EP4430805A1 - Verfahren zum erkennen von manipulation von daten in einem netzwerk - Google Patents
Verfahren zum erkennen von manipulation von daten in einem netzwerkInfo
- Publication number
- EP4430805A1 EP4430805A1 EP22812675.1A EP22812675A EP4430805A1 EP 4430805 A1 EP4430805 A1 EP 4430805A1 EP 22812675 A EP22812675 A EP 22812675A EP 4430805 A1 EP4430805 A1 EP 4430805A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- key
- public
- data
- private
- signature
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/126—Applying verification of the received information the source of the received data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3268—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B19/00—Program-control systems
- G05B19/02—Program-control systems electric
- G05B19/04—Program control other than numerical control, i.e. in sequence controllers or logic controllers
- G05B19/042—Program control other than numerical control, i.e. in sequence controllers or logic controllers using digital processors
- G05B19/0428—Safety, monitoring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
Definitions
- the invention relates to a method for detecting manipulation of data which is sent in a network comprising a field device of measurement/automation technology and a receiving device.
- Data can be transmitted in a secure manner, for example by encryption and subsequent decryption in a network, see DE202006000817T2.
- encryption and subsequent decryption in a network see DE202006000817T2.
- Encryption and subsequent decryption requires knowledge of the public keys of each data recipient.
- the object is solved by a method according to independent claim 1 .
- a method for detecting manipulation of data from a field device of measurement and automation technology which data is sent in the form of data packets within a network via an insecure communication channel to a receiving device
- the field device being part of a secure subnet formed from at least one subnetwork device is, which subnet comprises at least the field device of the measurement and automation technology or an edge device and at least the field device of the measurement and automation technology, with a device key pair with a private device key and a public device key being generated by means of an asymmetric cryptosystem in a first method step
- the private device key is stored in a signing subnetwork device
- the signing subnetwork device generates a digital data signature for a group of data packets comprising at least one data packet using the private device key and this digital data signature and the group of data packets for Receiving device transmits
- the receiving device sending the group of at least one data packet by means of a digital data signature and the associated group of data packets can be sent together
- the data can include, for example, measurement data and/or device characteristic data from a field device in measurement/automation technology.
- a cryptosystem such as RSA or ECC (Elliptic Curve Cryptography) can be used as an asymmetric cryptosystem.
- ECC Elliptic Curve Cryptography
- the person skilled in the art uses a cryptosystem of his choice. This exploits the fact that a private key can be used to create a signature for data, which data can then be verified using the signature and a public key belonging to the private key.
- the data to be transmitted are digitally signed using the private device key and can therefore be verified using the public device key.
- an affiliation of data groups and digital data signatures is documented using time stamps.
- the generation of the digital data signature can be applied to a hash value of the group of data packets.
- a master key pair with a private master key and a public master key is also generated, the public device key being verifiable using the public master key, and the private device key being stored in the signing subnetwork device, with the public device key being verifiable by the public master key a digital key signature for the public device key is created using the private master key, wherein the receiving device verifies the public device key using the public master key.
- the digital key signature can be sent together with the public device key or the digital key signature can be attached to the public device key.
- the data to be transmitted are digitally signed using the private device key and the public device key used to verify the data is itself verifiable.
- a security chain can be set up that can be checked at any time and by anyone, so that an undetectable manipulation of the data is ruled out from practically relevant points of view.
- a security chain can be set up that can be checked at any time and by anyone, so that an undetectable manipulation of the data is ruled out from practically relevant points of view.
- the security chain can be guaranteed by the owner of the private device key, for example by the manufacturer of the field device of measurement/automation technology.
- the digital key signature of the public device key is provided by a subnetwork device, in particular by the signing subnetwork device. In this way, anyone can use the public master key to verify the public device key and thus the transmitted data.
- the private device key is stored in a secure manner in the signing subnet device, for example by means of a TPM (Trusted Platform Module) chip.
- TPM Trusted Platform Module
- the signing subnetwork device is a field device of measurement/automation technology or an edge device in a network with at least one such field device.
- the device public key is provided over the channel so that it is publicly available.
- the main key pair is generated by the manufacturer of the signing subnetwork device or of the field device of the measuring/automation technology.
