WO2014094982A1 - Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques - Google Patents
Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques Download PDFInfo
- Publication number
- WO2014094982A1 WO2014094982A1 PCT/EP2013/003657 EP2013003657W WO2014094982A1 WO 2014094982 A1 WO2014094982 A1 WO 2014094982A1 EP 2013003657 W EP2013003657 W EP 2013003657W WO 2014094982 A1 WO2014094982 A1 WO 2014094982A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- commissioning
- network
- adapter
- communication
- wireless
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0806—Configuration setting for initial configuration or provisioning, e.g. plug-and-play
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0433—Key management protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0492—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload by using a location-limited connection, e.g. near-field communication or limited proximity of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/50—Service provisioning or reconfiguring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/70—Services for machine-to-machine communication [M2M] or machine type communication [MTC]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/80—Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/18—Self-organising networks, e.g. ad-hoc networks or sensor networks
- H04W84/22—Self-organising networks, e.g. ad-hoc networks or sensor networks with access to wired networks
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02P—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
- Y02P90/00—Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
- Y02P90/02—Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]
Definitions
- the invention relates to a commissioning system and a method for the secure and/or fail-safe or reliable exchange of sensitive information for the commissioning and configuration of technical equipment, in particular of a plant or process automation system, by means of wireless connections according to the preamble of the independent claims.
- wireless connections which intrinsically seem to be unsecure in real practice, may still be used securely by applying specific communication means, in particular interfaces, and restrictions.
- WirelessHART as a new communication standard in industrial automation introduces a number of new challenges compared to classical wired communication, which have to be addressed at an early stage in the respective Device Management System (DMS) during topology engineering and commissioning.
- DMS Device Management System
- the DMS requires instances for gateways and devices and must reflect the logical communication topology from the previous network layout.
- security measures defined in the HART standard introduce additional complexity into the commissioning workflow.
- WirelessHART WirelessHART
- the WirelessHART standard defines mandatory authentication and encryption mechanisms for the wireless communication. It further requires that the related encryption keys are exchanged through secure connections. Wired FSK (Frequency Shift Keying) communication is considered to fulfill this security requirement, are even fully autonomous wireless devices must provide a corresponding interface. Just like any other device parameter, also encryption keys may be pre-parameterized by the device manufacturer.
- WirelessHART uses symmetric encryption, namely usage of the same key for encryption and decryption, for the authentication and communication between field devices and wireless access points. Corresponding keys must be available within both the gateway and the field device that wish to communicate.
- a gateway receives an individual join key per device. To validate a join request, it requires a list of join keys and corresponding device IDs (hardware addresses). There is no way to disable encryption and authentication, but for ease of use the security level can be lowered. A common join key may then be shared between the devices in a network, and any device with a valid key is allowed to join.
- the WirelessHART - devices must be connected to a "join key source", for example a commissioning station/engineering/handheld, via a secure connection or communication line.
- Said connection typically is realized via a wired FSK Modem connection or a short-range IR connection, which all devices must support, even fully autonomous ones.
- a HMI (human machine interface) port is also technically possible, but not standardized among manufacturers. Any wired port must be exposed during commissioning, whereby only the non-standard HMI port allows the device to remain closed.
- the object of the invention is to provide an enhanced possibility for the secure exchange and easy management of sensitive information of technical equipment and in particular field devices by use of wireless connections, in particular also for wide range exchange.
- the invention relates to a commissioning system for a secure exchange of sensitive information for the commissioning and/or configuring of technical equipment, in particular field devices of a process automation system or plant automation system, comprising at least two components and/or devices, in particular field devices, using communication means to secure a wireless communication without the need to use higher protocol layers, like in particular authentication or encryption functionalities, wherein the communication means comprise a commissioning device and a commissioning network, in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multi-drop wired modem, and/or a key storage device for dedicated join key storage and/or generation is provided, which key storage device comprises a storage unit for a number of key/device and network IDs and is connectable to an engineering client and/or the commissioning device via a wired or wireless short range connection, in particular a handheld and/or USB stick with at least one of a FSK (Frequency Shift Keying)-, RFID-, IR-interface or HMI (Human
- the at least two components or devices may be "regular” field devices but also dedicated “care-free” routers, providing an adapter and an energy source, in particular a battery or an accumulator and/or a photovoltaic or solar cell.
- fully autonomous devices which in particular are equipped with wireless communication and autonomous energy sources, for example like batteries, which might physically be hard to access because of their site of operation or place of installation, and accordingly do not need or do not have to be accessed or opened and connected through a wired interface.
