Authentication of data for authentication with key agreement protocol flow

By using a hybrid authentication method in the authentication and key negotiation protocol process, combining traditional and post-quantum secure algorithms, the problems of high overhead and poor adaptability of existing hybrid key negotiation protocols are solved. This achieves post-quantum secure additional protection in industrial control systems, enhancing the trustworthiness and integrity of communication.

CN120917708APending Publication Date: 2025-11-07SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480020476.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-03-20
Filing Date
2024-03-12
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively combine traditional and post-quantum cryptographic algorithms in hybrid key negotiation protocols, resulting in high overhead in the authentication and key negotiation process and making it difficult to adapt to different security protocols and algorithms, thus failing to meet the security requirements of Europe and the United States.

Method used

The authentication and key negotiation protocol process is detected, created, authenticated, and provided using a verification unit. Hybrid authentication is performed using different cryptographic algorithms, including traditional and post-quantum secure methods, to form data that is protected by integrity.

Benefits of technology

It provides additional protection for post-quantum security without altering existing systems, meets European security requirements, and is suitable for control command and measurement data transmission in industrial control systems, enhancing the reliability and integrity of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120917708A_ABST
    Figure CN120917708A_ABST
Patent Text Reader

Abstract

The invention relates to a verification unit (2), comprising a detection unit (21) designed to detect an authentication and key agreement protocol process, a creation unit (22) designed to derive data belonging to the authentication and key agreement protocol process from the authentication and key agreement protocol process taking into account a confirmation criterion (211), an authentication unit (23) designed to authenticate the authentication and key agreement protocol process from the creation unit (22), the device comprises a protection unit (24) configured to protect data for integrity, thereby forming integrity-protected data (232), and a provision unit (24) configured to provide the integrity-protected data (232). The invention further relates to a device (1) and to a method for providing integrity-protected data (232).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Regardless of the grammatical gender of a particular term, persons with male, female gender identity are encompassed. TECHNICAL FIELD

[0002] The present invention relates to a verification unit. The present invention furthermore relates to a related device and a related method for providing integrity-protected data. BACKGROUND

[0003] For a cryptologically protected communication between two participants, protocols can be used, in particular as TLS, DTLS, QUIC or IPsec / IKEv2. For this, an authentication and key agreement (AKA) is first carried out, in which the participants are authenticated (mutual authentication) or at least unilaterally authenticated (unilateral authentication). Furthermore, an unauthenticated key agreement is also possible, even if this is relevant in practice, more precisely in special cases. In the authentication and key agreement, symmetric key material (session key) is set up, which is used for the cryptographic protection (encryption, integrity protection and / or authenticated encryption) of user data transmitted between the participants.

[0004] In the case of conventional cryptographic methods, such as RSA or elliptic curves, a digital signature is usually used for authentication, with which AKA protocol messages or AKA parameters contained therein are digitally signed. In the case of common post-quantum (PQ-) cryptographic algorithms (or generally "next generation crypto algorithms"), the operational overhead of the signature calculation is large. Therefore, KEM (Key Encapsulation Mechanism)-based authentication is proposed, for example by KEMTLS. In the case of both variants, however, the participants are simply authenticated, i.e. using a single cryptographic method for the method and the corresponding authentication credentials (private key and the associated digital certificate).

[0005] Some of the recommended principles for the exploitation of post-quantum cryptography algorithms, for example from the German Federal Office for Information Security (BSI) or from the French National Agency for the Security of Information Systems (Agence nationale de la sécurité des systèmes d'information, ANSSI), require a hybrid cryptographic approach in principle, in which PQ algorithms are used together with classical algorithms. See BSI: Migration to Post Quantum Cryptography, Recommendations for action by the BSI, 31.05.2021, Chapter 3.5: "Therefore, the BSI does not recommend using post-quantum cryptography alone, but only "hybrid" if possible, i.e. in combination with classical algorithms. In a hybrid key exchange, for example, the two negotiated secrets must be combined by means of a suitable key derivation function to form a session key. In high-security applications, the BSI requires the use of hybrid Solutions." (Therefore, the BSI does not recommend using post-quantum cryptography alone, but only "hybrid" if possible, i.e. in combination with classical algorithms. In a hybrid key exchange, for example, the two negotiated secrets must be combined by means of a suitable key derivation function to form a session key. In high-security applications, the BSI requires the use of hybrid Solutions.) The combination should be secure as long as at least one of the cryptographic algorithms used has not been broken (for example by a quantum computer or by algorithm design weaknesses or by implementation problems).

