WO2014094982A1 - Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques - Google Patents

Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques Download PDF

Info

Publication number
WO2014094982A1
WO2014094982A1 PCT/EP2013/003657 EP2013003657W WO2014094982A1 WO 2014094982 A1 WO2014094982 A1 WO 2014094982A1 EP 2013003657 W EP2013003657 W EP 2013003657W WO 2014094982 A1 WO2014094982 A1 WO 2014094982A1
Authority
WO
WIPO (PCT)
Prior art keywords
commissioning
network
adapter
communication
wireless
Prior art date
Application number
PCT/EP2013/003657
Other languages
English (en)
Inventor
Dirk Schulz
Ravish Kumar
Thomas Ruschival
Original Assignee
Abb Ag
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Abb Ag filed Critical Abb Ag
Publication of WO2014094982A1 publication Critical patent/WO2014094982A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0806Configuration setting for initial configuration or provisioning, e.g. plug-and-play
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0492Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload by using a location-limited connection, e.g. near-field communication or limited proximity of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/50Service provisioning or reconfiguring
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/70Services for machine-to-machine communication [M2M] or machine type communication [MTC]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/18Self-organising networks, e.g. ad-hoc networks or sensor networks
    • H04W84/22Self-organising networks, e.g. ad-hoc networks or sensor networks with access to wired networks
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02PCLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
    • Y02P90/00Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
    • Y02P90/02Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]