- the communication between devices in particular field devices , for example from specific and/or special WirelessHART gateways, from WirelessHART handhelds, or from handhelds supporting IR or RFID communication providing near-range communication, wherein a handheld may be any type of smartphone, mobile, tablet PC, net- book, PDA (personal digital assistant) or mobile computer, may be treated as being relatively secure.
- field devices for example from specific and/or special WirelessHART gateways, from WirelessHART handhelds, or from handhelds supporting IR or RFID communication providing near-range communication, wherein a handheld may be any type of smartphone, mobile, tablet PC, net- book, PDA (personal digital assistant) or mobile computer, may be treated as being relatively secure.
- the system according to the invention allows a pre-parameterization or installation or putting into operation / commissioning of wireless - devices, in particular WirelessHART - devices for example by use of a portable commissioning device or station or handheld, in general a portable data processing device or unit, in a secure environment.
- Secure in the context of this application means with high safety from interception but also a relatively high data or information transfer rate and/or a relatively high data or information transfer quality and/or high connectivity, independent from the circumstances and the environmental conditions in the plant or field.
- the system provides a time efficient, in particular with a reduced or minimized join time, flexible, secure and reliable interface or communication interface respectively and access to different type of distributed, in particular wireless or non-wireless, field devices in particular in a plant or field with a relatively high distance in between the different devices and/or with a relatively high pollution and/or dirt and/or dangerous environment, for example high temperatures and/or pressures, and/or high voltages, so that wired connections or cable connections would require an extended wide range cable net, which cables and/or cable connection might be damaged during operation of the plant and accordingly may not work properly anymore. Furthermore, assembly of the wired network as well as its maintenance will take a lot of effort and material.
- the invention allows a reduction of and/or minimizes the join time and/or commission time for one or more field devices arranged in a plant or field in industrial automation industry.
- the communication means to secure wireless communication comprise properties of a physical layer and/or link layer and/or measurements.
- physical layer describes the first and lowest layer in the seven-layer OSI model (Open System Interconnection Reference Model).
- the physical layer accordingly comprises all the basic networking hardware transmission technologies of a network and all the necessary means for implementing said technologies and in particular for transmitting raw bits as well as logical data packets over physical link connecting network nodes, whereas the data which have to be transmitted are converted to a physical signal that may be transmitted.
- identification means are provided, which use device identification information to determine the trustworthiness of a communication partner.
- verification means are provided to introduce a verification step executed by a human to yet increase the attained level of security.
- the system comprises communication means which provide or include a commissioning network, in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multi-drop wired modem, wherein said dedicated commissioning network, in particular a Wire- lessHART Network, uses a well-known Network ID and a shared Join Key and which network is not used for any production purpose whatsoever, and wherein the devices joined in this network are visible to the integration component for the wireless network implemented by the gateway, for example, an FDT (Field Device Tool) communication DTM (Device Type Manager) or an FDI (Field Device Integration) communication device or server, in the same manner as devices connected to an FSK (Frequency Shift Keying) modem, thus any such device may be assigned to the target network, in particular
- FDT Field Device Tool
- DTM Device Type Manager
- FDI Field Device Integration
- this commissioning network can be shared between all communication DTMs and/or FDIs and/or communication servers, wherein device assignment is a manual task and accordingly not more than one such DTM (Device Type Manager) or FDI or communication server might be opened at a time and communicates with the gateway.
- DTM Device Type Manager
- a device which initiates and/or executes a reset of the Network ID and Join Key to the well- known values, a so called soft reset, in particular by demand or request or rule based or signal based.
- a device is provided which supports and initiates and/or executes a "hard reset of the security data" to the default values using for example magnetic pins at the respective HMI (Human Machine Interface).
- the antenna of the commissioning gateway is enclosed in a radio-shielded tube, in particular made of plastic with embedded metal mesh, and connected via cable to the gateway.
- a radio-shielded tube in particular made of plastic with embedded metal mesh, and connected via cable to the gateway.
- this tube is simply put over the device antenna, resulting in secure and directed or targeted, almost vectored, communication already on the physical layer.
- a handheld wherein the commissioning network is provided by a wireless handheld.
- the term "handheld” is synonymously used for all type of handheld devices or handheld computer, in particular mobile computers and/or mobile phones and /or cell phones and or smart phones and /or PDA ' s and /or handhelds or handheld organizers and or tablet computer, whereas a handheld is a relatively small hand-held computing device with an operating system and a power supply, in particular a battery or rechargeable accumulator power source.
- IR infrared
- RFID radio frequency identification
- a RFID key storage may be provided, wherein an RFID chip stores the join key.
