EP3476098A1 - Verfahren und anordnung zur gesicherten elektronischen datenkommunikation - Google Patents
Verfahren und anordnung zur gesicherten elektronischen datenkommunikationInfo
- Publication number
- EP3476098A1 EP3476098A1 EP17743301.8A EP17743301A EP3476098A1 EP 3476098 A1 EP3476098 A1 EP 3476098A1 EP 17743301 A EP17743301 A EP 17743301A EP 3476098 A1 EP3476098 A1 EP 3476098A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- zone
- key
- message
- secret
- information processing
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0442—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0825—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/065—Network architectures or network communication protocols for network security for supporting key management in a packet data network for group communications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3242—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
Definitions
- the invention relates to a method and an arrangement for secure electronic data communication according to the
- an information processing unit may publish a message without addressing a particular recipient. Potential recipients do not need to be aware of the publishing entity. It is also not necessary that the unit that publishes a message, a response message gets to the ver ⁇ -published message. On the other hand, depending ⁇ de can information-processing unit that is registered as a recipient of a message specific messages based on predetermined criteria subscribe.
- a block or packet-based data communications is considered generation, based for example on news datagrams Tele ⁇ programs, or the like, as opposed to a Stream-based data communication.
- information processing units are understood to be essentially technical units, in particular control programs of technical units.
- programs and / or processes that can be executed on a computer can be information processing units within the meaning of the present invention.
- Data communication includes any type of messages exchanged between the information processing units.
- such messages may serve to directly or indirectly control rail traffic. This applies, for example, the operation of switches and signal systems, the examination of track sections as to whether they are free or busy, and the like.
- the data communication can be cryptographically secured.
- each information processing unit consisting of a public key and a secret key assigned to a key pair
- a proof of authenticity a message publica ⁇ fentlichende unit generate in that these signs a ⁇ After directing means of the associated unit of the secret Keyring ⁇ sels. An entity that subscribes to this message can then verify that signature using the public key of the publishing entity.
- a disadvantage of this solution is that due to the very large ⁇ number of information processing units that are involved for example in the control of rail transport, the management and provision of all public keys and in particular the security of all secret key requires considerable effort.
- the object of the present invention is therefore to propose an arrangement and a method which reduces the complexity of providing secure electronic packet or block-based data communication in the context of a Decreased publish / subscribe model between information processing units while maintaining the same level of security.
- an arrangement for secure electronic data communication between information-processing units of the arrangement is provided. It is based on the publish / subscribe model and the kommunika ⁇ tion is secured on the basis of an asymmetric encryption method.
- Each of the information processing units is assigned to a zone secured by hardware, in which the respective information processing unit is arranged.
- Each of the zones is assigned at least one zone key pair, each consisting of a public zone key and a secret zone key.
- Each of the zones includes at least one formed as a hardware module from ⁇ encryption unit which is arranged to store the or the secret key secured zone and to perform cryptographic operations by means of the or the secret key zone and the zone or public key.
- the encryption unit is the only ⁇ A standardized to the appropriate zone, which has access to the secret or key zone.
- the inventive method for secure electronic data communication according to the publish / subscribe model Zvi ⁇ rule information processing units of an arrangement based on an asymmetric encryption method includes fully basically the step of:
- the zone key pair is generated in the zone itself, preferably by the encryption unit assigned to the zone.
- the secret Zo ⁇ nen knowl then never leaves the encryption unit and is thus optimally secured.
- An inventive hardware module is configured secured as an encryption unit includes at least a secret key of a key pair of an asymmetric encryption ⁇ systems to store and execute cryptographic Ope ⁇ nen by the secret key. Because the encryption unit is designed as a hardware module, not only stored in secret zone key is adequately secured, but by the encryption unit conducted cryptographic Opera ⁇ tions such. As encrypting, decrypting, digitally signing or verifying a digital signature, can be performed much faster compared to a functionally comparable software module. This brings great benefits, in particular in connection with applications, which have to meet real-time requirements.
- a computing unit in particular a server, comprises at least one hardware module according to the invention and at least one information-processing unit.
- the calculation unit is configured to support a method of the type described above and below in the role of a hardwaremä ⁇ SSIG secured zone.