Definitions

  • the invention relates to a commissioning system and a method for the secure and/or fail-safe or reliable exchange of sensitive information for the commissioning and configuration of technical equipment, in particular of a plant or process automation system, by means of wireless connections according to the preamble of the independent claims.
  • wireless connections which intrinsically seem to be unsecure in real practice, may still be used securely by applying specific communication means, in particular interfaces, and restrictions.
  • WirelessHART as a new communication standard in industrial automation introduces a number of new challenges compared to classical wired communication, which have to be addressed at an early stage in the respective Device Management System (DMS) during topology engineering and commissioning.
  • DMS Device Management System
  • the DMS requires instances for gateways and devices and must reflect the logical communication topology from the previous network layout.
  • security measures defined in the HART standard introduce additional complexity into the commissioning workflow.
  • WirelessHART WirelessHART
  • the WirelessHART standard defines mandatory authentication and encryption mechanisms for the wireless communication. It further requires that the related encryption keys are exchanged through secure connections. Wired FSK (Frequency Shift Keying) communication is considered to fulfill this security requirement, are even fully autonomous wireless devices must provide a corresponding interface. Just like any other device parameter, also encryption keys may be pre-parameterized by the device manufacturer.
  • WirelessHART uses symmetric encryption, namely usage of the same key for encryption and decryption, for the authentication and communication between field devices and wireless access points. Corresponding keys must be available within both the gateway and the field device that wish to communicate.
  • a gateway receives an individual join key per device. To validate a join request, it requires a list of join keys and corresponding device IDs (hardware addresses). There is no way to disable encryption and authentication, but for ease of use the security level can be lowered. A common join key may then be shared between the devices in a network, and any device with a valid key is allowed to join.
  • the WirelessHART - devices must be connected to a "join key source", for example a commissioning station/engineering/handheld, via a secure connection or communication line.
  • Said connection typically is realized via a wired FSK Modem connection or a short-range IR connection, which all devices must support, even fully autonomous ones.
  • a HMI (human machine interface) port is also technically possible, but not standardized among manufacturers. Any wired port must be exposed during commissioning, whereby only the non-standard HMI port allows the device to remain closed.
  • the object of the invention is to provide an enhanced possibility for the secure exchange and easy management of sensitive information of technical equipment and in particular field devices by use of wireless connections, in particular also for wide range exchange.
  • the invention relates to a commissioning system for a secure exchange of sensitive information for the commissioning and/or configuring of technical equipment, in particular field devices of a process automation system or plant automation system, comprising at least two components and/or devices, in particular field devices, using communication means to secure a wireless communication without the need to use higher protocol layers, like in particular authentication or encryption functionalities, wherein the communication means comprise a commissioning device and a commissioning network, in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multi-drop wired modem, and/or a key storage device for dedicated join key storage and/or generation is provided, which key storage device comprises a storage unit for a number of key/device and network IDs and is connectable to an engineering client and/or the commissioning device via a wired or wireless short range connection, in particular a handheld and/or USB stick with at least one of a FSK (Frequency Shift Keying)-, RFID-, IR-interface or HMI (Human
  • the at least two components or devices may be "regular” field devices but also dedicated “care-free” routers, providing an adapter and an energy source, in particular a battery or an accumulator and/or a photovoltaic or solar cell.
  • fully autonomous devices which in particular are equipped with wireless communication and autonomous energy sources, for example like batteries, which might physically be hard to access because of their site of operation or place of installation, and accordingly do not need or do not have to be accessed or opened and connected through a wired interface.
  • the communication between devices in particular field devices , for example from specific and/or special WirelessHART gateways, from WirelessHART handhelds, or from handhelds supporting IR or RFID communication providing near-range communication, wherein a handheld may be any type of smartphone, mobile, tablet PC, net- book, PDA (personal digital assistant) or mobile computer, may be treated as being relatively secure.
  • field devices for example from specific and/or special WirelessHART gateways, from WirelessHART handhelds, or from handhelds supporting IR or RFID communication providing near-range communication, wherein a handheld may be any type of smartphone, mobile, tablet PC, net- book, PDA (personal digital assistant) or mobile computer, may be treated as being relatively secure.
  • the system according to the invention allows a pre-parameterization or installation or putting into operation / commissioning of wireless - devices, in particular WirelessHART - devices for example by use of a portable commissioning device or station or handheld, in general a portable data processing device or unit, in a secure environment.
  • Secure in the context of this application means with high safety from interception but also a relatively high data or information transfer rate and/or a relatively high data or information transfer quality and/or high connectivity, independent from the circumstances and the environmental conditions in the plant or field.
  • the system provides a time efficient, in particular with a reduced or minimized join time, flexible, secure and reliable interface or communication interface respectively and access to different type of distributed, in particular wireless or non-wireless, field devices in particular in a plant or field with a relatively high distance in between the different devices and/or with a relatively high pollution and/or dirt and/or dangerous environment, for example high temperatures and/or pressures, and/or high voltages, so that wired connections or cable connections would require an extended wide range cable net, which cables and/or cable connection might be damaged during operation of the plant and accordingly may not work properly anymore. Furthermore, assembly of the wired network as well as its maintenance will take a lot of effort and material.
  • the invention allows a reduction of and/or minimizes the join time and/or commission time for one or more field devices arranged in a plant or field in industrial automation industry.
  • the communication means to secure wireless communication comprise properties of a physical layer and/or link layer and/or measurements.
  • physical layer describes the first and lowest layer in the seven-layer OSI model (Open System Interconnection Reference Model).
  • the physical layer accordingly comprises all the basic networking hardware transmission technologies of a network and all the necessary means for implementing said technologies and in particular for transmitting raw bits as well as logical data packets over physical link connecting network nodes, whereas the data which have to be transmitted are converted to a physical signal that may be transmitted.
  • identification means are provided, which use device identification information to determine the trustworthiness of a communication partner.
  • verification means are provided to introduce a verification step executed by a human to yet increase the attained level of security.
  • the system comprises communication means which provide or include a commissioning network, in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multi-drop wired modem, wherein said dedicated commissioning network, in particular a Wire- lessHART Network, uses a well-known Network ID and a shared Join Key and which network is not used for any production purpose whatsoever, and wherein the devices joined in this network are visible to the integration component for the wireless network implemented by the gateway, for example, an FDT (Field Device Tool) communication DTM (Device Type Manager) or an FDI (Field Device Integration) communication device or server, in the same manner as devices connected to an FSK (Frequency Shift Keying) modem, thus any such device may be assigned to the target network, in particular
