ODVA further explained that the goal of process device profiles is to enable seamless device replacement by delivering plug-and-play type capabilities for process field devices to reduce the need for maintenance workers to be electronic device or Ethernet experts.
CIP Security pull model
The new pull model for CIP Security configuration data announced by ODVA in Hannover is an addition to the existing pull model for CIP Security certificates. This new model focuses on enabling more efficient distribution of device authenticity information.
According to ODVA, the new CIP Security pull model for configuration information will allow for parameters in JSON format to be automatically available for EtherNet/IP network-capable devices. This will make it possible for non-CIP devices, such as mobile phones and tablets, to access secure EtherNet/IP information. It also allows for hierarchical metadata to be more readily available.
With this addition, CIP Security now includes a pull model for configuration data and device certificates along with security properties, including a broad trust domain across a group of devices, a narrow trust domain by user and role, data confidentiality, device and user authentication, device and user identity, and device integrity.
“The addition of a CIP Security pull model for configuration makes it easier to replace devices to minimize downtime and allows for configuration data to be automatically provided to mobile devices and devices on a private network,” said Dr. Al Beydoun, president and executive director of ODVA. “CIP Security development is a continuous effort to help deter bad actors from accessing EtherNet/IP networks that enable efficient production in critical industries across the world.”
Use cases for the new CIP Security pull model for configuration include software that does not have CIP target functionality, such as with a mobile device application and with devices that are on a private network with Network Address Translation (NAT) that has configuration software on the public network.