- the device key pair is predefined, for example by a manufacturer of a TPM chip, or is created during production of the signing subnet device.
- the device key pair is generated by the manufacturer of the signing subnetwork device or by the signing subnetwork device itself.
- Fig. 1 describes an exemplary system according to the invention for implementing the method according to the invention, comprising a secure subnet 1, from which subnet data such as measurement data from a field device of measurement and automation technology 1.1 (see Fig. 2) is transmitted via an insecure communication channel 3, for example, in the form of data packets 11 be sent to a receiving device 2.
- a generator 5.1 of a device key pair provides the device key pair SG with a public device key SGO and a private device key SPG for a signing subnetwork device SSG.
- the signing subnet device is set up to sign this data of the field device 1.1 with the private device key.
- the signing subnetwork device SSG can be the field device 1.1, or also an edge device 1.2 (see Fig. 2), which, if present, is set up to enable communication from field devices 1.1 of the subnetwork 1 to the receiving device 2 to allow.
- a generator 5.2 of a master key pair with a public master key SHO and a private master key SHP can provide the public master key SHO in the network. Both pairs of keys are based on an asymmetric cryptosystem such as RSA or ECC (Elliptic Curve Cryptography) or a method derived from them.
- a digital key signature 30 of the public device key can be created and transmitted to a receiving device, for example.
- the secure subnet 1 can, for example, comprise a single field device of measurement/automation technology, which determines and provides measured values for a measured variable and, if necessary, sends this measured variable with device information in the form of data packets to the receiving device.
- the secure subnet 1 can also include multiple devices, such as an edge device 1.2, to which one or more, in this example three, field devices 1.1 described above are connected.
- the producer of the device key pair 5.1 and the producer of the main key pair 5.2 can be different or the same, the key pairs are different.
- the The producer of the device key pair can be a manufacturer of a security chip such as a TPM module and the producer of the master key pair can be a manufacturer of the edge device or the field device.
- the manufacturer of the edge device or the field device can also be the generator of both key pairs.
- a digital data signature 20 can be created for a group of data packets 10 (see also FIG. 4) comprising at least one data packet 11, which digital data signature can be verified using the public device key.
- the digital data signature can be applied to the group itself or to a hash value of the group. Verification of the group of data packets means applying the public device key SGO to the data signature and comparing the group obtained or its hash value with the directly output group or its hash value.
- the digital data signature is created by a signing subnetwork device SSG of the secure subnetwork 1.1, for example by a data-generating field device 1.1 or by the edge device 1.2.
- the public device key SGO itself can be verified using the public main key SOH.
- a digital key signature 30 is created for the public device key using the private master key.
- the digital key signature 30 can be attached to the public device key, for example, and made available to the receiving device or a user of the receiving device.
- the receiving device or an operator of the receiving device can then verify the group of data packets using the public device key and also the public device key itself using the digital key signature and the public master key.
- multiple private device keys can be provided to the signing subnet device for generating the digital data signatures 20, so that if the opportunity or necessity arises, a private device key used at a time can be declared invalid and replaced with a new private device key.
- the device public key associated with a device private key may be provided by the signing subnet device or otherwise.
- the public device key can be mounted on a housing of a receiving device so that it can be read. This can be achieved, for example, by means of a plaque or a sign.
- Fig. 3 outlines the sequence of an exemplary method 100 according to the invention, a device key pair SG with a public device key SGO and a private device key SGP being generated in a first method step 101,
- the private device key and in particular the public device key is stored in a signing subnetwork device for generating the data signature.
- the private device key is kept secret by this signing subnetwork device, with the public device key being provided by the signing subnetwork device, for example.
- a digital data signature is created for the group of data packets, which can for example be attached to the group of data packets or sent separately.
- the group of data packets is verified using the public device key.
- the public device key can be verified using the public main key, so that an effort for an attempt to manipulate the data to be transmitted cannot be justified.
- a master key pair SH is generated with a public master key SHO and a private master key SHP, and the public device key is signed with the private master key.
- the public device key is signed before the second method step is carried out, in order to prevent manipulation of the private main key.