  • FDT Field Device Tool
  • DTM Device Type Manager
  • FDI Field Device Integration
  • this commissioning network can be shared between all communication DTMs and/or FDIs and/or communication servers, wherein device assignment is a manual task and accordingly not more than one such DTM (Device Type Manager) or FDI or communication server might be opened at a time and communicates with the gateway.
  • DTM Device Type Manager
  • a device which initiates and/or executes a reset of the Network ID and Join Key to the well- known values, a so called soft reset, in particular by demand or request or rule based or signal based.
  • a device is provided which supports and initiates and/or executes a "hard reset of the security data" to the default values using for example magnetic pins at the respective HMI (Human Machine Interface).
  • the antenna of the commissioning gateway is enclosed in a radio-shielded tube, in particular made of plastic with embedded metal mesh, and connected via cable to the gateway.
  • a radio-shielded tube in particular made of plastic with embedded metal mesh, and connected via cable to the gateway.
  • this tube is simply put over the device antenna, resulting in secure and directed or targeted, almost vectored, communication already on the physical layer.
  • a handheld wherein the commissioning network is provided by a wireless handheld.
  • the term "handheld” is synonymously used for all type of handheld devices or handheld computer, in particular mobile computers and/or mobile phones and /or cell phones and or smart phones and /or PDA ' s and /or handhelds or handheld organizers and or tablet computer, whereas a handheld is a relatively small hand-held computing device with an operating system and a power supply, in particular a battery or rechargeable accumulator power source.
  • IR infrared
  • RFID radio frequency identification
  • a RFID key storage may be provided, wherein an RFID chip stores the join key.
  • This key can, contrary to WirelessHART, be read from the chip but only from about half a meter of distance, what still seems to be very secure, in particular in view of the risk of tapping or interception. Presuming that the RFID chip still works even in a damaged device, device exchange on location is possible without any connection to the device management system; the handheld can read the key from the old device and download it into the replacement device.
  • a key storage device for dedicated key storage and/or generation is provided, which contains a storage unit for a number of key/device and network IDs and which is connected to the engineering client and the commissioning device respectively, in particular via USB, to receive a list of key/ID triples.
  • the respective commissioning engineer may simply walk by each all wireless devices and establish a connection with each at one time, which will automatically cause the download of the key/network ID pair to a device whose ID is in the list.
  • USB stick with any of the previously described interfaces at the other end, like in particular FSK, RFID, IR, HMI Port or the like.
  • a commissioning/maintenance adapter in particular a "pre- secured portable wireless" connection device, for an HMI Port is provided as commissioning device, comprising a WirelessHART adapter equipped with an HMI interface so it can be plugged directly onto the device to provide wireless connectivity during commissioning or maintenance.
  • the FDT DTM Field Device Tool Device Type Manager
  • the FDT DTM Field Device Tool Device Type Manager
  • Said roaming adapter avoids the need for a handheld when distributing join keys to wireless devices, in particular wireless devices which have their own wireless connection once they have received the keys and/or in hybrid plants, where only some devices use wireless communication technologies, to parameterize the wired devices in the same way as the wireless ones.
  • a secure connectivity over unsecure channels for all variants of key distribution and device parameterization is provided, using either standardized interfaces or the ABB HMI interface.
  • the commissioning adapter may be used for configuring a wired or wireless device wirelessly.
  • the commissioning adapter is equipped with at least two interfaces, in particular comprising a wireiessHART- and a FSK- interface.
  • the commissioning adapter communicates with the wireiessHART gateway using the wireiessHART interface and device, which needs to be configured, using FSK interface.
  • the commissioning adapter provides more flexibility and mobility for remotely device configuration and secure handing of network credentials.
  • An exemplary setup is shown in Fig. 1.
  • the commissioning adapter is acting in a similar way like the other WireiessHART field devices. It joins the wireiessHART network in the same manner as specified in wireiessHART standard. After joining the network it will be used as remote device configurator.
  • the device which needs to be commissioned should have connection with
  • the device commissioning related commands can be sent to the commissioning adapter via the wireiessHART Gateway. After receiving the commissioning command, the commissioning adapter will start the device commissioning operation and will send back the command execution result to the engineering workplace via response message.
  • the commissioning adapter can have at least one of a RFID- or IR- HMI-Port or a combination thereof to establish or provide a connection to the field device which needs to be commissioned.
  • a commissioning adapter by means of a commissioning adapter a secure network credentials handling may be provided, wherein from an engineering workplace the distribution of device network credentials is initiated and executed in a completely secure manner.
  • a remote device diagnostic and troubleshooting operation is performed, wherein the commissioning adapter diagnoses the field device on the site location and sends the diagnostic information remotely to the network manager.
  • an easy commissioning is provided by means of the commissioning adapter because device commissioning workflow will be easy as there is no need to use a handheld device for importing/exporting device credentials.
  • join time of a device may be reduced and/or minimized.
  • the radio transmissions in the physical layer are influenced without any modification to the field device to restrict the transmissions to a secure area. This is done by various means and at least one of setting transmission power to a level sufficiently high for local communication but low enough so communication cannot be overheard from outside of the commissioning area; encasing at least the antenna, if not the entire device, of device and gateway in a common, shielded housing; restricting the radio direction of device and gateway by shields/reflectors which are not part of the device but for the gateway may be part of a static gateway setup.
  • the required interaction by the respective user according to the invention is a simple plug & play. Compared to a state-of-the-art handheld no manual parameterization task is needed, no knowledge of join keys is required. By integrating the secure connectivity with the DCS engineering clients, the join keys never need to be exposed or disclosed to a user.
  • the invention relates to a method for a secure exchange of sensitive information of technical equipment, in particular by use of a system according to the invention as described above, whereas a secure wireless communication between at least two components and/or devices, in particular field devices, is provided and established by using communication means to ensure a secure near-range communication, in particular by restricting communication signals to a secure area and determining if a device is within a certain area and allow communication if it is or refuse to communicate if it is not, without the need to use higher protocol layers, like in particular authentication or encryption functionalities.
  • device identification information is used to determine the trustworthiness of a communication partner.
  • a verification step is executed by a human to yet increase the attained level of security.
  • the radio transmissions in the physical layer are influenced without any modification to the field device to restrict the transmissions to a secure area.
  • this is done by various means and at least one of setting transmission power to a level sufficiently high for local communication but low enough so communication cannot be overheard from outside of the commissioning area; encasing at least the antenna, if not the entire device, of device and gateway in a common, shielded housing; restricting the radio direction of device and gateway by shields/reflectors which are not part of the device but for the gateway may be part of a static gateway setup.
