Monitoring system for downstream check system integrity
By collecting and checking configuration change information by monitoring the system, using smart contracts and AI algorithms to judge its rationality, the integrity protection problem of dynamic reconfigurable systems is solved, and the stability and security of the system are achieved in a flexible production environment.
Patent Information
- Application Number
- CN202380079035.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-16
- Filing Date
- 2023-11-15
- Publication Date
- 2025-07-11
AI Technical Summary
The prior art is difficult to effectively protect the system integrity of dynamically reconfigurable automation systems and industrial systems, especially in flexible production and Industry 4.0 environments, where traditional security methods hinder the flexible configuration adaptation of the system.
It provides a monitoring system that uses smart contracts and artificial intelligence algorithms to conduct downstream inspections, ensure the rationality of configuration changes, and uses distributed ledgers to record configuration changes history, and restore to normal working state if necessary.
Reliable integrity monitoring of reconfigurable systems is achieved, allowing necessary configuration changes while preventing unreasonable manipulation, ensuring that the system maintains stability and security in a dynamic environment.
Smart Images

Figure FT_1 
Figure FT_2
Abstract
Description
[0001] Both men and women are covered regardless of the grammatical gender of the specific term. Technical Field
[0002] The present invention relates to a monitoring system for checking the integrity of a reconfigurable system. The present invention also relates to a superior system and an associated method. Background Art
[0003] Flexible production, especially in the context of Industry 4.0, should be able to quickly adapt automation solutions (especially automation functions) to changing framework conditions. This should also be achieved by the increasing digitization in the case of using open computing platforms for implementing virtualized automation functions. In the future, the adaptation of existing automation functions and the introduction of new automation functions should be able to be carried out more quickly.
[0004] Therefore, automation systems will be changed regularly. For protecting the integrity of an automation system and the components it contains, the result is that preventing changes to ensure integrity is not a reasonable approach because then the automation functions will also not be able to change.
[0005] Intrusion detection systems (IDSs) for identifying attacks are known. These systems can analyze the configuration on a host (HIDS, host-based intrusion detection system) or network traffic (NIDS, network-based intrusion detection system). Generally, an IDS can identify changes in behavior (anomaly-based IDS) or known attack patterns (signature-based IDS) as attacks.
[0006] Solutions for file integrity monitoring (FIM) are known, which identify changes in the file system.
[0007] In a distributed ledger (blockchain), it is known that through program code (smart contract), it is stipulated whether a transaction is allowed, that is, whether a specific change to the state managed in the distributed ledger is allowed abstractly.
[0008] A system for integrity monitoring of cyber - physical systems is known from "System Integrity Monitoring for Industrial Cyber Physical Systems" by Rainer Falk, Steffen Fries (International Journal on Advances in Security, Vol. 11, No. 1&2, 2018, http: / / www.iariajournals.org / security). It is also known here that the integrity of a cyber - physical system (CPS) in the real physical world is determined by so - called "trusted sensors". These trusted sensors provide trusted physical measurement data that can be used for cross - comparison with the process images present in the automation system of the CPS.
[0009] It is known from "Enhancing the Resilience of Cyber - Physical Systems by Protecting the Physical - World Interface" by Rainer Falk, Steffen Fries (International Journal on Advances in Security, Vol. 3, No. 1&2, 2020, http: / / www.iariajournals.org / security) that in a dynamically reconfigurable cyber - physical system, its integrity monitoring system must also be adapted accordingly to the current configuration (reference policy) (see Section IV.C, "Policy Adaptation for Dynamically Reconfigurable CPS").
[0010] In an operating system such as Microsoft Windows, restore points are known. When the Windows system fails to work properly, the user or administrator can restore to an earlier, fully functional configuration state. Summary of the Invention
[0011] The object of the present invention is to provide a solution for improving the protection of the system integrity of dynamically reconfigurable systems, especially automation systems and industrial systems.
[0012] The present invention results from the features of the independent claims. Advantageous improvements and designs are the subject matter of the dependent claims. The design, application possibilities and advantages of the present invention result from the following description and the drawings.
[0013] The present invention relates to a monitoring system for checking the integrity of a reconfigurable system, wherein the reconfigurable system has a plurality of components, and the monitoring system has: - a receiving unit configured to receive a plurality of data sets, wherein each of the plurality of data sets originates from one of the plurality of components of the reconfigurable system, and wherein each of the plurality of data sets describes at least one configuration change that has occurred on the corresponding component of the plurality of components of the reconfigurable system by means of change information, and wherein the change information respectively indicates the type of at least one configuration change that has occurred; - an inspection unit configured to check the admissibility of the corresponding configuration change that has occurred by checking whether the type of at least one configuration change that has occurred is admissible and / or reasonable; and - an output unit configured to give an output based on the result of the inspection.