- This key can, contrary to WirelessHART, be read from the chip but only from about half a meter of distance, what still seems to be very secure, in particular in view of the risk of tapping or interception. Presuming that the RFID chip still works even in a damaged device, device exchange on location is possible without any connection to the device management system; the handheld can read the key from the old device and download it into the replacement device.
- a key storage device for dedicated key storage and/or generation is provided, which contains a storage unit for a number of key/device and network IDs and which is connected to the engineering client and the commissioning device respectively, in particular via USB, to receive a list of key/ID triples.
- the respective commissioning engineer may simply walk by each all wireless devices and establish a connection with each at one time, which will automatically cause the download of the key/network ID pair to a device whose ID is in the list.
- USB stick with any of the previously described interfaces at the other end, like in particular FSK, RFID, IR, HMI Port or the like.
- a commissioning/maintenance adapter in particular a "pre- secured portable wireless" connection device, for an HMI Port is provided as commissioning device, comprising a WirelessHART adapter equipped with an HMI interface so it can be plugged directly onto the device to provide wireless connectivity during commissioning or maintenance.
- the FDT DTM Field Device Tool Device Type Manager
- the FDT DTM Field Device Tool Device Type Manager
- Said roaming adapter avoids the need for a handheld when distributing join keys to wireless devices, in particular wireless devices which have their own wireless connection once they have received the keys and/or in hybrid plants, where only some devices use wireless communication technologies, to parameterize the wired devices in the same way as the wireless ones.
- a secure connectivity over unsecure channels for all variants of key distribution and device parameterization is provided, using either standardized interfaces or the ABB HMI interface.
- the commissioning adapter may be used for configuring a wired or wireless device wirelessly.
- the commissioning adapter is equipped with at least two interfaces, in particular comprising a wireiessHART- and a FSK- interface.
- the commissioning adapter communicates with the wireiessHART gateway using the wireiessHART interface and device, which needs to be configured, using FSK interface.
- the commissioning adapter provides more flexibility and mobility for remotely device configuration and secure handing of network credentials.
- An exemplary setup is shown in Fig. 1.
- the commissioning adapter is acting in a similar way like the other WireiessHART field devices. It joins the wireiessHART network in the same manner as specified in wireiessHART standard. After joining the network it will be used as remote device configurator.
- the device which needs to be commissioned should have connection with
- the device commissioning related commands can be sent to the commissioning adapter via the wireiessHART Gateway. After receiving the commissioning command, the commissioning adapter will start the device commissioning operation and will send back the command execution result to the engineering workplace via response message.
- the commissioning adapter can have at least one of a RFID- or IR- HMI-Port or a combination thereof to establish or provide a connection to the field device which needs to be commissioned.
- a commissioning adapter by means of a commissioning adapter a secure network credentials handling may be provided, wherein from an engineering workplace the distribution of device network credentials is initiated and executed in a completely secure manner.
- a remote device diagnostic and troubleshooting operation is performed, wherein the commissioning adapter diagnoses the field device on the site location and sends the diagnostic information remotely to the network manager.
- an easy commissioning is provided by means of the commissioning adapter because device commissioning workflow will be easy as there is no need to use a handheld device for importing/exporting device credentials.
- join time of a device may be reduced and/or minimized.
- the radio transmissions in the physical layer are influenced without any modification to the field device to restrict the transmissions to a secure area. This is done by various means and at least one of setting transmission power to a level sufficiently high for local communication but low enough so communication cannot be overheard from outside of the commissioning area; encasing at least the antenna, if not the entire device, of device and gateway in a common, shielded housing; restricting the radio direction of device and gateway by shields/reflectors which are not part of the device but for the gateway may be part of a static gateway setup.
- the required interaction by the respective user according to the invention is a simple plug & play. Compared to a state-of-the-art handheld no manual parameterization task is needed, no knowledge of join keys is required. By integrating the secure connectivity with the DCS engineering clients, the join keys never need to be exposed or disclosed to a user.
- the invention relates to a method for a secure exchange of sensitive information of technical equipment, in particular by use of a system according to the invention as described above, whereas a secure wireless communication between at least two components and/or devices, in particular field devices, is provided and established by using communication means to ensure a secure near-range communication, in particular by restricting communication signals to a secure area and determining if a device is within a certain area and allow communication if it is or refuse to communicate if it is not, without the need to use higher protocol layers, like in particular authentication or encryption functionalities.
- device identification information is used to determine the trustworthiness of a communication partner.
- a verification step is executed by a human to yet increase the attained level of security.