  • the method for a secure exchange of sensitive information of technical equipment is applied to a commissioning network with a wireless gateway and uses a well-known Network ID and a shared Join Key wherein the devices joined in this network are visible to the respective Communication DTM (device type manager) for the wireless gateway in the same manner as devices connected to an FSK (Frequency Shift Keying) modem, thus any such device may be assigned to the target network, in particular by a commissioning engineer, and to secure this process, the identification information, in particular the device type, the manufacturer, the serial number or the like, or the device proximity to the commissioning network can be used by man or machine to check the legitimacy of the device; the latter is achieved by evaluating receive signal levels and used transmission energy.
  • FSK defines a common frequency modulation technique.
  • this commissioning network can be shared between all Communication DTMs and/or FDIs and/or communication servers, wherein device assignment is a manual task and accordingly not more than one such DTM or FDI or communication server might be opened at a time and communicates with the gateway.
  • a handheld wherein the commissioning network is provided by a wireless handheld.
  • the term "handheld” is synonymously used for all type of handheld devices or handheld computer, in particular mobile computers and/or mobile phones and /or cell phones and or smart phones and /or PDA ' s and/or handhelds or handheld organizers and or tablet computer, whereas a handheld is a relatively small hand-held computing device with an operating system and a power supply, in particular a battery or rechargeable accumulator power source.
  • IR infrared
  • RFID radio frequency identification
  • a RFID key storage may be provided, wherein an RFID chip stores the join key.
  • This key can, contrary to WirelessHART, be read from the chip but only from about half a meter of distance, what still seems to be very secure, in particular in view of the risk of tapping or interception. Presuming that the RFID chip still works even in a damaged device, device exchange on location is possible without any connection to the device management system; the handheld can read the key from the old device and download it into the replacement device.
  • a number of key/device and network IDs may be retrieved and accessed via a key storage, for example acommissioning and/or handheld device for dedicated key storage and/or generation, which contains a storage unit for said key/device and network ID's and which is connected to the engineering client to receive a list of key/ID triples.
  • a key storage for example acommissioning and/or handheld device for dedicated key storage and/or generation, which contains a storage unit for said key/device and network ID's and which is connected to the engineering client to receive a list of key/ID triples.
  • a connection with each wireless device may be established at one time, which will automatically initiate and cause the download of the key/network ID pair to a device whose ID is the list.
  • this key storage/commissioning device or handheld could be a USB stick with any of the previously described interfaces at the other end, like in particular FSK, RFID, IR, HMI Port or the like.
  • a commissioning/maintenance adapter in particular a "pre- secured portable wireless" connection device, for a maintenance port, comprising a WirelessHART adapter equipped with an FSK interface so it can be plugged directly onto the device to provide wireless connectivity during commissioning or maintenance.
  • the FDT DTM field device tool device type manager
  • the FDT DTM field device tool device type manager
  • Said roaming adapter avoids the need for a handheld when distributing join keys to wireless devices, in particular wireless devices which have their own wireless connection once they have received the keys and/or in hybrid plants, where only some devices use wireless communication technologies, to parameterize the wired devices in the same way as the wireless ones.
  • a secure connectivity over unsecure channels for all variants of key distribution and device parameterization is provided, using either standardized interfaces or the ABB HMI interface.
  • the required interaction by the respective user according to the invention is a simple plug & play. Compared to a state-of-the-art handheld no manual parameterization task is needed, no knowledge of join keys is required. By integrating the secure connectivity with the DCS (distributed control system) engineering clients, the join keys never need to be exposed or disclosed to a user.
  • DCS distributed control system
  • the figure 1 discloses a commissioning system for a secure exchange of sensitive information of technical equipment by use of at least one wireless connection comprising communication means which provide or include a commissioning network, wherein said dedicated commissioning network uses a well-known Network ID and a shared Join Key and which network is not used for any production purpose whatsoever, and wherein the devices 1 ,4,6,8, joined in this network are visible to the integration component for the wireless network or gateway such as a communication DTM (device type manager) or FDI gateway or communication device package instance for the WirelessHART Gateway 1 in the same manner as devices connected to an FSK (frequency shift keying) modem, thus any such device may be assigned to the target network, in particular by a commissioning engineer.
  • a communication DTM device type manager
  • FDI gateway communication device package instance for the WirelessHART Gateway 1
  • the commissioning system for a secure exchange of sensitive information of technical equipment comprises at least three field devices 4,6,8 and
  • communication means comprise a commissioning device and a wireless Hart network as commissioning network comprising a regular WirelessHART gateway 1 which in the wireless management system is integrated like a multi-drop wired modem, wherein a commissioning / maintenance adapter 10 for an HMI Port, in particular an FSK interface 12, is provided as commissioning device, comprising a WirelessHART adapter so it can be plugged directly onto the respective field device 4 to provide wireless connectivity during commissioning and/or maintenance, so that no join key or network credentials have to be exchanged.
  • the commissioning adapter 10 may be used for configuring a wired or wireless device wirelessly, wherein the commissioning adapter is equipped with at least two interfaces, in particular comprising a WirelessHART- and a FSK- interface 12, wherein the commissioning adapter 10 communicates with the WirelessHART gateway 1 of the commissioning network using the WirelessHART interface and with the respective field device 4, which needs to be configured and/or commissioned using the FSK interface 12.
  • the commissioning adapter 10 is acting in a similar way like the other WirelessHART field devices and joins the WirelessHART network in the same man- ner as specified in WirelessHART standard, wherein after joining the network it will be used as remote device configurator, wherein device commissioning related commands may be send to the commissioning adapter via the commissioning network gateway and in particular the WirelessHART gateway and wherein after receiving the commissioning command, the commissioning adapter will start the device commissioning operation and will send back the command execution result to the engineering workplace via response message.
  • a secure network credentials handling may be provided, wherein from the engineering workplace the distribution of device network credentials is initiated and executed in a completely secure manner.
  • a remote device diagnostic and troubleshooting operation is performed by the commissioning adapter, wherein the commissioning adapter diagnoses the field device on the site location and sends the diagnostic information remotely to the respective network manager.
  • a commissioning network in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multidrop wired modem, and a commissioning device is provided, wherein the commissioning device is connected to the field device which has to be commissioned and is connected to the commissioning network so that information can be exchanged and communication can be established between the at least one field device and the commissioning device and/or commissioning network securely, in particular to exchange one or more join keys and/or ID triples and/or commissioning commands and/or parameters.
  • the commissioning network is shared between all Communication DTMs, wherein device assignment is a manual task and accordingly not more than one such DTM might be opened at
  • the present invention also comprises any combination of preferred embodiments as well as individual features and developments provided they do not exclude each other.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Selective Calling Equipment (AREA)