[0014] The check of admissibility is not based on a comparison of the actual configuration with a fixed, preset target configuration, but on checking whether the configuration change made is admissible and / or reasonable.
[0015] The type of at least one configuration change that has occurred describes the manner in which the configuration of at least one of the plurality of components of the reconfigurable system has been changed. The change type indicates how the configuration has changed. In addition, the change type particularly indicates which functional category of the configuration has been changed. The functional categories of the configuration particularly include: security function, network function, control function, communication function, management function and / or identification function.
[0016] A positive result of the check of the admissibility of the corresponding configuration change that has occurred means that the configuration change that has occurred on one of the plurality of components of the reconfigurable system is admissible. Accordingly, the corresponding component has integrity. If all of the plurality of components have integrity, it is inferred that the entire reconfigurable system has integrity. The output unit is configured to give an output based on the integrity of the corresponding component and / or the reconfigurable system.
[0017] A negative result of the admissibility check for a corresponding configuration change means that the configuration change that occurred on one of the multiple components of the reconfigurable system is not allowed. Consequently, the corresponding component does not possess integrity. If there is no integrity for at least one of the multiple components, it is inferred that the entire reconfigurable system lacks integrity. The output unit is configured to give an output based on the fact that the corresponding component and / or the reconfigurable system does not possess integrity.
[0018] The reconfigurable system is in particular configured as a cyber-physical system (CPS).
[0019] In the context of the present invention, "multiple" should be understood as a plural number. In the context of the present invention, "multiple" should not be understood as the larger part of a specific quantity. In the context of the present invention, "multiple" particularly means at least 3, preferably more than 10, particularly preferably more than 50 or more than 100. This applies both to multiple components and to multiple data sets.
[0020] The components among the multiple components of the reconfigurable system are configured to provide the multiple data sets. For the protection of know-how, the multiple data sets are each in particular protected by privacy, in particular by anonymization, pseudonymization, by using verifiable credentials / verifiable presentations, or by privacy-preserving encryption methods (such as homomorphic encryption or secure multi-party computation) for privacy protection.
[0021] Each of the multiple data sets is in particular formed and provided by the component itself involved, by additional components belonging to the component involved, or by the application (App) of the component involved. The additional component or the application (App) can repeatedly determine the configuration of the component for this purpose, in particular via OPC UA or via NETCONF, and confirm the change of the determined configuration compared to the previously determined configuration in an encryption-protected manner. When monitoring a configuration change of the component itself, additional information can be determined and confirmed if necessary, in particular that this results in a configuration change, in particular which authentication credentials and / or which communication protocol and / or which device interface were applied during the configuration change (identifier or authentication credentials / certificates in the case of remote access, in particular via HTTPS, NETCONF / TLS, NETCONF / ssh, OPC UA).
[0022] For the protection of know-how, this integrity confirmation is in particular protected by privacy, in particular by anonymization, pseudonymization, by using verifiable credentials / verifiable presentations, or by privacy-preserving encryption methods (such as homomorphic encryption or secure multi-party computation) for privacy protection.
[0023] Regarding reconfigurable systems, in particular cyber-physical systems, in particular device operators, multiple machine manufacturers of the production machines used, multiple device manufacturers of the automation components used, integrators, IT departments or IoT cloud providers, have a legitimate interest in system integrity monitoring. However, they are each only responsible for a subfield (area of responsibility, AOR). Therefore, it is also proposed to filter multiple data sets according to different areas of responsibility and provide them to the corresponding AOR monitoring system for inspection. The AOR monitoring system in turn confirms whether the changes checked are permissible from the perspective of the corresponding area of responsibility.
[0024] From this, an overall view of the cyber-physical system (CPS) is determined, which shows from which AOR areas of responsibility the integrity of the system exists. This information is in particular provided to the production planning system or the production data management system. The production planning of further production processes, the release of the products produced or the downstream inspection of the products produced can be carried out depending on whether the CPS used for this in production or the CPS area used for this (in particular the production machine) is or was in a permissible state. This information can also be passed on to the CPS component management system, in particular the common device management system, in order to cause configuration changes not recognized as permissible to be reversed.
