EP4097946A1 - Verfahren, vorrichtungen und computerprogramm für die verteilung von zertifikaten auf elektronische bauteile - Google Patents
Verfahren, vorrichtungen und computerprogramm für die verteilung von zertifikaten auf elektronische bauteileInfo
- Publication number
- EP4097946A1 EP4097946A1 EP21711753.0A EP21711753A EP4097946A1 EP 4097946 A1 EP4097946 A1 EP 4097946A1 EP 21711753 A EP21711753 A EP 21711753A EP 4097946 A1 EP4097946 A1 EP 4097946A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- certificate
- component
- distributor
- components
- file
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/33—User authentication using certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3265—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate chains, trees or paths; Hierarchical trust model
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/101—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measures for digital rights management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/30—Services specially adapted for particular environments, situations or purposes
- H04W4/40—Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
- H04W4/42—Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P] for mass transport vehicles, e.g. buses, trains or aircraft
Definitions
- the distributor of the component can be its manufacturer.
- the method described here preferably includes the following steps, in particular in the specified order:
- the root certificate in particular the trust anchor, the distributor and / or the manufacturer of the component is preferably part of the original programming of the component, also referred to as firmware.
- the root certificate is then in particular an X.509 root certificate.
- a closed security framework with certain certificates and components, identified by their identifiers, is thus defined.
- the self-signed certificate list file is then signed with a certificate from the distributor, this certificate from the distributor being traceable to the root certificate from the distributor and / or the manufacturer provided in step 1, for example via a certificate chain, also as a certificate Called chain.
- the component verifies the signature and the certificate of the signed certificate list file, in particular whether the certificate of the user with which the certificate list file is signed goes back to the root certificate of the user.
- the component optionally verifies whether the certificate with which the certificate list file is signed has the specific key usage and is thus authorized to sign the certificate list file.
- the component trusts the user's certificates that are contained in the certificate list file.
- steps 7, 8 and / or 9 are carried out again, for example when a new connection is established, the component that uses the self-signed certificates is restarted or a reboot takes place.
- the method described here is based in particular on the interaction of the distributor's root certificate and the unique identifier on the components with the self-signed certificate list file, so that a secure IT solution can be provided. This is especially true for users who do not have their own PKI.
- the method is applied to a large number of the components.
- the same self-signed certificate file is preferably uploaded to all components in step D).
- the underlying certificate list file includes the identifiers of all relevant components. It is therefore not necessary to create a separate certificate list file for each component.
- a data connection can only be established between those components that have successfully passed through the above process steps A) to E).
- a data connection can also be established to components that have one of the user's certificates, this certificate being contained in the certificate list file.
- those components can communicate with one another as intended that are explicitly authorized to do so by means of the certificates and the identifiers in the certificate list file.
- steps B), C) and D) are carried out by the distributor and / or by the manufacturer.
- the distributor and / or the manufacturer can exercise full control over the signing and optionally also over the creation of the certificate list file.
- the unsigned certificate list file can also be generated by the user and only the signing of the certificate list file is carried out by the distributor and / or manufacturer.
- step D) is carried out before the component is delivered to the user. Alternatively, step D) is carried out after delivery.
- the certificate of the distributor with which the certificate list file is signed has a special key usage, which indicates that this certificate is authorized to sign customer certificates. Accordingly, the component checks in step D) and / or in step E) before given whether the distributor's certificate has the special key usage.
- a computer program product comprising instructions which, when the program is executed by a computer or by a computer system, cause the program or causes it, in particular steps B), C) and D) or all steps of a method according to one or more carry out the above embodiments.
- Features of the computer program product are therefore also disclosed for the method and vice versa.
- the relevant program is partially or fully executed on the component.
- a component comprising a memory, a processor and a communication interface.
- the component is set up for a method as described in connection with one or more of the above-mentioned embodiments, in particular for method steps A) and E). Features of the component are therefore also disclosed for the method and vice versa.
- Figure 3 shows a schematic representation of a communication network with components described here
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Stored Programmes (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102020203915.1A DE102020203915A1 (de) | 2020-03-26 | 2020-03-26 | Verteilungsverfahren für Zertifikate auf elektronische Bauteile |