Abstract

L'invention concerne un système de mise en service et un procédé correspondant pour un échange sécurisé d'informations sensibles afin de mettre en service et/ou de configurer des équipements techniques, comportant au moins deux éléments et/ou dispositifs, en particulier des dispositifs sur le terrain utilisant des moyens de communication pour sécuriser une communication sans fil, en particulier sans avoir besoin d'utiliser des couches de protocole supérieures, telles que des fonctionnalités d'authentification ou de chiffrement, lesdits moyens de communication comportant un dispositif et un réseau de mise en service, en particulier un réseau de mise en service comportant une passerelle sans fil standard qui, dans le système de gestion sans fil, est intégrée comme modem filaire multipoint, et/ou un dispositif de stockage de clés destiné au stockage et/ou à la génération de clés de jointure dédiées, ledit dispositif de stockage de clés comportant une unité de stockage pour un certain nombre de clés/périphériques et d'ID de réseau, et pouvant être connecté à un client d'ingénierie et/ou au dispositif de mise en service par l'intermédiaire d'une connexion filaire ou sans fil à courte portée, en particulier un appareil portatif et/ou une clé USB avec au moins une interface FSK/RFID/IR ou un port HMI ou autre, pour recevoir et/ou stocker une ou plusieurs clés de jointure et/ou des ID à trois chiffres.
PCT/EP2013/003657 2012-12-20 2013-12-04 Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques WO2014094982A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
IN1437KO2012 2012-12-20
IN1437/KOL/2012 2012-12-20