[0025] In summary, the idea of the present invention is a monitoring system for industrial automation systems, in particular an integrity monitoring system, which collects multiple data sets and thus collects change information of multiple components. The monitoring system checks the permissibility of changes of multiple components of the reconfigurable system.
[0026] Therefore, one aspect of the present invention is a monitoring system that reliably collects the configuration changes that occur and performs a downstream inspection of the type of configuration changes that occur through program code (in particular through smart contracts). "Downstream" means that the configuration change has occurred at the time of inspection.
[0027] Therefore, an integrity monitoring system for a reconfigurable system is proposed, which allows configuration changes in such a way that it does not recognize changes as impermissible before they are executed, unlike known integrity monitoring tools (file integrity monitoring (FIM), intrusion detection system (IDS)), but monitors the type of observable changes and checks their reasonableness.
[0028] Abstractly, this can be understood as a distributed ledger (“blockchain”), but where transactions (here: configuration changes of a reconfigurable system) are first collected in a transaction database. Only afterwards are these transactions that already (because first collected) exist in the database checked according to a smart contract as to whether they are permitted.
[0029] Thereby, for a cyber-physical system (CPS) under distributed control (distributed ledger, blockchain), the following advantage arises: The restore point enables a return to a previously still fully functional configuration state of the CPS in case of problems or inadmissible manipulations.
[0030] Traditional security methods are access control, which strictly controls access such that only permitted actions are executable. Another traditional method consists in identifying deviations from a reference state (set or learned) defined as complete as manipulations. This traditional security method assumes that the configuration is fixed. The disadvantage is that when configuration changes should occur regularly in order to flexibly adapt a production system to different requirements, these security methods are therefore not applicable. This security method, if it is strictly set up, hinders the flexible configuration adaptation or reconfiguration of industrial automation and control systems (usually: industrial IoT or cyber-physical systems). Therefore, this security method only makes sense in static industrial systems. However, in systems that should be able to be dynamically reconfigured, extensive changes must be permitted.
[0031] In contrast, in the present application, as a complementary security method, it is proposed to reliably collect the occurring configuration changes and to check the admissibility of the occurring changes downstream.
[0032] In an improved embodiment of the present invention, the reconfigurable system is configured as: - a cyber-physical system, and / or - an Internet of Things system, and / or - an industrial system, and / or - an automation system, and / or - a manufacturing system, and / or - a control system, and / or - a robot, and / or - a production machine, and / or - an autonomous transport system.
[0033] In another improved embodiment of the present invention, the receiving unit is additionally configured to call a plurality of data sets.
[0034] Multiple data sets can in particular be called up by the receiving unit from a database. The change information of multiple data sets and thus of multiple components is in particular stored in a database (which can also be referred to as a CPS component configuration change database), in particular in a relational database, an object database or a distributed transaction database (which can also be referred to as a distributed ledger and / or blockchain). Thereby, a history of the changes occurring on multiple components of the reconfigurable system exists.
[0035] In a further refinement of the invention, the multiple data sets each have encryption protection.
[0036] This has the advantage that the multiple data sets are protected against manipulation, and thus the change information is assumed to be valid.
[0037] In a further refinement of the invention, the change information states: - the time point of at least one configuration change that has occurred, and / or - the start in time, and / or - the end in time, and / or - the initiator, and / or - the location of initiation.
[0038] The initiator of at least one configuration change that has occurred can also be referred to as the executor of at least one configuration change that has occurred.
[0039] According to the invention, the monitoring system checks the admissibility of configuration changes occurring on the multiple components of the reconfigurable system. For this purpose, in addition to the type of at least one configuration change that has occurred, it is also possible to evaluate at what time and / or by whom and / or where what changes have been made to the respective components of the reconfigurable system. This has the advantage that further information is incorporated to check the admissibility, and the result of the check is more reliable. Here, the admissibility of individual configuration changes can be checked. Equally, the admissibility of a series of multiple configuration changes can also be checked.
[0040] In a further refinement of the invention, the type of at least one configuration change that has occurred includes: - security-related changes, and / or - changed network configurations, and / or - changes to industrial projects, and / or - updated implementations.
[0041] In a further refinement of the invention, the checking unit is configured to check the change information of a first configuration change occurring on a first component among the multiple components in combination with the change information of a second configuration change occurring on a second component among the multiple components.
[0042] According to the present invention, at least one configuration change that occurs in a component is already recognizable as not allowed per se, but additionally, its impact on the reconfigurable system can also be recognized, in particular by the inconsistency between components and another configuration change that occurs, and can be evaluated as not allowed. Therefore, the checking unit is configured in particular to check whether the components are reconfigured consistently, especially during the production setup phase.