- the radio transmissions in the physical layer are influenced without any modification to the field device to restrict the transmissions to a secure area.
- this is done by various means and at least one of setting transmission power to a level sufficiently high for local communication but low enough so communication cannot be overheard from outside of the commissioning area; encasing at least the antenna, if not the entire device, of device and gateway in a common, shielded housing; restricting the radio direction of device and gateway by shields/reflectors which are not part of the device but for the gateway may be part of a static gateway setup.
- the method for a secure exchange of sensitive information of technical equipment is applied to a commissioning network with a wireless gateway and uses a well-known Network ID and a shared Join Key wherein the devices joined in this network are visible to the respective Communication DTM (device type manager) for the wireless gateway in the same manner as devices connected to an FSK (Frequency Shift Keying) modem, thus any such device may be assigned to the target network, in particular by a commissioning engineer, and to secure this process, the identification information, in particular the device type, the manufacturer, the serial number or the like, or the device proximity to the commissioning network can be used by man or machine to check the legitimacy of the device; the latter is achieved by evaluating receive signal levels and used transmission energy.
- FSK defines a common frequency modulation technique.
- this commissioning network can be shared between all Communication DTMs and/or FDIs and/or communication servers, wherein device assignment is a manual task and accordingly not more than one such DTM or FDI or communication server might be opened at a time and communicates with the gateway.
- a handheld wherein the commissioning network is provided by a wireless handheld.
- the term "handheld” is synonymously used for all type of handheld devices or handheld computer, in particular mobile computers and/or mobile phones and /or cell phones and or smart phones and /or PDA ' s and/or handhelds or handheld organizers and or tablet computer, whereas a handheld is a relatively small hand-held computing device with an operating system and a power supply, in particular a battery or rechargeable accumulator power source.
- IR infrared
- RFID radio frequency identification
- a RFID key storage may be provided, wherein an RFID chip stores the join key.
- This key can, contrary to WirelessHART, be read from the chip but only from about half a meter of distance, what still seems to be very secure, in particular in view of the risk of tapping or interception. Presuming that the RFID chip still works even in a damaged device, device exchange on location is possible without any connection to the device management system; the handheld can read the key from the old device and download it into the replacement device.
- a number of key/device and network IDs may be retrieved and accessed via a key storage, for example acommissioning and/or handheld device for dedicated key storage and/or generation, which contains a storage unit for said key/device and network ID's and which is connected to the engineering client to receive a list of key/ID triples.
- a key storage for example acommissioning and/or handheld device for dedicated key storage and/or generation, which contains a storage unit for said key/device and network ID's and which is connected to the engineering client to receive a list of key/ID triples.
- a connection with each wireless device may be established at one time, which will automatically initiate and cause the download of the key/network ID pair to a device whose ID is the list.
- this key storage/commissioning device or handheld could be a USB stick with any of the previously described interfaces at the other end, like in particular FSK, RFID, IR, HMI Port or the like.
- a commissioning/maintenance adapter in particular a "pre- secured portable wireless" connection device, for a maintenance port, comprising a WirelessHART adapter equipped with an FSK interface so it can be plugged directly onto the device to provide wireless connectivity during commissioning or maintenance.
- the FDT DTM field device tool device type manager
- the FDT DTM field device tool device type manager
- Said roaming adapter avoids the need for a handheld when distributing join keys to wireless devices, in particular wireless devices which have their own wireless connection once they have received the keys and/or in hybrid plants, where only some devices use wireless communication technologies, to parameterize the wired devices in the same way as the wireless ones.
- a secure connectivity over unsecure channels for all variants of key distribution and device parameterization is provided, using either standardized interfaces or the ABB HMI interface.
- the required interaction by the respective user according to the invention is a simple plug & play. Compared to a state-of-the-art handheld no manual parameterization task is needed, no knowledge of join keys is required. By integrating the secure connectivity with the DCS (distributed control system) engineering clients, the join keys never need to be exposed or disclosed to a user.
- DCS distributed control system
- the figure 1 discloses a commissioning system for a secure exchange of sensitive information of technical equipment by use of at least one wireless connection comprising communication means which provide or include a commissioning network, wherein said dedicated commissioning network uses a well-known Network ID and a shared Join Key and which network is not used for any production purpose whatsoever, and wherein the devices 1 ,4,6,8, joined in this network are visible to the integration component for the wireless network or gateway such as a communication DTM (device type manager) or FDI gateway or communication device package instance for the WirelessHART Gateway 1 in the same manner as devices connected to an FSK (frequency shift keying) modem, thus any such device may be assigned to the target network, in particular by a commissioning engineer.
