System and method for using digital signatures to assign permissions
US-9021267-B2 · Apr 28, 2015 · US
US10862676B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10862676-B2 |
| Application number | US-201815994705-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 31, 2018 |
| Priority date | May 31, 2017 |
| Publication date | Dec 8, 2020 |
| Grant date | Dec 8, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method is described for secure communication with a field measuring device of process measuring technology. A plurality of scopes of rights, and a plurality of public keys of a corresponding plurality of asymmetrical key pairs, are stored in the field measuring device. Each public key is assigned a scope of rights, and at least one private key of the corresponding plurality of asymmetric key pairs is stored in an external communicator. Upon establishing contact of the external communicator with the field measuring device, the external communicator identifies itself by a public-key authentication with the stored private key to the field measuring device. The field measuring device authenticates the external communicator using a suitable public key stored in the field measuring device. The field measuring device then opens an operating session in which the external communicator is granted access to the information technology content of the field measuring device.
Opening claim text (preview).
The invention claimed is: 1. A method for secure communication with a field measuring device of process measuring technology, wherein the field measuring device comprises a sensor, an evaluation unit, a fieldbus interface for the transmission of measurement data detected and provided by the field measuring device to other bus devices and/or to a process control system, and a communication interface, and wherein an external communicator has external access to information technology content of the field measuring device via the communication interface, wherein the information technology content is not the actual measurement data, the method comprising: storing a plurality of scopes of rights in the field measuring device, wherein each scope of rights defines to what extent the information technology content of the field measuring device can be accessed; storing a plurality of public keys of a corresponding plurality of asymmetrical key pairs in the field measuring device; assigning each public key a scope of rights; storing at least one private key of the corresponding plurality of asymmetric key pairs in the external communicator; upon establishing contact of the external communicator with the field measuring device via the communication interface, the external communicator identifies itself by a public-key authentication with the stored private key to the field measuring device; authenticating the external communicator using a suitable public key stored in the field measuring device; and after successful authentication, opening an operating session in which the external communicator is granted access to the information technology content of the field measuring device, namely in the scope of rights of the public key corresponding to the suitable private key. 2. The method according to claim 1 , wherein the communication interface is designed according to one of the following technologies: Bluetooth, wireless local area network, infrared, Ethernet. 3. The method according to claim 2 , wherein a scope of rights stored in the field measuring device allows access to a group of the following information technology content: parameters for representation of data without influence on metrological functions, parameters for commissioning of metrological functions, parameters for calibration of the field measuring device, parameters for special functions and service, parameters for activation of special functions. 4. The method according to claim 1 , wherein the same scopes of rights are stored in a plurality of field measuring devices and the same public keys of a corresponding plurality of asymmetric key pairs are stored. 5. The method according to claim 4 , wherein the plurality of field measuring devices belong to at least one of the following measuring device groups: the measuring device group of a specific measuring method, the measuring device group of a field measuring device model, the measuring device group of the field measuring devices of a specific user, the measuring device group of the field measuring devices of a system or a part of the system, the measuring device group of the field measuring devices of a certain time production interval or installation interval. 6. The method according to claim 1 , wherein the operating session is terminated after at least one of the following events: performing a predetermined number of accesses to the information technology content of the field measuring device, expiration of a predetermined period of time after the start of the operating session, transmission of information for the explicit termination of the operating session, occurrence of an error condition in the field measuring device. 7. The method according to claim 1 , wherein a plurality of private keys are stored in the external communicator and the external communicator identifies itself by a public-key authentication to the field meter in that identification data of the field measuring device is transmitted to the external communicator, the external communicator selects an suitable private key based on the identification data, and the external communicator identifies itself with the selected suitable private key to the field meter. 8. The method according to claim 1 , wherein the external communicator and the field measuring device connect via the communication interface by an encrypted secure shell network protocol (SSH), wherein the external communicator is authenticated for the field measuring device by public-key authentication. 9. A field measuring device of process measuring technology, comprising: a sensor; an evaluation unit; a fieldbus interface for the transmission of measured data detected and provided by the field measuring device to other bus devices and/or to a process control system; and a communication interface, wherein information technology content of the field measuring device is externally accessible for an external communicator via the communication interface and wherein the information technology content is not the actual measurement data; wherein a plurality of scopes of rights is stored in the field measuring device, wherein each scope of rights defines to what extent the information technology content of the field measuring device can be accessed; a plurality of public keys of a corresponding plurality of asymmetrical key pairs are stored in the field measuring device and each public key is assigned a scope of rights, wherein at least one private key of the corresponding plurality of asymmetric key pairs is stored in the external communicator; upon establishing contact of the external communicator with the field measuring device via the communication interface, the external communicator identifies itself by a public-key authentication with the stored private key to the field measuring device, the field measuring device authenticates the external communicator using a suitable public key stored in the field measuring device; and after successful authentication, the field measuring device opens an operating session in which the external communicator is granted access to the information technology content of the field measuring device, namely in the scope of rights of the public key corresponding to the suitable private key. 10. The field measuring device according to claim 9 , wherein the communication interface is designed according to one of the following technologies: Bluetooth, wireless local area network, infrared, Ethernet. 11. The field measuring device according to claim 9 , wherein a scope of rights stored in the field measuring device allows access to a group of the following information technology content: parameters for representation of data without influence on metrological functions, parameters for commissioning of metrological functions, parameters for calibration of the field measuring device, parameters for special functions and service, parameters for activation of special functions. 12. The field measuring device according to claim 9 , wherein the operating session is terminated after at least one of the following events: performing a predetermined number of accesses to the information technology content of the field measuring device, expiration of a predetermined period of time after the start of the operating session, transmission of information for the explicit termination of the operating session, occurrence of an error condition in the field measuring device. 13. The field measuring device according to claim 9 , wherein the communication interface implements an encrypted secure shell network protocol (SSH), so that an encrypted network connection can be produced with an external communicator via the comm
Program or device authentication · CPC title
by creating or determining hardware identification, e.g. serial numbers · CPC title
to a system of files or objects, e.g. local or distributed file system or database · CPC title
by local area network [LAN], network structure · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.