[0043] Additionally, in particular, it is checked whether the changes made to the components (especially the changed network configuration), which may have an impact on the entire reconfigurable system, are consistent in content and are carried out in a consistent manner. From this, it can be recognized in particular whether the same type or similar changes have been applied to multiple components within a defined period.
[0044] Furthermore, the checking unit is configured in particular to check whether the configuration changes that occur serve different purposes and / or are divided into different change processes. Through the inconsistencies in these criteria, in particular, non - allowed configurations can be recognized.
[0045] In another improvement of the present invention, the checking unit is configured to check the admissibility by using the following: - Program code, especially smart contracts, and / or - AI - based algorithms, and / or - At least one security policy.
[0046] Therefore, the checking of the admissibility of the configuration changes that occur is carried out especially by smart contracts, that is, usually by program code. This program code checks according to definable criteria whether there are allowed configuration changes in the CPS.
[0047] Alternatively or additionally, the checking of the admissibility of the configuration changes that occur is carried out by AI - based algorithms, that is, based on AI. In particular, during the learning phase, allowed configuration changes are trained based on criteria, and during the production phase, non - allowed changes are identified and, if necessary, the non - allowed changes are prohibited, that is, recognized as not allowed.
[0048] In another improvement of the present invention, the checking unit is configured to check the admissibility by using the following: - The impact of at least one configuration change that occurs, and / or - The input behavior and / or output behavior of the changes of multiple components caused by at least one configuration change that occurs, especially functional changes, performance changes, and / or changes in real - time behavior, and / or - The purpose of at least one configuration change that occurs.
[0049] Accordingly, it is further proposed to determine the input behavior and / or output behavior of a plurality of components with respect to a plurality of data sets. This can be determined directly at the input / output interface or on the data bus. Even if there are unexpected and unforeseen indirect effects on some automation functions, the changed input behavior and / or output behavior is recognizable. Therefore, both the input / output behavior of the CPS or its existing internal components and the configuration changes occurring on the components of the CPS are monitored. Using this information, in particular, it is determined which configuration change has led to an undesirable input / output behavior. In particular, by performing an additional cross-comparison of the configuration changes of the collected CPS components and the input / output behavior of the CPS automation / control functions, it is identified which changes may have led to an unacceptable CPS behavior. Subsequently, in particular, an automatic fallback to a normally working version is performed.
[0050] In a further improvement of the invention, the checking unit is furthermore configured to create, based on the change information: - an assessment of the integrity of the respective components among the plurality of components, and / or - an assessment of the integrity of the reconfigurable system.
[0051] According to this embodiment, the monitoring system not only classifies the components among the plurality of components and / or the reconfigurable system as complete or incomplete, but also additionally states the assessment of integrity, in particular in the form of a confidence measure. A higher assessment means a higher probability of integrity. A relatively lower assessment means a lower probability of integrity. Furthermore, the following information is particularly included in this assessment: which configuration change or which combination of changes (in particular as a reference to this change (or these changes)) has led to a lower integrity assessment.
[0052] This assessment and / or confidence measure can be determined for the entire reconfigurable system. Similarly, a plurality of confidence measures can also be determined for different sub-regions of the reconfigurable system. The sub-regions can be fixedly preset, but preferably, the sub-regions with a unified confidence measure are dynamically determined.
[0053] In a further improvement of the invention, the output is configured to: - an integrity confirmation, and / or - an encrypted-protected integrity confirmation, and / or - an integrity assessment, and / or - a warning message, and / or - a warning signal, and / or - an alarm, and / or - a command to stop production.
[0054] If the change is recognized as not allowed, in one embodiment, a corresponding output is performed. Alternatively or additionally, an alarm is triggered or production is stopped.
[0055] If the change is recognized as permitted, an integrity confirmation protected by encryption is optionally formed, in particular an integrity proof, which confirms that the reconfigurable system is currently or within a defined period of time was in a permitted and complete state.
[0056] According to this embodiment, the integrity confirmation is formed and output by the output unit. Alternatively or additionally, the integrity confirmation, also referred to as an integrity proof, is in particular formed and output by a downstream integrity confirmation unit (in particular a CPS system integrity prover). In the case of a downstream integrity confirmation unit, the integrity confirmation unit obtains the result of the admissibility check formed by the checking unit.