Publications (1)

Publication Number Publication Date
WO2014094982A1 true WO2014094982A1 (fr) 2014-06-26

Family

ID=49999861

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2013/003657 WO2014094982A1 (fr) 2012-12-20 2013-12-04 Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques

Country Status (1)

Country Link
WO (1) WO2014094982A1 (fr)

Cited By (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3291510A1 (fr) * 2016-09-02 2018-03-07 United Technologies Corporation Caracterisation de dispositifs uniques ou multiples dans un systeme
GB2558056A (en) * 2016-10-24 2018-07-04 Fisher Rosemount Systems Inc Securely transporting data across a data diode for secured process control communications
GB2558055A (en) * 2016-10-24 2018-07-04 Fisher Rosemount Systems Inc Publishing data across a data diode for secured process control communications
US10051345B2 (en) 2014-02-28 2018-08-14 United Technologies Corporation Shielded electromagnetic communication with functional components of a machine
CN108431705A (zh) * 2015-10-12 2018-08-21 费希尔-罗斯蒙特系统公司 使用i/o抽象的现场设备配置的过程工厂中的配置
US10057663B2 (en) 2014-02-28 2018-08-21 United Technologies Corporation Remote communication and powered sensing/control/identification devices
US20180246499A1 (en) * 2015-01-27 2018-08-30 Nippon Seiki Co., Ltd. Plant equipment state gathering system
WO2019100150A1 (fr) * 2017-11-24 2019-05-31 Elsi Inc. Dispositifs, systèmes et procédés de stockage et de gestion de manière sécurisée d'informations sensibles
CN110383755A (zh) * 2017-01-05 2019-10-25 皇家飞利浦有限公司 网络设备和可信第三方设备
US10619760B2 (en) 2016-10-24 2020-04-14 Fisher Controls International Llc Time-series analytics for control valve health assessment
US10877465B2 (en) 2016-10-24 2020-12-29 Fisher-Rosemount Systems, Inc. Process device condition and performance monitoring
CN113039498A (zh) * 2018-11-14 2021-06-25 Abb瑞士股份有限公司 在工业系统网络中调试现场设备的方法
CN113297091A (zh) * 2021-06-18 2021-08-24 海光信息技术股份有限公司 SoC芯片的调试方法、装置及SoC芯片
JP2022028747A (ja) * 2014-10-02 2022-02-16 フィッシャー-ローズマウント システムズ,インコーポレイテッド 通信の促進方法、プラント無線アクセスポイント、及び非一時的有形コンピュータ可読媒体
US11438307B2 (en) 2019-02-07 2022-09-06 AO Kaspersky Lab Systems and methods for configuring a gateway for protection of automated systems
US11546367B2 (en) 2019-02-07 2023-01-03 AO Kaspersky Lab Systems and methods for protecting automated systems using a gateway

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2096505A1 (fr) * 2008-02-26 2009-09-02 ABB Research Ltd. Procédé, produits et système pour la configuration d'un nouveau noed dans un réseau sans fil industriel
US20100290351A1 (en) * 2009-05-15 2010-11-18 Fisher-Rosemount Systems, Inc. Maintenance of wireless field devices
US20120036568A1 (en) * 2010-08-09 2012-02-09 Yokogawa Electric Corporation Provisioning device
US20120237034A1 (en) * 2007-11-13 2012-09-20 Rosemount Inc. Wireless mesh network with secure automatic key loads to wireless devices

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120237034A1 (en) * 2007-11-13 2012-09-20 Rosemount Inc. Wireless mesh network with secure automatic key loads to wireless devices
EP2096505A1 (fr) * 2008-02-26 2009-09-02 ABB Research Ltd. Procédé, produits et système pour la configuration d'un nouveau noed dans un réseau sans fil industriel
US20100290351A1 (en) * 2009-05-15 2010-11-18 Fisher-Rosemount Systems, Inc. Maintenance of wireless field devices
US20120036568A1 (en) * 2010-08-09 2012-02-09 Yokogawa Electric Corporation Provisioning device