- the main key pair can be present independently of the method steps, for example, or can be generated while the method is being carried out.
- the verification of the public master key can be carried out occasionally or regularly, but is not absolutely necessary.
- the digital signature 20 for the group and the public device key SGO can be appended to the group 10 .
- a time stamp 40 can also be appended.
- the digital signature 20 and/or the public device key and/or the time stamp can also be transmitted separately.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102021129430.4A DE102021129430A1 (de) | 2021-11-11 | 2021-11-11 | Verfahren zum Erkennen von Manipulation von Daten in einem Netzwerk |
| PCT/EP2022/080895 WO2023083721A1 (de) | 2021-11-11 | 2022-11-07 | Verfahren zum erkennen von manipulation von daten in einem netzwerk |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4430805A1 true EP4430805A1 (de) | 2024-09-18 |
Family
ID=84362674
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22812675.1A Pending EP4430805A1 (de) | 2021-11-11 | 2022-11-07 | Verfahren zum erkennen von manipulation von daten in einem netzwerk |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20250015990A1 (de) |
| EP (1) | EP4430805A1 (de) |
| CN (1) | CN118216119A (de) |
| DE (1) | DE102021129430A1 (de) |
| WO (1) | WO2023083721A1 (de) |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102006000817B4 (de) | 2006-01-03 | 2009-01-15 | Nachtmann Gmbh | Feeder zum Abgeben eines Tropfens geschmolzener Glasmasse und Glasschmelzofen |
| DE202006000817U1 (de) | 2006-01-19 | 2006-03-16 | Allit Aktiengesellschaft Kunststofftechnik | Flaschenaufsatz mit Verwirbelungskammer |
| DE102014112611A1 (de) | 2014-09-02 | 2016-03-03 | Endress + Hauser Conducta Gesellschaft für Mess- und Regeltechnik mbH + Co. KG | Verfahren zur Authentifikation mindestens einer ersten Einheit an mindestens einer zweiten Einheit |
| DE102016106819A1 (de) | 2016-04-11 | 2017-10-26 | Endress+Hauser Conducta Gmbh+Co. Kg | Verfahren zur Aktualisierung einer Firmware-Komponente und Gerät der Mess- und Regeltechnik |
| DE102016118614A1 (de) * | 2016-09-30 | 2018-04-05 | Endress+Hauser Gmbh+Co. Kg | Verfahren zum manipulationssicheren Speichern von Daten eines Feldgeräts |
| EP3531333B1 (de) * | 2018-02-23 | 2020-04-15 | VEGA Grieshaber KG | Manipulationsgeschützte speicherung beweiserheblicher daten |
| EP3681102B1 (de) * | 2019-01-10 | 2022-03-16 | Siemens Aktiengesellschaft | Verfahren zur validierung eines digitalen nutzerzertifikats |
| EP3681099A1 (de) * | 2019-01-14 | 2020-07-15 | Siemens Aktiengesellschaft | Verfahren zum betreiben eines rechnersystems für eine automatisierungsanlage und/oder fertigungsanlage sowie rechnersystem |
| US11115218B2 (en) * | 2019-01-15 | 2021-09-07 | Fisher-Rosemount Systems, Inc. | System for secure metering from systems of untrusted data derived from common sources |
| US11960473B2 (en) * | 2019-01-15 | 2024-04-16 | Fisher-Rosemount Systems, Inc. | Distributed ledgers in process control systems |
| US11310059B2 (en) * | 2020-06-02 | 2022-04-19 | Microsoft Technology Licensing, Llc | Ephemeral cryptography keys for authenticating computing services |
| US11809567B2 (en) * | 2020-10-21 | 2023-11-07 | Dell Products L.P. | System and method of authenticating firmware for an information handling system |
-
2021
- 2021-11-11 DE DE102021129430.4A patent/DE102021129430A1/de active Pending
-
2022
- 2022-11-07 WO PCT/EP2022/080895 patent/WO2023083721A1/de not_active Ceased
- 2022-11-07 CN CN202280074928.7A patent/CN118216119A/zh active Pending
- 2022-11-07 EP EP22812675.1A patent/EP4430805A1/de active Pending