[0057] The invention also includes a superior system having: - a monitoring system according to any one of the preceding claims, and - a reconfigurable system, wherein the reconfigurable system has a plurality of components.
[0058] The plurality of components are configured to provide a plurality of data sets. These components are in particular configured as automation components. For this purpose, units for determining configuration changes and in particular for encrypting and protecting the confirmation of the identified configuration changes are provided on the components.
[0059] In a further improvement of the invention, the superior system also has: - a database configured to provide a plurality of data sets, and / or - a prover configured to create an integrity proof based on the output.
[0060] The invention also includes a method for checking the integrity of a reconfigurable system, wherein the reconfigurable system has a plurality of components, the method having the following steps: - receiving a plurality of data sets, where each of the plurality of data sets originates from one of the plurality of components of the reconfigurable system, where each of the plurality of data sets describes at least one configuration change occurring on a corresponding one of the plurality of components of the reconfigurable system by change information, where the change information respectively describes the type of at least one configuration change that occurred; - checking the admissibility of the corresponding configuration change that occurred according to the change information; and - outputting an output according to the result of the check.
[0061] A further improvement of the invention relates to a method according to the invention for checking the integrity of a reconfigurable system by means of a monitoring system according to the invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] The features and advantages of the present invention become visible from the following description of multiple embodiments based on schematic drawings.
[0063] Figure 1 A schematic diagram of a superior system is shown, which includes, among other things, a monitoring system according to the present invention; and Figure 2 A flowchart of a method according to the present invention is shown. DETAILED DESCRIPTION
[0064] Figure 1 A superior system is shown, which has: - A monitoring system 1 according to the present invention, which is divided into two monitoring systems 1 for different sub-regions of a reconfigurable system 2; - A reconfigurable system 2, wherein the reconfigurable system 2 has a plurality of components 21, and the plurality of components 21 are connected to a database 3 via a gateway 22 and a network 5; - A database 3, configured to provide a plurality of data sets 23 (stored over time t) to the monitoring system 1 and receive a plurality of data sets 23 from the reconfigurable system 2, wherein each data set in the plurality of data sets 23 describes at least one configuration change that occurs on a corresponding one of the plurality of components 21 in the reconfigurable system 2 by changing information, and the change information respectively explains the type of at least one configuration change that occurs; and - A prover 4, configured to create an integrity proof 41 based on the output of the monitoring system 1.
[0065] Therefore, Figure 1 In particular, an implementation example with three CPS components 21 in an automation network 2 is shown. In addition, two system integrity monitoring units 1 for two different scopes of responsibility are shown. One scope of responsibility can be given, for example, by a subset of the CPS components 21, and / or by the type of configuration change that occurs (i.e., the functional category).
[0066] Intuitively, the proposed monitoring system 1, also referred to as an integrity monitoring system 1, can be understood as a distributed ledger (blockchain), where smart contracts check the admissibility of a series of transactions collected in the data sets 23. However, a configuration change has occurred, and the corresponding transaction has been stored in the database 3. Different from known blockchains / distributed ledgers, their admissibility is only checked downstream. Here, multiple checks can also be performed corresponding to different scopes of responsibility, that is, through multiple "smart contracts". Provide the results of the checks.
[0067] Optionally, based on the results of the inspection, the prover 4 determines an integrity proof 41 to show whether the configuration changes that have occurred are allowed or not allowed for the transactions stored in the database 3. In the integrity proof 41, it can be stated in particular for which functional areas of the reconfigurable system 2 (in particular which production machines or which production lines (scope of responsibility)), the configuration changes applied to these functional areas are allowed.
[0068] Figure 2 A method for checking the integrity of a reconfigurable system 2 is shown, where the reconfigurable system 2 has a plurality of components, and the method has the following steps: - Step S1: Receive a plurality of data sets, where each data set 23 in the plurality of data sets is derived from one component 21 among the plurality of components of the reconfigurable system 2, where each data set 23 in the plurality of data sets describes at least one configuration change that has occurred on the corresponding one component 21 among the plurality of components of the reconfigurable system by change information, where the change information respectively states the type of the at least one configuration change that has occurred; - Step S2: Check the admissibility of the corresponding configuration change that has occurred based on the change information, where the check includes checking whether the type of the at least one configuration change that has occurred is allowed and / or reasonable; and - Step S3: Output an output based on the results of the inspection.
[0069] Although the present invention has been illustrated and described in detail by way of examples, the present invention is not limited by the disclosed examples, and those skilled in the art can derive other variant solutions therefrom without departing from the protection scope of the present invention.