- a communication DTM device type manager
- FDI gateway communication device package instance for the WirelessHART Gateway 1
- the commissioning system for a secure exchange of sensitive information of technical equipment comprises at least three field devices 4,6,8 and
- communication means comprise a commissioning device and a wireless Hart network as commissioning network comprising a regular WirelessHART gateway 1 which in the wireless management system is integrated like a multi-drop wired modem, wherein a commissioning / maintenance adapter 10 for an HMI Port, in particular an FSK interface 12, is provided as commissioning device, comprising a WirelessHART adapter so it can be plugged directly onto the respective field device 4 to provide wireless connectivity during commissioning and/or maintenance, so that no join key or network credentials have to be exchanged.
- the commissioning adapter 10 may be used for configuring a wired or wireless device wirelessly, wherein the commissioning adapter is equipped with at least two interfaces, in particular comprising a WirelessHART- and a FSK- interface 12, wherein the commissioning adapter 10 communicates with the WirelessHART gateway 1 of the commissioning network using the WirelessHART interface and with the respective field device 4, which needs to be configured and/or commissioned using the FSK interface 12.
- the commissioning adapter 10 is acting in a similar way like the other WirelessHART field devices and joins the WirelessHART network in the same man- ner as specified in WirelessHART standard, wherein after joining the network it will be used as remote device configurator, wherein device commissioning related commands may be send to the commissioning adapter via the commissioning network gateway and in particular the WirelessHART gateway and wherein after receiving the commissioning command, the commissioning adapter will start the device commissioning operation and will send back the command execution result to the engineering workplace via response message.
- a secure network credentials handling may be provided, wherein from the engineering workplace the distribution of device network credentials is initiated and executed in a completely secure manner.
- a remote device diagnostic and troubleshooting operation is performed by the commissioning adapter, wherein the commissioning adapter diagnoses the field device on the site location and sends the diagnostic information remotely to the respective network manager.
- a commissioning network in particular a commissioning network comprising a regular wireless gateway which in the wireless management system is integrated like a multidrop wired modem, and a commissioning device is provided, wherein the commissioning device is connected to the field device which has to be commissioned and is connected to the commissioning network so that information can be exchanged and communication can be established between the at least one field device and the commissioning device and/or commissioning network securely, in particular to exchange one or more join keys and/or ID triples and/or commissioning commands and/or parameters.
- the commissioning network is shared between all Communication DTMs, wherein device assignment is a manual task and accordingly not more than one such DTM might be opened at
- the present invention also comprises any combination of preferred embodiments as well as individual features and developments provided they do not exclude each other.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Selective Calling Equipment (AREA)
Abstract
L'invention concerne un système de mise en service et un procédé correspondant pour un échange sécurisé d'informations sensibles afin de mettre en service et/ou de configurer des équipements techniques, comportant au moins deux éléments et/ou dispositifs, en particulier des dispositifs sur le terrain utilisant des moyens de communication pour sécuriser une communication sans fil, en particulier sans avoir besoin d'utiliser des couches de protocole supérieures, telles que des fonctionnalités d'authentification ou de chiffrement, lesdits moyens de communication comportant un dispositif et un réseau de mise en service, en particulier un réseau de mise en service comportant une passerelle sans fil standard qui, dans le système de gestion sans fil, est intégrée comme modem filaire multipoint, et/ou un dispositif de stockage de clés destiné au stockage et/ou à la génération de clés de jointure dédiées, ledit dispositif de stockage de clés comportant une unité de stockage pour un certain nombre de clés/périphériques et d'ID de réseau, et pouvant être connecté à un client d'ingénierie et/ou au dispositif de mise en service par l'intermédiaire d'une connexion filaire ou sans fil à courte portée, en particulier un appareil portatif et/ou une clé USB avec au moins une interface FSK/RFID/IR ou un port HMI ou autre, pour recevoir et/ou stocker une ou plusieurs clés de jointure et/ou des ID à trois chiffres.