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
RAINER FALK ET AL: "Security Service for the Rollout of Security Credentials in Ubiquitous Industrial Automation Environments", SERVICE COMPUTATION 2010, 21 November 2010 (2010-11-21), pages 104 - 110, XP055073477, Retrieved from the Internet <URL:http://www.thinkmind.org/index.php?view=article&articleid=service_computation_2010_5_20_20033> [retrieved on 20130730] *

Cited By (39)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10405066B2 (en) 2014-02-28 2019-09-03 United Technologies Corporation Electromagnetic communication through components of a machine
US10531166B2 (en) 2014-02-28 2020-01-07 United Technologies Corporation Metal ceramic composite for electromagnetic signal transparent materials
US10491970B2 (en) 2014-02-28 2019-11-26 United Technologies Corporation Characterization of single or multiple devices in a system
US10051345B2 (en) 2014-02-28 2018-08-14 United Technologies Corporation Shielded electromagnetic communication with functional components of a machine
US10484760B2 (en) 2014-02-28 2019-11-19 United Technologies Corporation Electromagnetic communication from waveguide confinement
US10057663B2 (en) 2014-02-28 2018-08-21 United Technologies Corporation Remote communication and powered sensing/control/identification devices
US10469920B2 (en) 2014-02-28 2019-11-05 United Technologies Corporation Electromagnetic sensing of components in electromagnetic communication and method
US10638207B2 (en) 2014-02-28 2020-04-28 United Technologies Corporation Component counterfeit prevention
US11089389B2 (en) 2014-02-28 2021-08-10 Raytheon Technologies Corporation Remote communication and powered sensing/control/identification devices using high temperature compatible semiconductor materials
US11937031B2 (en) 2014-02-28 2024-03-19 Rtx Corporation Remote communication and powered sensing/control/identification devices using high temperature compatible semiconductor materials
US10091562B2 (en) 2014-02-28 2018-10-02 United Technologies Corporation Electromagnetic communication from waveguide confinement
US10419831B2 (en) 2014-02-28 2019-09-17 United Technologies Corporation Remote communication and powered sensing/control/identification devices using high temperature compatible semiconductor materials
JP2022028747A (ja) * 2014-10-02 2022-02-16 フィッシャー-ローズマウント システムズ,インコーポレイテッド 通信の促進方法、プラント無線アクセスポイント、及び非一時的有形コンピュータ可読媒体
JP7346520B2 (ja) 2014-10-02 2023-09-19 フィッシャー-ローズマウント システムズ,インコーポレイテッド 通信の促進方法、プラント無線アクセスポイント、及び非一時的有形コンピュータ可読媒体
US10416659B2 (en) 2015-01-27 2019-09-17 Nippon Seiki Co., Ltd. Plant equipment state gathering system
US20180246499A1 (en) * 2015-01-27 2018-08-30 Nippon Seiki Co., Ltd. Plant equipment state gathering system
EP3252699A4 (fr) * 2015-01-27 2018-10-10 Nippon Seiki Co., Ltd. Système de collecte de l'état d'équipements d'installations
CN108431705A (zh) * 2015-10-12 2018-08-21 费希尔-罗斯蒙特系统公司 使用i/o抽象的现场设备配置的过程工厂中的配置
CN108431705B (zh) * 2015-10-12 2022-04-05 费希尔-罗斯蒙特系统公司 使用i/o抽象的现场设备配置的过程工厂中的配置
EP3291510A1 (fr) * 2016-09-02 2018-03-07 United Technologies Corporation Caracterisation de dispositifs uniques ou multiples dans un systeme
GB2558056B (en) * 2016-10-24 2022-01-12 Fisher Rosemount Systems Inc Securely transporting data across a data diode for secured process control communications
GB2558055B (en) * 2016-10-24 2022-04-06 Fisher Rosemount Systems Inc Publishing data across a data diode for secured process control communications
US10877465B2 (en) 2016-10-24 2020-12-29 Fisher-Rosemount Systems, Inc. Process device condition and performance monitoring
GB2558056A (en) * 2016-10-24 2018-07-04 Fisher Rosemount Systems Inc Securely transporting data across a data diode for secured process control communications
GB2558055A (en) * 2016-10-24 2018-07-04 Fisher Rosemount Systems Inc Publishing data across a data diode for secured process control communications
US10619760B2 (en) 2016-10-24 2020-04-14 Fisher Controls International Llc Time-series analytics for control valve health assessment
US11700232B2 (en) 2016-10-24 2023-07-11 Fisher-Rosemount Systems, Inc. Publishing data across a data diode for secured process control communications
US10530748B2 (en) 2016-10-24 2020-01-07 Fisher-Rosemount Systems, Inc. Publishing data across a data diode for secured process control communications
US11240201B2 (en) 2016-10-24 2022-02-01 Fisher-Rosemount Systems, Inc. Publishing data across a data diode for secured process control communications
CN110383755A (zh) * 2017-01-05 2019-10-25 皇家飞利浦有限公司 网络设备和可信第三方设备
WO2019100150A1 (fr) * 2017-11-24 2019-05-31 Elsi Inc. Dispositifs, systèmes et procédés de stockage et de gestion de manière sécurisée d'informations sensibles
GB2583250A (en) * 2017-11-24 2020-10-21 Wolverton Jerry Devices, systems, and methods for securely storing and managing sensitive information
GB2583250B (en) * 2017-11-24 2022-05-11 Wolverton Jerry Devices, systems, and methods for securely storing and managing sensitive information
US11062050B2 (en) 2017-11-24 2021-07-13 Elsi Inc Devices, systems, and methods for securely storing and managing sensitive information
CN113039498A (zh) * 2018-11-14 2021-06-25 Abb瑞士股份有限公司 在工业系统网络中调试现场设备的方法
US11438307B2 (en) 2019-02-07 2022-09-06 AO Kaspersky Lab Systems and methods for configuring a gateway for protection of automated systems
US11546367B2 (en) 2019-02-07 2023-01-03 AO Kaspersky Lab Systems and methods for protecting automated systems using a gateway
CN113297091B (zh) * 2021-06-18 2022-04-29 海光信息技术股份有限公司 SoC芯片的调试方法、装置及SoC芯片
CN113297091A (zh) * 2021-06-18 2021-08-24 海光信息技术股份有限公司 SoC芯片的调试方法、装置及SoC芯片