- the invention is based on the realization that it is not necessary in vorlie ⁇ constricting context that a private Keyring ⁇ selschreib must be created for each one ⁇ zelne information processing unit, but that it is sufficient to group the suitable information processing units, that is defined, assigned to secure zones, and only each of these zones to assign a separate key pair, a so-called zone key pair.
- the term to be "hardware-secured” is understood to the effect that the corresponding zone against intrusion from the outside secured not only access rights or other software ⁇ medium, but at least also physically, by means of specific hardware resources.
- a zone by a computer in particular a server is provided. It is possible that a computer includes a plurality of various ⁇ dene zones in accordance with the present invention, and consequently, several serving as the encryption units of these zones hardware modules.
- zone in the more non-preferred, but possible case in that a zone comprises a plurality of computers, there are zone-internal connections between the computers which are separate and physically separate from connections to the outside.
- zone is used in the context of the present invention in accordance with a definition of this B egriffs used as z. In the standard IEC62443-3-3, under point 3.1.47.
- such information- processing units can be assigned to a zone that are already arranged in the zone. If the zone is provided for example by ei ⁇ nen server can be assigned on the server ⁇ executable programs or processes as an information-processing ⁇ de units this zone.
- the He-making ⁇ data communication may, in principle in a known manner based on the asymmetric system Ver etc. It does not matter whether the informati ⁇ onsverinde unit that publishes a message is assigned to the same zone as a message abon ⁇ nating information processing unit.
- a publication informa ⁇ tion processing unit may be arranged, one (in the Re ⁇ gel cryptographically secure sender information z.
- a subscribing information processing unit is then arranged to evaluate the sender information to determine the identity of the publishing entity.
- a first information processing unit of a first region is configured to publish a ⁇ After reporting. The message is then likewiseis cryptographically secured under Ver ⁇ application of the associated secret zone of the first zone.
- a second informati ⁇ onsveronde unit is adapted to authenticate the message un ⁇ ter using the associated public zone of the first zone key as a message that has been sent from an information processing unit of the first zone.
- the first information processing unit may be adapted, a sender information in the message to integrie ⁇ ren.
- the second information processing unit may be adapted to evaluate the sender information to determine the identity of the sender of the message.
- the step of publishing a message following substeps umfas ⁇ can sen:
- the message is created by the first information processing unit. Then, a hash value of the message is determined, preferably by the first informationsverarbei ⁇ tend unit itself. Alternatively, the formation of the Hashwer- tes also be performed by the encryption unit of the corresponding zone.
- the hash value is digitally signed by the encryption unit of the zone to which the first information-processing unit is assigned by means of the secret zone key information assigned to the zone and stored in the encryption unit. This can for example take place in that the hash value is encrypted by the secret Zonenschlüs ⁇ sels.
- the signed hash value is then appended to the message by the first information processing unit and the
- the step of authenticating the message by the second information processing unit then comprises, prior ⁇ preferably the following partial steps:
- the verified hash value is then compared to the reference hash value. Only in case of a match is the message considered authentic - that is, a message published by an information processing unit of the first zone.
- the encryption unit of each zone is directed a ⁇ comprising to generate a new zone ⁇ en public key and a new secret key zone, the zone for a new zone key pair.
- the keys assigned to a zone are preferably exchanged at regular or irregular intervals.
- the new public zone key can then be published by the encryption unit via a message. This message will be secured by means of the previous ge ⁇ heimen key zone of the zone.
- Each information-processing unit that subscribes to this message is thereby informed about an exchange of the key pair in the corresponding zone and, after receiving the new public zone key of that zone, can also authenticate such messages, which are then encrypted using the newly created secret zone key of this kryptogra - be secured phically.
- the encryption unit is therefore preferably also set up to at least temporarily store various secret zone keys in a secure manner.
- Different solutions can be found to publish the initial public zone shell. In principle, it must be ensured that no public zone keys are introduced into the system without authorization. A possibility friendliness is part of all zones to provide the key with conventionally known ⁇ th digital certificates from a part of the system, ie, trusted certification respected ⁇ fiz istsinstanz. Alternatively, all zones can be equipped with a secret master key, by means of which the initial public zone key can be securely published. Finally, there is the possibility that public zone keys will be distributed between adjacent zones via secure communication channels existing between these zones, for example based on a Diff / Hellman method.