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
IN1437KO2012 | 2012-12-20 | ||
IN1437/KOL/2012 | 2012-12-20 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2014094982A1 true WO2014094982A1 (fr) | 2014-06-26 |
Family
ID=49999861
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/EP2013/003657 WO2014094982A1 (fr) | 2012-12-20 | 2013-12-04 | Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques |
Country Status (1)
Country | Link |
---|---|
WO (1) | WO2014094982A1 (fr) |
Cited By (16)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP3291510A1 (fr) * | 2016-09-02 | 2018-03-07 | United Technologies Corporation | Caracterisation de dispositifs uniques ou multiples dans un systeme |
GB2558056A (en) * | 2016-10-24 | 2018-07-04 | Fisher Rosemount Systems Inc | Securely transporting data across a data diode for secured process control communications |
GB2558055A (en) * | 2016-10-24 | 2018-07-04 | Fisher Rosemount Systems Inc | Publishing data across a data diode for secured process control communications |
US10051345B2 (en) | 2014-02-28 | 2018-08-14 | United Technologies Corporation | Shielded electromagnetic communication with functional components of a machine |
CN108431705A (zh) * | 2015-10-12 | 2018-08-21 | 费希尔-罗斯蒙特系统公司 | 使用i/o抽象的现场设备配置的过程工厂中的配置 |
US10057663B2 (en) | 2014-02-28 | 2018-08-21 | United Technologies Corporation | Remote communication and powered sensing/control/identification devices |
US20180246499A1 (en) * | 2015-01-27 | 2018-08-30 | Nippon Seiki Co., Ltd. | Plant equipment state gathering system |
WO2019100150A1 (fr) * | 2017-11-24 | 2019-05-31 | Elsi Inc. | Dispositifs, systèmes et procédés de stockage et de gestion de manière sécurisée d'informations sensibles |
CN110383755A (zh) * | 2017-01-05 | 2019-10-25 | 皇家飞利浦有限公司 | 网络设备和可信第三方设备 |
US10619760B2 (en) | 2016-10-24 | 2020-04-14 | Fisher Controls International Llc | Time-series analytics for control valve health assessment |
US10877465B2 (en) | 2016-10-24 | 2020-12-29 | Fisher-Rosemount Systems, Inc. | Process device condition and performance monitoring |
CN113039498A (zh) * | 2018-11-14 | 2021-06-25 | Abb瑞士股份有限公司 | 在工业系统网络中调试现场设备的方法 |
CN113297091A (zh) * | 2021-06-18 | 2021-08-24 | 海光信息技术股份有限公司 | SoC芯片的调试方法、装置及SoC芯片 |
JP2022028747A (ja) * | 2014-10-02 | 2022-02-16 | フィッシャー-ローズマウント システムズ,インコーポレイテッド | 通信の促進方法、プラント無線アクセスポイント、及び非一時的有形コンピュータ可読媒体 |
US11438307B2 (en) | 2019-02-07 | 2022-09-06 | AO Kaspersky Lab | Systems and methods for configuring a gateway for protection of automated systems |
US11546367B2 (en) | 2019-02-07 | 2023-01-03 | AO Kaspersky Lab | Systems and methods for protecting automated systems using a gateway |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP2096505A1 (fr) * | 2008-02-26 | 2009-09-02 | ABB Research Ltd. | Procédé, produits et système pour la configuration d'un nouveau noed dans un réseau sans fil industriel |
US20100290351A1 (en) * | 2009-05-15 | 2010-11-18 | Fisher-Rosemount Systems, Inc. | Maintenance of wireless field devices |
US20120036568A1 (en) * | 2010-08-09 | 2012-02-09 | Yokogawa Electric Corporation | Provisioning device |
US20120237034A1 (en) * | 2007-11-13 | 2012-09-20 | Rosemount Inc. | Wireless mesh network with secure automatic key loads to wireless devices |
-
2013
- 2013-12-04 WO PCT/EP2013/003657 patent/WO2014094982A1/fr active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20120237034A1 (en) * | 2007-11-13 | 2012-09-20 | Rosemount Inc. | Wireless mesh network with secure automatic key loads to wireless devices |
EP2096505A1 (fr) * | 2008-02-26 | 2009-09-02 | ABB Research Ltd. | Procédé, produits et système pour la configuration d'un nouveau noed dans un réseau sans fil industriel |
US20100290351A1 (en) * | 2009-05-15 | 2010-11-18 | Fisher-Rosemount Systems, Inc. | Maintenance of wireless field devices |
US20120036568A1 (en) * | 2010-08-09 | 2012-02-09 | Yokogawa Electric Corporation | Provisioning device |
Non-Patent Citations (1)
Title |
