory 50, the verification unit 30 opens the switch 35 and thus prevents data transmission from the input unit 45 to the control unit 20 and access to configuration data in the control unit 20. If a key file 55 is stored on the data memory 50, the verification unit 30 checks in a third step whether the key file 55 contains a valid key. If the key file 55 does not contain a valid key, the verification unit 30 opens the switch 35 and thus prevents data transmission from the input unit 45 to the control unit 20 and access to configuration data in the control unit 20.
- the verification unit 30 thus prevents configuration data from being sent from the input unit 45 to the control unit 20 and access to configuration data in the control unit 20
- Checking thus also prevents the verification unit 30 from sending configuration data from the control unit 20 via the system bus interface 21 to the field device. Only in the case of a successful check in all steps does the verification unit 30 close the switch 35 and thus allows configuration data to be sent from the input unit 45 to the control unit 20 and access to configuration data in the control unit 20. If the check is successful, the verification unit 30 thus allows sending of configuration data from the control unit 20 via the system bus interface 21 to the field device.
- control device 12 system bus
Landscapes
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Engineering & Computer Science (AREA)
- Automation & Control Theory (AREA)
- Programmable Controllers (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102021000836 | 2021-02-18 | ||
| PCT/EP2022/051774 WO2022175040A1 (de) | 2021-02-18 | 2022-01-26 | Steuerungsgerät für ein automatisierungssystem, automatisierungssystem und verfahren zum betreiben eines steuerungsgerät |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4295201A1 true EP4295201A1 (de) | 2023-12-27 |
Family
ID=80168077
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22702240.7A Pending EP4295201A1 (de) | 2021-02-18 | 2022-01-26 | Steuerungsgerät für ein automatisierungssystem, automatisierungssystem und verfahren zum betreiben eines steuerungsgerät |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4295201A1 (de) |
| DE (1) | DE102022000293A1 (de) |
| WO (1) | WO2022175040A1 (de) |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102004045195A1 (de) * | 2004-09-17 | 2006-04-06 | Siemens Ag | Steuerungs- oder Regelungseinrichtung einer Werkzeug- oder Produktionsmaschine |
| DE102011086726B4 (de) | 2011-11-21 | 2014-04-03 | Siemens Aktiengesellschaft | Verfahren zur redundanten Kommunikation zwischen einem Nutzer-Terminal und einem Leitsystem-Server |
| DE102014016349B4 (de) | 2014-11-05 | 2025-02-13 | Sew-Eurodrive Gmbh & Co Kg | Verfahren zum Herstellen und Betreiben einer industriellen Maschine oder Anlage |
| DE102015121809A1 (de) * | 2015-12-15 | 2017-06-22 | Endress+Hauser Conducta Gmbh+Co. Kg | Funkdongle und Verfahren zur drahtlosen Übertragung von Daten von einem Computer zu zumindest einem Feldgerät |
| US10795849B2 (en) | 2016-07-04 | 2020-10-06 | Sew-Eurodrive Gmbh & Co. Kg | System of automation components and method for operating the same |
| DE202016105474U1 (de) | 2016-09-30 | 2016-11-17 | Jumo Gmbh & Co. Kg | Vorrichtung zur manipulationssicheren Registrierung von Messwerten |
| EP3525390A1 (de) | 2018-02-13 | 2019-08-14 | Siemens Aktiengesellschaft | Einrichtung und verfahren zum bereitstellen mindestens eines sicheren kryptographischen schlüssels für den durch ein steuergerät initiierten kryptographischen schutz von daten |
| DE102018211597A1 (de) | 2018-07-12 | 2020-01-16 | Siemens Aktiengesellschaft | Verfahren zur Einrichtung eines Berechtigungsnachweises für ein erstes Gerät |