- the encryption unit simultaneously stores various secret zone keys, also of different lengths. These various secret zone keys are associated in a conventionally known manner respective public zone key corresponding length.
- the method may include the steps of: generating a further zone key pair be ⁇ standing from a further public zone key and a further secret-zone key, wherein the key ⁇ length of the key of the further zone key pair on the key length, the key of the zone key pair deviate ⁇ chen can.
- the further zone key pair is associated with the respective zone and the further secret Zonenschlüs ⁇ sel is stored secured in the encryption unit of the zone.
- a zone can be assigned, for example, four zone tags of different length, for example with the bowl ⁇ lengths 40 bits, 80 bits, 200 bits and 400 bits. The shorter the keys, the more often they are exchanged.
- a message to publish a newly generated public key zone by means of the old secret key zone - of the sliding surfaces ⁇ length - is cryptographically secured, according to a a message for publishing a new public zone key of a first length is cryptographically secured by means of a secret Zo ⁇ nen everybodyls a second length, wherein the second key length exceeds the first key length.
- a 40-bit key is secured, for example by means of an 80-bit key, an 80-bit Schlüs ⁇ sel means of a 200-bit key, etc. Since in the context of data communication in the arrangement basically every published message in the above ⁇ be written It should be ensured that the creation and checking of the corresponding signatures can be carried out quickly, for example in connection with railway signaling technology.
- the time required to create or verify a signature, ie in particular to encrypt and decrypt a hash value via a message again depends directly on the length of the keys used. DA ago shorter secret zone key to back up very often published ⁇ lichenden messages are used in a preferred embodiment.
- shorter zone secret keys should then be correspondingly more frequently by new ge ⁇ home-zone key (of the same length) is replaced, in the manner described above.
- Longer secret zone keys can be used to back up messages that are published less often, such as a message. B. News with which newly generated public zone key ver ⁇ shares. Longer keys offer greater security than shorter keys.
- the method may include the steps of:
- the backup by means of the two secret keys is carried out separately, as described above, ie the message is attached two digitally signed hash values, one of which is signed by means of the first secret zone key and the second by means of the second secret zone key. It ver ⁇ is that more than two secret zone keys, for example three or four, can be used to save a message cryptographically.
- a subscribing unit only needs a check of the signatures at ⁇ .
- each message may be sent using the "old" secret zone key and the "new", ie. H. of the newly created secret zone key. After a predetermined time can then be dispensed with the backup using the "old" secret zone key.
- FIG. 1 steps of a method according to the invention.
- FIG. 1 shows an arrangement 10 for secure electronic data communication, as could be done, for example, in railroad signaling technology.
- the arrangement 10 comprises a plurality of information processing units 21, 22, 23, 31, 32, 33, between which the data communication takes place via a data communication network 40.
- the data communication takes place by the so-called ⁇ publish / subscribe model.
- a message is published by an information processing unit 21, without specifically addressing one or more recipients of the message, similar to a broadcast or multicast method.
- Each information processing ⁇ A standardized 22, 23, 31, 32, 33 can subscribe to particular messages according to predetermined criteria, that is, register as a recipient of a message.
- a message can also be subscribed to by a plurality of information processing units 22, 23, 31, 32, 33.
- the information processing units 21, 22, 23, 31, 32, 33 are each assigned to different hardware-secured zones 20, 30, d. H. Each of the information-processing units is assigned to one of the zones 20, 30.
- Zones 20, 30 are hardware-based and optionally additionally formed by software in such a way that an unauthorized intrusion from the outside into the zone 20, 30 is not possible.
- the Number of zones is variable and can be greater than two. The example in FIG. 1 is limited to the two zones 20, 30 for the sake of simplicity.
- an information processing unit 21, 31 is assigned to the zone 20, 30 in which it is arranged.
- the first group of information processing units 21, 22, 23 corresponds to one in the embodiment shown
- This server 42 is connected to the data communication network 40 and may be arranged, for example, in a control center or the like. From this server 42 news are published by subscribing which of informationsverarbei ⁇ Tenden units of the same or a different zone 30 can be defined.