---|
RAINER FALK ET AL: "Security Service for the Rollout of Security Credentials in Ubiquitous Industrial Automation Environments", SERVICE COMPUTATION 2010, 21 November 2010 (2010-11-21), pages 104 - 110, XP055073477, Retrieved from the Internet <URL:http://www.thinkmind.org/index.php?view=article&articleid=service_computation_2010_5_20_20033> [retrieved on 20130730] * |
Cited By (39)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10405066B2 (en) | 2014-02-28 | 2019-09-03 | United Technologies Corporation | Electromagnetic communication through components of a machine |
US10531166B2 (en) | 2014-02-28 | 2020-01-07 | United Technologies Corporation | Metal ceramic composite for electromagnetic signal transparent materials |
US10491970B2 (en) | 2014-02-28 | 2019-11-26 | United Technologies Corporation | Characterization of single or multiple devices in a system |
US10051345B2 (en) | 2014-02-28 | 2018-08-14 | United Technologies Corporation | Shielded electromagnetic communication with functional components of a machine |
US10484760B2 (en) | 2014-02-28 | 2019-11-19 | United Technologies Corporation | Electromagnetic communication from waveguide confinement |
US10057663B2 (en) | 2014-02-28 | 2018-08-21 | United Technologies Corporation | Remote communication and powered sensing/control/identification devices |
US10469920B2 (en) | 2014-02-28 | 2019-11-05 | United Technologies Corporation | Electromagnetic sensing of components in electromagnetic communication and method |
US10638207B2 (en) | 2014-02-28 | 2020-04-28 | United Technologies Corporation | Component counterfeit prevention |
US11089389B2 (en) | 2014-02-28 | 2021-08-10 | Raytheon Technologies Corporation | Remote communication and powered sensing/control/identification devices using high temperature compatible semiconductor materials |
US11937031B2 (en) | 2014-02-28 | 2024-03-19 | Rtx Corporation | Remote communication and powered sensing/control/identification devices using high temperature compatible semiconductor materials |
US10091562B2 (en) | 2014-02-28 | 2018-10-02 | United Technologies Corporation | Electromagnetic communication from waveguide confinement |
US10419831B2 (en) | 2014-02-28 | 2019-09-17 | United Technologies Corporation | Remote communication and powered sensing/control/identification devices using high temperature compatible semiconductor materials |
JP2022028747A (ja) * | 2014-10-02 | 2022-02-16 | フィッシャー-ローズマウント システムズ,インコーポレイテッド | 通信の促進方法、プラント無線アクセスポイント、及び非一時的有形コンピュータ可読媒体 |
JP7346520B2 (ja) | 2014-10-02 | 2023-09-19 | フィッシャー-ローズマウント システムズ,インコーポレイテッド | 通信の促進方法、プラント無線アクセスポイント、及び非一時的有形コンピュータ可読媒体 |
US10416659B2 (en) | 2015-01-27 | 2019-09-17 | Nippon Seiki Co., Ltd. | Plant equipment state gathering system |
US20180246499A1 (en) * | 2015-01-27 | 2018-08-30 | Nippon Seiki Co., Ltd. | Plant equipment state gathering system |
EP3252699A4 (fr) * | 2015-01-27 | 2018-10-10 | Nippon Seiki Co., Ltd. | Système de collecte de l'état d'équipements d'installations |
CN108431705A (zh) * | 2015-10-12 | 2018-08-21 | 费希尔-罗斯蒙特系统公司 | 使用i/o抽象的现场设备配置的过程工厂中的配置 |
CN108431705B (zh) * | 2015-10-12 | 2022-04-05 | 费希尔-罗斯蒙特系统公司 | 使用i/o抽象的现场设备配置的过程工厂中的配置 |
EP3291510A1 (fr) * | 2016-09-02 | 2018-03-07 | United Technologies Corporation | Caracterisation de dispositifs uniques ou multiples dans un systeme |
GB2558056B (en) * | 2016-10-24 | 2022-01-12 | Fisher Rosemount Systems Inc | Securely transporting data across a data diode for secured process control communications |
GB2558055B (en) * | 2016-10-24 | 2022-04-06 | Fisher Rosemount Systems Inc | Publishing data across a data diode for secured process control communications |
US10877465B2 (en) | 2016-10-24 | 2020-12-29 | Fisher-Rosemount Systems, Inc. | Process device condition and performance monitoring |
GB2558056A (en) * | 2016-10-24 | 2018-07-04 | Fisher Rosemount Systems Inc | Securely transporting data across a data diode for secured process control communications |
