US2020394342A1PendingUtilityA1
System and method for administering physical security access to components of a process control system
Est. expiryMar 10, 2035(~8.6 yrs left)· nominal 20-yr term from priority
G07C 2209/64H04L 63/0428G07C 2009/00412G07C 9/00309G07C 9/00571H04L 63/10G06F 21/88G07C 2009/00365G06F 21/86
58
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system for restricting physical access to at least one component process control system component has a locking device that is integrated with process control system security administration data. The locking device accesses the process control system security data when authenticating a user. Upon authentication of a user for physical access to the particular process control component, the user may directly access the component for which the user is authorized. The system provides tracking of all authenticated users and attempts to access the various control system components.
Claims
exact text as granted — not AI-modified1 .- 6 . (canceled)
7 . A method for controlling physical access to at least one component of a process control system, comprising:
a. receiving user credentials by an electronic lock installed with an enclosure housing at least one component of said process control system; b. transmitting said user credentials and a lock address from said electronic lock to an access management component of a said process control system; c. requesting user granted permissions by said access management component from said process control system asset management component; d. identifying said enclosure by using said locking system network address; e. receiving physical access permissions of said enclosure by said asset management component from said electronic lock; f. validating by said asset management component whether said received physical access permissions are equivalent to said user granted permissions in said control system; g. providing access to the at least one component inside said enclosure if said user is validated for access to said enclosure contents, and preventing access if said user is not validated for access to said enclosure.
8 . The method of claim 7 , further comprising: h. transmitting an unauthorized access attempt alarm from said asset management component to an alarm system when a user is denied access to said enclosure.
9 . The method of claim 7 , further comprising: h. transmitting a user/enclosure access denied message to an audit system when a user is denied access to said enclosure.
10 . The method of claim 7 , further comprising: h. recording in an audit system the tracking date, time and enclosure name for when enclosure access is granted to a user.
11 . The method of claim 7 , further comprising: h. recording in an audit system the tracking date, time and enclosure name when enclosure access is denied to a user.
12 . A method for restricting physical access to at least one process control component inside an enclosure, the system comprising the enclosure, an electronic lock installed with the enclosure, a process control system having an access management component and an asset management component stored on a computer readable medium having computer readable instructions thereon that when executed by a processor, comprising:
a. receiving, by the access management system through an application programming interface, user credentials presented to said electronic lock and the corresponding electronic lock address; b. receiving, by the asset management system, the user credentials and electronic lock address from the access management component; c. retrieving the user role permissions defined by the asset management system using the user credentials; d. retrieving, by the asset management system, required permissions for accessing the at least one process control component housed in the enclosure; e. comparing, by the asset management system, the user role permission with the required access permissions for the at least one process control component; f. transmitting an open request over the application programming interface to the electronic lock with the user role required permissions; and g. permitting access if the user roles are equivalent and denying access if they are not equivalent.
13 . The system of claim 12 , wherein the steps further comprise:
a. retrieving a lockout status in the asset management system for the enclosure from a maintenance management component; and b. transmitting an open request to the enclosure electronic lock if the lockout status parameter is negative and restricting access to the enclosure if the lockout status parameter is affirmative.
14 . A system comprising:
a first enclosure having a first component for a computer system disposed therein; a first electronic lock configured to control physical access to the first component within the first enclosure; a first set of access permissions associated with the first electronic lock; a second enclosure disposed within the first enclosure, the second enclosure having a second component for a computer system disposed therein; a second electronic lock configured to control physical access to the second component within the second enclosure; and a second set of access permissions associated with the second electronic lock.
15 . The system of claim 14 , wherein the first set of access permissions is different from the second set of access permissions.
16 . The system of claim 14 further comprising user credentials operable to define access permissions for a user.
17 . The system of claim 16 , wherein physical access to the first and second enclosures is determined based on comparisons between the access permissions of the first and second sets respectively and the access permissions defined by the user credentials.
18 . The system of claim 17 , wherein physical access to the component in the second enclosure is permitted if the access permission defined by the user credentials satisfies the permission requirements of the first and second sets of enclosure permissions.
19 . The system of claim 16 , wherein the user credentials operate to permit the user to electronically access the computer component located within the enclosure.
20 . The system of claim 14 further comprising additional enclosures with additional computer components disposed within the first and/or the second enclosures.
21 . The system of claim 20 further comprising an audit system operable for logging data related to both successful and unsuccessful access events into each enclosure.
22 . The system of claim 14 further comprising:
a control system;
an access management component defined in the control system configured to tie the first enclosure, the first component and the first electronic lock to a first logical representation within the control system.
23 . The system of claim 22 , wherein the access management component of the control system is configured to tie the second enclosure, the second component and the second electronic lock to a second logical representation.Join the waitlist — get patent alerts
Track US2020394342A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.