Field Instrument · Est. 1986

HART Protocol Security

HART (Highway Addressable Remote Transducer) was developed in 1986 and is the most widely deployed digital field instrument protocol globally — with an estimated 40 million HART-enabled devices in service. It overlays FSK (Frequency Shift Keying) digital signals at 1200 baud on the existing 4-20mA analog current loop, allowing simultaneous analog process measurement and digital communication without disrupting the control signal.

The digital channel carries device diagnostics, configuration parameters, engineering units, and secondary variables that the analog signal cannot convey. HART-IP (2012) extends HART protocol over TCP/UDP networks, enabling integration with higher-level systems without dedicated hardware.

4-20mA + HART Architecture

The 4-20mA loop carries the primary process variable: 4mA represents 0% of range; 20mA represents 100%. The HART digital signal rides on top without interfering with the analog current. A HART master (handheld communicator or multiplexer) communicates with up to 15 devices per loop in multi-drop mode.

Security Vulnerabilities

HART Security Layer

HART 7 introduced an optional challenge-response authentication mechanism for write commands. When enabled, the device issues a challenge nonce; the master must respond with an HMAC computed from the nonce and a pre-shared device key. Without this layer, all HART write commands are unauthenticated. Field adoption is very limited.

Defences

ControlSREffect
Enable HART challenge-responseSR 1.2Authenticates write commands to field instruments
Restrict HART-IP port 5094SR 5.2Allow only asset management server IPs
Physical loop securitySR 5.1Restrict access to field junction boxes and marshalling panels
Calibration audit trailSR 2.8Log all trim/calibration changes for anomaly detection
⚡ Explore HART in ICSora Labs

Examine HART command structure, sensor spoofing via trim manipulation, and HART-IP network exposure in the interactive protocol lab.

Open HART Protocol Lab →