GB2558055A (en) * | 2016-10-24 | 2018-07-04 | Fisher Rosemount Systems Inc | Publishing data across a data diode for secured process control communications |
US10619760B2 (en) | 2016-10-24 | 2020-04-14 | Fisher Controls International Llc | Time-series analytics for control valve health assessment |
US11700232B2 (en) | 2016-10-24 | 2023-07-11 | Fisher-Rosemount Systems, Inc. | Publishing data across a data diode for secured process control communications |
US10530748B2 (en) | 2016-10-24 | 2020-01-07 | Fisher-Rosemount Systems, Inc. | Publishing data across a data diode for secured process control communications |
US11240201B2 (en) | 2016-10-24 | 2022-02-01 | Fisher-Rosemount Systems, Inc. | Publishing data across a data diode for secured process control communications |
CN110383755A (zh) * | 2017-01-05 | 2019-10-25 | 皇家飞利浦有限公司 | 网络设备和可信第三方设备 |
WO2019100150A1 (fr) * | 2017-11-24 | 2019-05-31 | Elsi Inc. | Dispositifs, systèmes et procédés de stockage et de gestion de manière sécurisée d'informations sensibles |
GB2583250A (en) * | 2017-11-24 | 2020-10-21 | Wolverton Jerry | Devices, systems, and methods for securely storing and managing sensitive information |
GB2583250B (en) * | 2017-11-24 | 2022-05-11 | Wolverton Jerry | Devices, systems, and methods for securely storing and managing sensitive information |
US11062050B2 (en) | 2017-11-24 | 2021-07-13 | Elsi Inc | Devices, systems, and methods for securely storing and managing sensitive information |
CN113039498A (zh) * | 2018-11-14 | 2021-06-25 | Abb瑞士股份有限公司 | 在工业系统网络中调试现场设备的方法 |
US11438307B2 (en) | 2019-02-07 | 2022-09-06 | AO Kaspersky Lab | Systems and methods for configuring a gateway for protection of automated systems |
US11546367B2 (en) | 2019-02-07 | 2023-01-03 | AO Kaspersky Lab | Systems and methods for protecting automated systems using a gateway |
CN113297091B (zh) * | 2021-06-18 | 2022-04-29 | 海光信息技术股份有限公司 | SoC芯片的调试方法、装置及SoC芯片 |
CN113297091A (zh) * | 2021-06-18 | 2021-08-24 | 海光信息技术股份有限公司 | SoC芯片的调试方法、装置及SoC芯片 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2014094982A1 (fr) | Procédé et système de mise en service pour un échange sécurisé d'informations sensibles pour la mise en service et à la configuration d'équipements techniques | |
JP5399554B2 (ja) | 無線フィールド機器の改善されたメンテナンス | |
CN101855854B (zh) | 向无线设备安全自动加载密钥的无线网格网络 | |
CN101960888B (zh) | 无线设备的连接密钥配置 | |
RU2666495C2 (ru) | Передатчик технологического параметра с беспроводным приемопередатчиком с питанием от контура | |
CN103885394B (zh) | 用于配置控制系统的现场设备的系统和方法 | |
JP2017516367A (ja) | ワイヤレスな電力計測およびメトリクス | |
JP6273155B2 (ja) | 情報設定装置、情報設定方法、情報設定プログラム、記録媒体、及び無線通信システム | |
CN103218876B (zh) | 远控智能电能表信息安全管理模块 | |
CN103198574B (zh) | 嵌有信息安全管理模块的远控智能水表 | |
CN106597873A (zh) | 用于对自动化设备进行远程维护的方法、装置和系统 | |
CN103152166A (zh) | 远控智能水表信息安全管理模块 | |
Haase et al. | Wireless sensor/actuator device configuration by NFC | |
CN103152175B (zh) | 远控智能燃气表信息安全管理模块 | |
CN107925630A (zh) | 机器对机器通信系统中的通信策略控制 | |
WO2014094983A1 (fr) | Système de mise en service et procédé pour un échange sécurisé d'informations sensibles en vue de la mise en service et de la configuration d'un équipement technique | |
CN203104484U (zh) | 远控智能燃气表信息安全管理模块 | |
KR20170039609A (ko) | 웨어러블 디바이스를 활용한 보안 강화 및 편의성 향상 방안 | |
Hjalmarsson et al. | Wireless remote control of a PLC system | |
CN105205363A (zh) | 一种水表信息安全管理模块 | |
CN206833185U (zh) | 借助各种类型的无线连接来控制空间内微气候的微气候控制设备 | |
Haase et al. | Configuration of smart embedded devices in the field using NFC | |
Trevisan | Automation system of powder-based 3D printer in the Industry 4.0 environment | |
CN104504815A (zh) | 嵌有信息安全管理模块的远控智能热能表 | |
Amidi et al. | An open, standard-based wireless network: connecting WirelessHART® sensor networks to Experion™ PKS using Honeywell’s OneWireless™ network |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13823934 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 13823934 Country of ref document: EP Kind code of ref document: A1 |