| PCT/EP2021/054771 WO2021190853A1 (de) | 2020-03-26 | 2021-02-26 | Verfahren, vorrichtungen und computerprogramm für die verteilung von zertifikaten auf elektronische bauteile |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4097946A1 true EP4097946A1 (de) | 2022-12-07 |
Family
ID=74873688
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP21711753.0A Pending EP4097946A1 (de) | 2020-03-26 | 2021-02-26 | Verfahren, vorrichtungen und computerprogramm für die verteilung von zertifikaten auf elektronische bauteile |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4097946A1 (de) |
| DE (1) | DE102020203915A1 (de) |
| WO (1) | WO2021190853A1 (de) |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20110276803A1 (en) * | 2010-05-10 | 2011-11-10 | Research In Motion Limited | System and method for multi-certificate and certificate authority strategy |
Family Cites Families (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7853790B2 (en) * | 2004-03-19 | 2010-12-14 | Microsoft Corporation | Enhancement to volume license keys |
| US8756675B2 (en) * | 2008-08-06 | 2014-06-17 | Silver Spring Networks, Inc. | Systems and methods for security in a wireless utility network |
| EP2608477B1 (de) | 2011-12-23 | 2014-03-19 | BlackBerry Limited | Vertrauenswürdige Zertifizierungsstelle zur Erstellung von Zertifizierungen basierend auf Verfahrenskapazitäten |
| DE102014102168A1 (de) | 2014-02-20 | 2015-09-03 | Phoenix Contact Gmbh & Co. Kg | Verfahren und System zum Erstellen und zur Gültigkeitsprüfung von Gerätezertifikaten |
| DE102015214696A1 (de) | 2015-07-31 | 2017-02-02 | Siemens Aktiengesellschaft | Vorrichtung und Verfahren zum Verwenden eines Kunden-Geräte-Zertifikats auf einem Gerät |
| DE102017214359A1 (de) | 2017-08-17 | 2019-02-21 | Siemens Aktiengesellschaft | Verfahren zum sicheren Ersetzen eines bereits in ein Gerät eingebrachten ersten Herstellerzertifikats |
| DE102017220490A1 (de) | 2017-11-16 | 2019-05-16 | Siemens Aktiengesellschaft | Verfahren und Vorrichtung zur Ermöglichung der Authentisierung von Erzeugnissen, insbesondere industriell gefertigten Geräten, sowie Computerprogrammprodukt |
| DE102018208201A1 (de) | 2018-05-24 | 2019-11-28 | Siemens Aktiengesellschaft | Anordnung und Verfahren zum Verändern des Inhalts eines Wurzelzertifikatsspeichers eines technischen Geräts |
-
2020
- 2020-03-26 DE DE102020203915.1A patent/DE102020203915A1/de not_active Withdrawn
-
2021
- 2021-02-26 EP EP21711753.0A patent/EP4097946A1/de active Pending
- 2021-02-26 WO PCT/EP2021/054771 patent/WO2021190853A1/de not_active Ceased
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20110276803A1 (en) * | 2010-05-10 | 2011-11-10 | Research In Motion Limited | System and method for multi-certificate and certificate authority strategy |
Also Published As
| Publication number | Publication date |
|---|---|
| DE102020203915A1 (de) | 2021-09-30 |
| WO2021190853A1 (de) | 2021-09-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE102015220224B4 (de) | Verfahren zur geschützten Kommunikation eines Fahrzeugs | |
| EP2936259B1 (de) | Aktualisieren eines digitalen geräte-zertifikats eines automatisierungsgeräts | |
| EP3649768B1 (de) | Verfahren zum sicheren ersetzen eines bereits in ein gerät eingebrachten ersten herstellerzertifikats | |
| WO2018036701A1 (de) | Gesichertes verarbeiten einer berechtigungsnachweisanfrage | |
| DE102020004832A1 (de) | Verfahren zur sicheren Ausstattung eines Fahrzeugs mit einem individuellen Zertifikat | |
| EP3417395B1 (de) | Nachweisen einer authentizität eines gerätes mithilfe eines berechtigungsnachweises | |
| DE102016218986A1 (de) | Verfahren zur Zugriffsverwaltung eines Fahrzeugs | |
| DE102015220228A1 (de) | Verfahren und System zur Absicherung einer erstmaligen Kontaktaufnahme eines Mobilgeräts mit einem Gerät | |
| EP3422274A1 (de) | Verfahren zur konfiguration oder änderung einer konfiguration eines bezahlterminals und/oder zur zuordnung eines bezahlterminals zu einem betreiber | |
| EP3244360A1 (de) | Verfahren zur registrierung von geräten, insbesondere von zugangskontrollvorrichtungen oder bezahl- bzw. verkaufsautomaten bei einem server eines systems, welches mehrere derartige geräte umfasst | |
| EP3697019A1 (de) | Verfahren zur bereitstellung eines herkunftsortnachweises für ein digitales schlüsselpaar | |
| EP4097946A1 (de) | Verfahren, vorrichtungen und computerprogramm für die verteilung von zertifikaten auf elektronische bauteile | |
| DE102009053230A1 (de) | Verfahren zur Autorisierung eines externen Systems auf einem Steuergerät eines Fahrzeugs, insbesondere eines Kraftfahrzeugs | |
| EP3767513B1 (de) | Verfahren zur sicheren durchführung einer fernsignatur sowie sicherheitssystem | |
| EP3435265A1 (de) | Verfahren zur sicheren authentifizierung bei mit einem server verbindbaren geräten, insbesondere bei zugangskontrollvorrichtungen oder bezahl- bzw. verkaufsautomaten eines zugangskontrollsystems | |
| DE102024117006A1 (de) | Digitaler Fahrzeugschlüssel für ein Kraftfahrzeug | |
| DE102025000375B3 (de) | Informationstechnisches System zum Einbringen von kryptografischen Schlüsseln in Recheneinheiten | |
| EP4097613A1 (de) | Verifizierungsverfahren für ein elektronisches bauteil und bauteil | |
| DE102024001629B3 (de) | Verfahren zur sicheren Ausstattung von Systemen mit einem individuellen Zertifikat | |
| DE102020202879A1 (de) | Verfahren und Vorrichtung zur Zertifizierung eines anwendungsspezifischen Schlüssels und zur Anforderung einer derartigen Zertifizierung | |
| DE102015208176A1 (de) | Gerät und Verfahren zur Autorisierung eines privaten kryptographischen Schlüssels in einem Gerät | |
| WO2021190854A1 (de) | Verteilungsverfahren für lizenzen auf elektronische bauteile | |
| WO2024046681A1 (de) | Verfahren zur authentifizierung von daten | |
| EP4672048A1 (de) | Verfahren und gerät zur bereitstellung und validierung kryptographisch gesicherter geräteidentitätsinformationen | |
| DE102024210000A1 (de) | Inbetriebnahme eines Fortbewegungsmittels in der Produktion |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20220831 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: SIEMENS MOBILITY GMBH |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20260210 |