Claims
1. A monitoring system (1) for checking the integrity of a reconfigurable system (2), wherein the reconfigurable system (2) has a plurality of components (21), and the monitoring system (1) has: - A receiving unit configured to receive a plurality of data sets, wherein each data set (23) of the plurality of data sets is derived from one component (21) of the plurality of components of the reconfigurable system (2), wherein each data set (23) of the plurality of data sets describes at least one configuration change that has occurred on a corresponding one of the plurality of components (21) of the reconfigurable system (2) by changed information, wherein the changed information respectively explains the type of at least one configuration change that has occurred; - An inspection unit configured to check the admissibility of a corresponding occurring configuration change based on the changed information by checking whether the type of at least one configuration change that has occurred is allowed and / or whether it is reasonably admissible; and - An output unit configured to give an output according to the result of the inspection.
2. The monitoring system (1) according to claim 1, wherein the reconfigurable system (2) is configured as: - A cyber-physical system, and / or - An Internet of Things system, and / or - An industrial system, and / or - An automation system, and / or - A manufacturing system, and / or - A control system, and / or - A robot, and / or - A production machine, and / or - An unmanned transportation system.
3. The monitoring system (1) according to any one of the preceding claims, wherein the receiving unit is additionally configured to call the plurality of data sets.
4. The monitoring system (1) according to any one of the preceding claims, wherein the plurality of data sets respectively have encryption protection.
5. The monitoring system (1) according to any one of the preceding claims, wherein the changed information explains the at least one configuration change that has occurred - Time point, and / or - Temporal start, and / or - Temporal end, and / or - Initiator, and / or - Initiation location.
6. The monitoring system (1) according to any one of the preceding claims, wherein the type of at least one configuration change that has occurred includes: - Security-related changes, and / or - Changed network configuration, and / or - Changes to industrial projects, and / or - Updated implementation.
7. The monitoring system (1) according to any one of the preceding claims, wherein the inspection unit is configured to check the changed information of a first configuration change that has occurred on a first component (21) of the plurality of components in combination with the changed information of a second configuration change that has occurred on a second component (21) of the plurality of components.
8. The monitoring system (1) according to any one of the preceding claims, wherein the inspection unit is configured to check the admissibility by using: - Program code, especially a smart contract, and / or - An artificial intelligence-based algorithm, and / or - At least one security policy.
9. The monitoring system (1) according to any one of the preceding claims, wherein the inspection unit is configured to check the admissibility by using: - The impact of at least one configuration change that has occurred, and / or - The input behavior and / or output behavior of the changes of the plurality of components caused by at least one configuration change that has occurred, in particular changes in functionality, performance, and / or real-time behavior, and / or - The purpose of at least one configuration change that has occurred.
10. The monitoring system (1) according to any one of the preceding claims, wherein the checking unit is further configured to create, based on the change information: - An assessment of the integrity of the corresponding component (21) among the plurality of components, and / or - An assessment of the integrity of the reconfigurable system (2).
11. The monitoring system (1) according to any one of the preceding claims, wherein the output is configured to: - An integrity confirmation, and / or - An integrity confirmation with encryption protection, and / or - An integrity assessment, and / or - A warning message, and / or - A warning signal, and / or - An alarm, and / or - A command to stop production.
12. A superior system, having: - The monitoring system (1) according to any one of the preceding claims, and - A reconfigurable system (2), wherein the reconfigurable system (2) has a plurality of components.
13. The superior system according to claim 12, further having: - A database (3) configured to provide a plurality of data sets, and / or - A prover (4) configured to create an integrity proof (41) based on the output.
14. A method for checking the integrity of a reconfigurable system (2), wherein the reconfigurable system (2) has a plurality of components, the method comprising the following steps: - Receiving (S1) a plurality of data sets, wherein each data set (23) of the plurality of data sets is derived from one component (21) of the plurality of components of the reconfigurable system (2), wherein each data set (23) of the plurality of data sets describes at least one configuration change that has occurred on the corresponding one component (21) of the plurality of components of the reconfigurable system by change information, wherein the change information respectively describes the type of at least one configuration change that has occurred; - Checking (S2) the admissibility of the corresponding configuration change that has occurred based on the change information, wherein the checking includes checking whether the type of at least one configuration change that has occurred is allowed and / or reasonable; and - Outputting (S3) an output based on the result of the checking.
15. The method for checking the integrity of a reconfigurable system (2) according to claim 14, which is performed by the monitoring system (1) according to any one of claims 1 to 11.