Similar Documents

Publication Publication Date Title
WO2014094982A1 (fr) Procédé et système de mise en service pour un échange sécurisé d&#39;informations sensibles pour la mise en service et à la configuration d&#39;équipements techniques
JP5399554B2 (ja) 無線フィールド機器の改善されたメンテナンス
CN101855854B (zh) 向无线设备安全自动加载密钥的无线网格网络
CN101960888B (zh) 无线设备的连接密钥配置
RU2666495C2 (ru) Передатчик технологического параметра с беспроводным приемопередатчиком с питанием от контура
CN103885394B (zh) 用于配置控制系统的现场设备的系统和方法
JP2017516367A (ja) ワイヤレスな電力計測およびメトリクス
JP6273155B2 (ja) 情報設定装置、情報設定方法、情報設定プログラム、記録媒体、及び無線通信システム
CN103218876B (zh) 远控智能电能表信息安全管理模块
CN103198574B (zh) 嵌有信息安全管理模块的远控智能水表
CN106597873A (zh) 用于对自动化设备进行远程维护的方法、装置和系统
CN103152166A (zh) 远控智能水表信息安全管理模块
Haase et al. Wireless sensor/actuator device configuration by NFC
CN103152175B (zh) 远控智能燃气表信息安全管理模块
CN107925630A (zh) 机器对机器通信系统中的通信策略控制
WO2014094983A1 (fr) Système de mise en service et procédé pour un échange sécurisé d&#39;informations sensibles en vue de la mise en service et de la configuration d&#39;un équipement technique
CN203104484U (zh) 远控智能燃气表信息安全管理模块
KR20170039609A (ko) 웨어러블 디바이스를 활용한 보안 강화 및 편의성 향상 방안
Hjalmarsson et al. Wireless remote control of a PLC system
CN105205363A (zh) 一种水表信息安全管理模块
CN206833185U (zh) 借助各种类型的无线连接来控制空间内微气候的微气候控制设备
Haase et al. Configuration of smart embedded devices in the field using NFC
Trevisan Automation system of powder-based 3D printer in the Industry 4.0 environment
CN104504815A (zh) 嵌有信息安全管理模块的远控智能热能表
Amidi et al. An open, standard-based wireless network: connecting WirelessHART® sensor networks to Experion™ PKS using Honeywell’s OneWireless™ network

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13823934

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13823934

Country of ref document: EP

Kind code of ref document: A1