- 2022-11-07 US US18/709,669 patent/US20250015990A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| CN118216119A (zh) | 2024-06-18 |
| WO2023083721A1 (de) | 2023-05-19 |
| US20250015990A1 (en) | 2025-01-09 |
| DE102021129430A1 (de) | 2023-05-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3610605B1 (de) | Verfahren und vorrichtung zum erzeugen eines kryptographischen zeitstempels für ein digitales dokument auf mehrheitsbasis | |
| EP4193567B1 (de) | Verfahren zur sicheren ausstattung eines fahrzeugs mit einem individuellen zertifikat | |
| DE60208614T2 (de) | Verfahren und Vorrichtung zur Bereitstellung einer Liste von öffentlichen Schlüsseln in einem Public-Key-System | |
| DE60006147T2 (de) | Schlüsselzustimmungsprotokoll mit getrennten Schlüsseln | |
| DE60302276T2 (de) | Verfahren zur ferngesteuerten Änderung eines Kommunikationspasswortes | |
| DE102004032057A1 (de) | Verfahren und Anordnung zum Generieren eines geheimen Sitzungsschlüssels | |
| DE102012206341A1 (de) | Gemeinsame Verschlüsselung von Daten | |
| EP2462529A1 (de) | Verfahren zur ausstellung eines digitalen zertifikats durch eine zertifizierungsstelle, anordnung zur durchführung des verfahrens und rechnersystem einer zertifizierungsstelle | |
| EP3058701B1 (de) | Verfahren, verwaltungsvorrichtung und gerät zur zertifikat-basierten authentifizierung von kommunikationspartnern in einem gerät | |
| DE102004040312B4 (de) | Verfahren und Vorrichtung zum Synchronisieren einer anspassbaren Sicherheitsstufe bei einer elektronischen Datenübertragung | |
| EP3525414A1 (de) | Verfahren zur verschlüsselten übertragung von daten auf einer kryptographisch geschützten, unverschlüsselten kommunikationsverbindung | |
| EP3881486B1 (de) | Verfahren zur bereitstellung eines herkunftsortnachweises für ein digitales schlüsselpaar | |
| EP2829011A1 (de) | Verfahren und vorrichtung zur erzeugung kryptographisch geschützter redundanter datenpakete | |
| DE102014226772A1 (de) | Vorrichtung und Verfahren zum Senden und Verfifizieren einer Signatur | |
| EP4430805A1 (de) | Verfahren zum erkennen von manipulation von daten in einem netzwerk | |
| EP3955509A1 (de) | Bereitstellung von quantenschlüsseln in einem netzwerk | |
| DE102023115999A1 (de) | Verfahren, Vorrichtung, System und Computerprogrammprodukt zur PQ-sicheren Aktualisierung einer Datenverarbeitungseinheit | |
| EP3734478A1 (de) | Verfahren zur vergabe von zertifikaten, leitsystem, verwendung eines solchen, technische anlage, anlagenkomponente und verwendung eines identitätsproviders | |
| DE102005025325B4 (de) | Verfahren zur Übertragung und zur Überprüfung von Synchronisierungs-Nachrichten | |
| DE102015208899A1 (de) | Vorrichtung und Verfahren zur flexiblen Erzeugung von kryptographischen privaten Schlüsseln und Gerät mit flexibel erzeugten kryptographischen privaten Schlüsseln | |
| EP1286494B1 (de) | Verfahren zur Erzeugung eines asymmetrischen kryptografischen Gruppenschlüsselpaares | |
| EP3252990A1 (de) | Verfahren und vorrichtung zum bereitstellen eines geheimnisses zum authentisieren eines systems und/oder komponenten des systems | |
| EP3866386A1 (de) | Verfahren, vorrichtung und computerprogrammprodukt zur anwendung eines kryptographischen verfahrens | |
| EP3909217A1 (de) | Verfahren und system zur informationsübermittlung | |
| DE102018203143A1 (de) | Verfahren zum Versenden und Verfahren zum Überprüfen von wenigstens zwei unter Verwendung eines Schlüssels authentifizierten Datenblöcken |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20240430 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ENDRESS+HAUSER FLOWTEC AG |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) |