Method for securing the authenticity of hardware and software in a networked system
Granted 10 Jun 2008 · 4 office actions
Current assignee: SIEMENS AKTIENGESELL SCHAFT · originally Siemens AG
Law firm: Law firm · Log in to unlock
Attorney: Attorney · Log in to unlock
Inventors: Uwe Retzow, Peter Eitel, Guido Heidt · Examiner: Nasser Moazzami · AU 2136 · TC 2100
Life of the application
19 dated eventsAbstract
The invention relates to a method for securing a networked system comprising system components having hardware and software modules connected via a system bus. According to the invention, the system components each comprise an authentication feature for the hardware modules and/or a further authentication and/or integrity securing feature each for the software modules. Further, a central testing module attached to the system bus for testing the authenticity features and/or the integrity securing features is provided.
Description
6 parts›CROSS-REFERENCE TO RELATED APPLICATION
This is a continuing application, under 35 U.S.C. §120, of copending international application No. PCT/EP01/01055, filed Feb. 1, 2001, which designated the United States; this application also claims the priority, under 35 U.S.C. §119, of European patent application No. 00 103 075.8, filed Feb. 15, 2000; the prior applications are herewith incorporated by reference in their entirety.
›FIELD OF THE INVENTION
The present invention relates to a method for securing a networked system comprising system components connected to hardware modules and software modules via a system bus.
›BACKGROUND OF THE INVENTION AND PRIOR ART
Such a system may for example be formed by the following scenarios:
system for remote inquiry of electricity meter readings over the power line or the power supply network, database server with accesses via clients client/server configuration comprising internal data exchange remote setting of devices remote inquiry of account balances system in a vehicle having networked processors/microcontrollers, in particular motor control, alarm system or central door safety system, etc.
Symmetric and asymmetric encryption methods are generally known, wherein a safe message channel between communication parties is formed. Further, symmetric and asymmetric methods, like for example a digital signature or a message authentication code (MAC) are generally used, wherein the authenticity and/or integrity of a message, a party, or a key may be tested by a reception unit. General basics are for example described in the book “Kryptographie” by W. Fumy and H. P. Rieβ, “Entwurf und Analyse symmetrischer Kryptosysteme”, R. Oldenburg Verlag Munchen, Wien, 1988.
›SUMMARY OF THE INVENTION
It is the object of the invention to protect the above mentioned hardware and software systems against unauthorized manipulation.
In accordance with the present invention, this object is achieved by a method for securing a networked system comprising system components connected to hardware modules and software modules via a system bus, the system components each comprise an authentication feature for the hardware modules and/or a further authentication or an integrity securing feature each for the software modules, and a central testing module attached to the system bus for testing the authentication features and/or the integrity securing features is provided.
The inventive method protects the hardware and software devices of a system against unauthorized changes and/or recognizes manipulations, in particular during the effective operation.
In one embodiment of the inventive method the external access to the devices of the system is secured. This includes among others the exchange or the renewal of system components and/or hardware and software components being part of the same.
Further advantageous implementations are stated in the dependent claims.
›BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1 illustrates a system comprising system components SK 1 to SKn connected via system bus SB.
›DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS
In the following, the invention is described using an embodiment illustrated in the FIGURE.
In the single FIGURE a system S is illustrated, comprising system components SK 1 to SKn connected via a system bus SB. The system components SK 1 to SKn comprise hardware and software modules which are not described in detail, formed according to the specific tasks of the individual system components SK 1 to SKn.
The system components SK 1 to SKn are for example realized by personal computers, printers, servers, but also by devices within a motor control, like for example processors and memory devices.
According to the invention, a central testing module PM connected to the system bus SB is provided within the system S. Further, the hardware modules in the system components SK 1 to SKn are provided with authentication features K 1 to Kn. Analogously, the software modules of the system components SK 1 to SKn comprise further authentication and/or integrity securing features S 1 to Sn.
The storage of the integrity securing features S 1 to Sn is optional according to the implementation of the system S.
The authentication features K 1 to Kn and/or the integrity securing features S 1 to Sn are preferably created at the end of the development process of the respective modules before the delivery. The authentication feature (K 1 to Kn) is for example the serial number of a hardware circuit and may for example be additionally provided with a date. The integrity securing features S 1 to Sn are preferably digital signatures using a public key method or symmetric authentication and/or integrity codes (MAC, Message Authentication Codes) created by a trustworthy entity.
The hardware/software devices of the respective system S are tested during effective operation. The testing may be performed by a so-called trap, i.e., upon a request of one of the system components SK 1 to SKn. The testing may also be carried out by a so-called polling, i.e., upon a request by the testing module PM. The testing of the authentication features K 1 to Kn or the integrity securing features S 1 to Sn is in any case done centrally within the testing module PM. The testing may for example be done by powering down and/or switching off the system S but for example also in specific time intervals during operation.
When recognizing inconsistencies, the system S may for example be shut down. It is further possible to output a more or less detailed message to an information module IM. To this end, the information module IM is for example directly connected to the testing module PM.
In one embodiment of the invention the testing module PM comprises an input/output interface EAS. This interface EAS forms the only access to the system S. I.e., via this interface EAS an external access to data and functions of the system S is accomplished. Here both an authentication and a testing of the access rights of the accessing person and/or entity is carried out.
A further type of access is for example the software update of corresponding modules within the system components SK 1 to SKn. In this context, again both testing of the accessing person and/or entity and determining the rights is accomplished to perform the corresponding update. Further, a first testing of the respective authentication and or the corresponding integrity securing feature (S 1 -Sn) of the software is accomplished. The same applies for the exchange of hardware modules in the system components SK 1 to SKn.
In the following, further embodiments of the invention are described.
Thus, the data exchange in testing the authentication features K 1 to Kn and the further authentication and/or integration securing features S 1 to Sn between the central testing module PM and the respective system components SK 1 to SKn may be secured. The securing may be accomplished by an internal digital signature or by an MAC (Message Authentication Code). Additionally, the exchanged data records may be encrypted. The cryptographic functions used within the system are independent of the cryptographic mechanisms by use of which for example the authentication features K 1 to Kn and the integrity securing features S 1 to Sn were created. In particular, theses mechanisms need not be implemented within the system components SK 1 to SKn, and a self-sufficient key management may further be used internally. The testing module PM having a corresponding implementation may function as the key distribution centre.
In a further embodiment of the invention, the formation of the authentication features K 1 to Kn of the hardware modules may also be taken over by crypto-functions within the system. In this context, the authentication features K 1 to Kn are for example created by the respective system S itself in an initialising step. Also this may be performed centrally within the testing module PM.
According to the respective safety requirements both symmetric and asymmetric crypto-methods may be applied externally and internally.
Claims as granted
10 claimsLog in to read the claims of this application.
Log in to unlockClassifications
17 codes- G06F21/57
- G06F21/51
- G06F21/73
- G09C1/00
- G06F11/30
- G06F12/14
- G06F1/00
- H04L9/10
- H04L12/28
- H04L9/32
- H04L29/06
Claim changes
SoonSee which claims were amended, added or cancelled during examination, with every added and removed word marked.
The published claims of this application are not paired with the granted ones in what we hold.
File wrapper
See the full prosecution history — every USPTO and applicant action on this file, in order.
Log in to unlockDocuments
Log in to open the documents of this file: the application as filed, every office action and response, the notice of allowance.
Log in to unlockChain of title
See the full assignment history — every owner this patent has passed through, with recordation dates and reel/frame numbers.
Log in to unlock