- Such other information processing units 31, 32, 33 may be, for example, control programs of technical devices, for example controllers of switches or signal systems.
- the information processing units 31, 32, 33 are associated with a various of the first zone 20 second zone 30 which is provided on a white ⁇ direct server 44, which is also connected to the data communication network 40th
- Each of the zones 20, 30 is assigned a zone key pair 120, 130, each comprising a public zone key 122, 132 and a secret zone key 124, 134, whereby an authenticatable data communication between information processing units 21, 22, 23, 31, 32, 33 , can be carried out regardless of the zone belonging, as is described below with reference to Fig. 2 in more detail Darge ⁇ is.
- Each of the zones 20, 30 each comprises an opening formed as a hardware module encryption unit 25, 35. That is turned ⁇ directed, at least in the zone 20, 30 respectively associated secret key zone 124, 134 secured to stores.
- the encryption unit 25 of a zone 20 stores, in addition also the respective associated public zone keys 122, and optionally the public zones ⁇ key 132 in other areas 30.
- the encryption unit 25, 35 is established, cryptographic operations using the secret zone key 124 to execute 134th
- the information processing units 21, 22, 23, a zone 20 are each arranged to communicate with the Ver Bachlungsein ⁇ standardized 25 of the zone 20, for example, the encryption unit 25 digital data to be signed to give and receive signed data.
- Fig. 2 are steps of a method for secure electronic data communication according to the
- each of the information processing units 21, 22, 23, 31, 32, 33 of the hardware secured zone 20, 30 is assigned, in which the respective unit is angeord ⁇ net.
- the number of zones is not limited to two. The number of information processing units per zone is variable.
- step S2 the individual zones 20, 30 see cryptographic key assigned by means of which then an nachfol ⁇ constricting data communication between the information processing units 21, 31 secured, in particular can be made authenticated.
- step S2.1 a zone key pair 120, 130 is first generated for each of the zones 20, 30.
- Such a zone key pair comprises in each case a public zone key 122, 132 and a secret zone key 124, 134.
- step S2.2 each zone 20, 30 which for this zone, he testified ⁇ zone key pair 120, is assigned to the 130th
- step S2.3 of a zone 20 30 associated with the behest ⁇ zone me key 124 is stored secured 30 134 in the encryption unit 25, 35 of the respective zone 20.
- the information processing units 21, 31 of a zone 20, 30 generally have no access to the secret zone key 124, 134.
- the public zone keys 122, 132 can be provided in a conventionally known manner to all information-processing units or all zones 20, 30 of the arrangement 10.
- step S3 a tendency informationsverarbei ⁇ unit 21 of the first group 20 then publishes a message, which can be subscribed to by any other information processing units 22, 31st The message is digitally signed by means of the secret key 124 of the first zone 20.
- a hash value is first formed over the message. This hash value is then signed by the encryption unit 25 using the secret key zone, ⁇ example, by the hash value is encrypted by this secret Zonenschlüs ⁇ sels 124th Subsequently, the Locks ⁇ doubted hash value of the message is attached and the message will be published along with the encrypted hash value appended.
- the information processing unit 31 may, after receiving the message, Judges the origin of the message at step S4 characterized Che ⁇ fen that it verifies the digital signature using the public key zone 122 of the first zone 20th More specifically, unit 31 may form a reference hash via the message.
- the decrypted hash value matches the refer- ence hash value, it is assumed that the post ⁇ directing actually comes from the zone 20th
- the infor ⁇ mationsver formatden units 31, 32, 33 of the second zone 30 on the server 44 may, for example, in such a way be arranged to subscribe and further process only messages originating from the server 42, ie signed by means of the secret zone key assigned to the first zone 20.