| DE102019210982A1 (de) * | 2019-07-24 | 2021-01-28 | Robert Bosch Gmbh | Verfahren zur abgesicherten Konfiguration von Automatisierungssystemen |
-
2022
- 2022-01-26 EP EP22702240.7A patent/EP4295201A1/de active Pending
- 2022-01-26 WO PCT/EP2022/051774 patent/WO2022175040A1/de not_active Ceased
- 2022-01-26 DE DE102022000293.0A patent/DE102022000293A1/de active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| DE102022000293A1 (de) | 2022-08-18 |
| WO2022175040A1 (de) | 2022-08-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2250598B1 (de) | Client/server-system zur kommunikation gemäss dem standardprotokoll opc ua und mit single sign-on mechanismen zur authentifizierung sowie verfahren zur durchführung von single sign-on in einem solchen system | |
| EP3353610B2 (de) | Verbindungseinheit, überwachungssystem und verfahren zum betreiben eines automatisierungssystems | |
| EP1872180B1 (de) | Verfahren zum sicheren bedienen eines feldgerätes der automatisierungstechnik | |
| EP3975502B1 (de) | Verfahren und system zur bereitstellung von zeitkritischen diensten mittels einer ablaufsteuerungsumgebung | |
| DE102019210982A1 (de) | Verfahren zur abgesicherten Konfiguration von Automatisierungssystemen | |
| EP2400708B1 (de) | Netzwerk-Schutzeinrichtung | |
| EP3871393B1 (de) | Verfahren zur überwachung eines datenübertragungssystems, datenübertragungssystem und kraftfahrzeug | |
| WO2022175040A1 (de) | Steuerungsgerät für ein automatisierungssystem, automatisierungssystem und verfahren zum betreiben eines steuerungsgerät | |
| EP1224510B1 (de) | System und verfahren zum verhindern von unberechtigtem zugriff auf module, insbesondere bei automatisierungssystemen | |
| EP1496664A2 (de) | Vorrichtung und Verfahren sowie Sicherheitsmodul zur Sicherung eines Datenzugriffs eines Kommunikationsteilnehmers auf mindestens eine Automatisierungskomponente eines Automatisierungssystems | |
| WO2011032796A1 (de) | Bereitstellung anlagenbezogener betriebsdaten unter verwendung eines diagnose-datenservers als weiteren feldbusmaster | |
| DE102011082962A1 (de) | System und Verfahren zur Bereitstellung eines Steuerungsprogrammcodes | |
| EP2599258B1 (de) | Verfahren zum verarbeiten von nachrichten in einem kommunikationsnetz aus mehreren netzknoten | |
| EP1497735B1 (de) | Verfahren und vorrichtung zur überprufung einer überwachungsfunktion eines bussystems und bussystem | |
| EP4254233A1 (de) | Verfahren und system zur gesicherten ausführung von steuerungsanwendungen, host | |
| EP2618522A1 (de) | Verfahren zum rechnergestützten Entwurf einer Automatisierungsanlage | |
| EP4096182A1 (de) | Verfahren zur gesicherten einräumung eines zugriffs auf daten und/oder ressourcen und gateway-komponente | |
| DE102021001792B3 (de) | Automatisierungssystem und Verfahren zum Betrieb eines Automatisierungssystems | |
| EP3891950B1 (de) | Router mit anmeldungsfunktionalität und hierfür geeignetes zugriffskontrollverfahren | |
| EP3479538A1 (de) | Sicherheitseinrichtung mit ortsgebundenem schlüsselspeicher, system und verfahren | |
| EP1430647B1 (de) | Verfahren zum Betrieb eines Koppelknotens in einem Datennetz | |
| DE102024120252A1 (de) | Verfahren zur Verwaltung eines Bestandsfeldgeräts und entsprechendes System | |
| DE102024105113A1 (de) | Verfahren zur Erlangung von Zugriff auf ein Feldgerät und entsprechendes System | |
| EP3478541B1 (de) | Sicherheitseinrichtung und verfahren zum betreiben eines systems | |
| WO2026017549A1 (de) | Verfahren und system zur anmeldung eines benutzers an einem oder mehreren feldgeräten der automatisierungstechnik |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20230918 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20250703 |