- the exact sender identity ie which of the information processing units 21, 22, 23 the message Additionally, for example, it may be coded in a header of the message.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Power Engineering (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- Mathematical Physics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102016215520.2A DE102016215520A1 (de) | 2016-08-18 | 2016-08-18 | Verfahren und Anordnung zur gesicherten elektronischen Datenkommunikation |
| PCT/EP2017/068072 WO2018033326A1 (de) | 2016-08-18 | 2017-07-18 | Verfahren und anordnung zur gesicherten elektronischen datenkommunikation |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3476098A1 true EP3476098A1 (de) | 2019-05-01 |
Family
ID=59399408
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP17743301.8A Withdrawn EP3476098A1 (de) | 2016-08-18 | 2017-07-18 | Verfahren und anordnung zur gesicherten elektronischen datenkommunikation |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20210297245A1 (de) |
| EP (1) | EP3476098A1 (de) |
| CN (1) | CN109644185A (de) |
| DE (1) | DE102016215520A1 (de) |
| WO (1) | WO2018033326A1 (de) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11088981B2 (en) * | 2017-09-26 | 2021-08-10 | Amazon Technologies, Inc. | Receiving a data object at a device |
| DE102018203072A1 (de) | 2018-03-01 | 2019-09-05 | Siemens Aktiengesellschaft | Verfahren und Anordnung zum gesicherten Übertragen einer Nachricht von einer Sendeeinrichtung zu einer Empfangseinrichtung |
| CN110266783B (zh) * | 2019-06-13 | 2022-02-22 | 中国铁道科学研究院集团有限公司通信信号研究所 | 一种基于dds的铁路ctc系统通信平台 |
| DE102020216277A1 (de) | 2020-12-18 | 2022-06-23 | Siemens Mobility GmbH | Verfahren zur initialen Verteilung von schützenswerten Daten in einem ETCS-Zugsicherungssystem |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013117404A1 (de) * | 2012-02-07 | 2013-08-15 | Bundesdruckerei Gmbh | Verfahren zur personalisierung eines smart meter oder smart meter gateway sicherheitsmoduls |
| WO2015149836A1 (en) * | 2014-03-31 | 2015-10-08 | Irdeto B.V. | Cryptographic chip and related methods |
| WO2016099644A1 (en) * | 2014-12-19 | 2016-06-23 | Private Machines Inc. | Systems and methods for using extended hardware security modules |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7089211B1 (en) * | 2000-01-12 | 2006-08-08 | Cisco Technology, Inc. | Directory enabled secure multicast group communications |
| US20030204741A1 (en) * | 2002-04-26 | 2003-10-30 | Isadore Schoen | Secure PKI proxy and method for instant messaging clients |
| BR112012028616A2 (pt) * | 2010-05-14 | 2016-08-02 | Siemens Ag | método para distribuição de chave de grupo dedicado em sistemas que empregam eventos genéricos de subestação orientados a objeto e controlador de grupo para uma rede que compreende dispositivos de campo |
| JP5786670B2 (ja) * | 2011-11-17 | 2015-09-30 | ソニー株式会社 | 情報処理装置、情報記憶装置、情報処理システム、および情報処理方法、並びにプログラム |
| US9049011B1 (en) * | 2012-08-15 | 2015-06-02 | Washington State University | Secure key storage and distribution |
| US9239933B2 (en) * | 2013-06-14 | 2016-01-19 | Richard Chuang | Piracy prevention and usage control system using access-controlled encrypted data containers |
| EP2890084B1 (de) * | 2013-12-31 | 2018-04-18 | Thales Nederland B.V. | Datensicherungssystem und -verfahren |
| CN104158816A (zh) * | 2014-08-25 | 2014-11-19 | 中国科学院声学研究所 | 认证方法、装置和服务器 |
| CN105634736A (zh) * | 2014-10-28 | 2016-06-01 | 艾优有限公司 | 用于对数据进行加密的方法 |
| US10341103B2 (en) * | 2015-01-29 | 2019-07-02 | Entit Software Llc | Data analytics on encrypted data elements |
-
2016
- 2016-08-18 DE DE102016215520.2A patent/DE102016215520A1/de not_active Withdrawn
-
2017
- 2017-07-18 WO PCT/EP2017/068072 patent/WO2018033326A1/de not_active Ceased
- 2017-07-18 CN CN201780050943.7A patent/CN109644185A/zh active Pending
- 2017-07-18 EP EP17743301.8A patent/EP3476098A1/de not_active Withdrawn
- 2017-07-18 US US16/326,439 patent/US20210297245A1/en not_active Abandoned
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013117404A1 (de) * | 2012-02-07 | 2013-08-15 | Bundesdruckerei Gmbh | Verfahren zur personalisierung eines smart meter oder smart meter gateway sicherheitsmoduls |
| WO2015149836A1 (en) * | 2014-03-31 | 2015-10-08 | Irdeto B.V. | Cryptographic chip and related methods |
| WO2016099644A1 (en) * | 2014-12-19 | 2016-06-23 | Private Machines Inc. | Systems and methods for using extended hardware security modules |
Non-Patent Citations (2)
| Title |
|---|
| MARKO WOLF ET AL: "Design, Implementation, and Evaluation of a Vehicular Hardware Security Module", 30 November 2011, INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2011, SPRINGER BERLIN HEIDELBERG, BERLIN, HEIDELBERG, PAGE(S) 302 - 318, ISBN: 978-3-642-31911-2, XP047011554 * |
| See also references of WO2018033326A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20210297245A1 (en) | 2021-09-23 |
| CN109644185A (zh) | 2019-04-16 |
| DE102016215520A1 (de) | 2018-02-22 |
| WO2018033326A1 (de) | 2018-02-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3649768B1 (de) | Verfahren zum sicheren ersetzen eines bereits in ein gerät eingebrachten ersten herstellerzertifikats | |
| DE102015220224B4 (de) | Verfahren zur geschützten Kommunikation eines Fahrzeugs | |
| DE102010027586B4 (de) | Verfahren zum kryptographischen Schutz einer Applikation | |
| DE102016224537B4 (de) | Masterblockchain | |
| EP3488557A1 (de) | Absichern einer gerätenutzungsinformation eines gerätes | |
| DE102013206185A1 (de) | Verfahren zur Erkennung einer Manipulation eines Sensors und/oder von Sensordaten des Sensors | |
| EP2863610B1 (de) | Verfahren und System zum manipulationssicheren Bereitstellen mehrerer digitaler Zertifikate für mehrere öffentliche Schlüssel eines Geräts | |
| EP3476098A1 (de) | Verfahren und anordnung zur gesicherten elektronischen datenkommunikation | |
| EP3910875B1 (de) | Konzept zum austausch von kryptographischen schlüsselinformationen | |
| EP3791534B1 (de) | Verfahren zum sichern eines datenaustausches in einer verteilten infrastruktur | |
| EP3881486B1 (de) | Verfahren zur bereitstellung eines herkunftsortnachweises für ein digitales schlüsselpaar | |
| DE102021001919A1 (de) | Verfahren zum sicheren Verteilen eines Softwareupdates | |
| EP2730050A1 (de) | Verfahren zur erstellung und überprüfung einer elektronischen pseudonymen signatur | |
| EP3954082B1 (de) | Verfahren zum sicheren austausch von verschlüsselten nachrichten | |
| EP3955509A1 (de) | Bereitstellung von quantenschlüsseln in einem netzwerk | |
| EP4662829A1 (de) | Beglaubigung von daten eines authentisierungs- und schlüsselvereinbarungsprotokoll-ablaufs | |
| DE102019216203A1 (de) | Auf Blockverschlüsselung basierender Proof-of-Work | |
| DE102014213454A1 (de) | Verfahren und System zur Erkennung einer Manipulation von Datensätzen | |
| EP3955508B1 (de) | Austausch quantensicherer schlüssel zwischen lokalen netzen | |
| EP3288215A1 (de) | Verfahren und vorrichtung zur ausgabe von authentizitätsbescheinigungen sowie ein sicherheitsmodul | |
| DE102025000375B3 (de) | Informationstechnisches System zum Einbringen von kryptografischen Schlüsseln in Recheneinheiten | |
| DE102010021655A1 (de) | Verfahren zum Bereitstellen von EDRM (Enterprise Digital Rights Management) geschützten Datenobjekten | |
| EP4436097A1 (de) | Verfahren und system zur kryptographisch abgesicherten datenübertragung | |
| EP3754931B1 (de) | Verfahren zur manipulationssicheren datenübertragung | |
| WO2026047256A1 (de) | Computerimplementiertes verfahren zum erstellen von signierten zertifikaten |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20190122 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20200902 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20220426 |