[0006] BSI, Quantum-safe cryptography - fundamentals, current developments and recommendations, Okt. 2021 gives an overview on PQ cryptography. Therein, in chapter 3.1.1 "Key agreement" hybrid key agreement is described, in chapter 3.1.2 "Hybrid signatures and adaptation of public key infrastructures" multiple signatures of messages (message authentication) are described.

[0007] Within the authentication and key agreement protocol flow between two nodes, in case of a hybrid key agreement two cryptographically different key agreements are performed, from which session keys are derived, which then form a total session key for the protection of transmitted user data.

[0008] However, the design and implementation of a hybrid authentication method combining two different cryptographically authentication algorithms is overhead and cannot be easily implemented for different security protocols and different cryptographic algorithms. SUMMARY

[0009] It is the task of the present application to provide a solution for an improved trustworthiness protection for a communication between participants.

[0010] The present application results from the features of the independent claims. Advantageous refinements and design solutions are the subject of the dependent claims. The design solutions, application possibilities and advantages of the present application result from the subsequent description and the figures.

[0011] The present application relates to a verification unit having: - a detection unit, which is configured for detecting an authentication and key agreement protocol flow, - a creation unit, which is configured for deriving, in consideration of a confirmation criterion, data belonging to the authentication and key agreement protocol flow from the authentication and key agreement protocol flow, - an authentication unit, which is configured for protecting the data with respect to integrity, whereby integrity-protected data is formed, and - a provision unit, which is configured for providing the integrity-protected data.

[0012] In other words, the verification unit is configured for deriving a verification of the data belonging to the authentication and key agreement protocol flow and providing it in integrity-protected, in particular signed, form.

[0013] Integrity protected data can also be referred to as authenticated data.

[0014] Generally, the authentication and key agreement protocol procedure can be understood as a communication session, a communication connection and / or a data transmission.

[0015] A session key is created by the authentication and key agreement. The authentication and key agreement is known in English as "authentication and key agreement" (AKA). The created session key is constructed for protecting data which is exchanged in the communication protocol procedure, i.e. the authentication and key agreement protocol procedure. Thus, the previously created session key is used in the authentication and key agreement protocol procedure (AKA procedure) in order to protect the running communication protocol, in particular the messages exchanged in the procedure. The exchanged messages are an implementation form of the data belonging to the authentication and key agreement protocol procedure.

[0016] In particular in one implementation, the authentication and key agreement is used for setting up a symmetric session key between two participants (first and second participant). The symmetric session key is used for the cryptographic protection of user data which is transmitted between the participants (e.g. IPsec, TLS Record Layer, IEEE 802.1AE). The authentication and key agreement is authenticated by means of a first authentication credential (also referred to as "private key") of the first participant by means of a first cryptographic algorithm (or generally, a first authentication method) which is assigned to the first authentication credential. Optionally (two-way, mutual authentication), the authentication and key agreement can additionally be authenticated by means of a second authentication credential (private key) of the second participant by means of a second cryptographic algorithm (or generally, a second authentication method) which is assigned to the second authentication credential.

[0017] Generally, the first cryptographic algorithm and the second cryptographic algorithm are identical, i.e. the first participant and the second participant use the same cryptographic algorithm for the authentication, respectively (e.g. RSA (classical), ECC (classical), KEM (classical or PQ)).

[0018] The verification unit can also be referred to as "AKA Notarization Module", "AKA Verification System" and / or "AKA Verification Unit". The integrity protected data can also be referred to as "AKA Verification".

[0019] Data belonging to the authentication and key agreement protocol procedure can also be referred to as a data structure, which in the sense of the present application can in particular be considered a "not yet signed AKA verification data structure". In particular, the feature "data 'belongs' to the authentication and key agreement protocol procedure" can be understood as the data being derived by the authentication and key agreement protocol that is running or (a previous, pertaining) authentication and key agreement. Generally, the data in particular has information about the authentication and key agreement protocol procedure to be verified.

[0020] The confirmation criterion can also be referred to as "AKA confirmation policy" or "AKA notarization policy". The confirmation criterion in particular also comprises a plurality of criteria.

[0021] The authentication unit is configured to protect the data in terms of its integrity, thereby forming integrity-protected data. The authentication unit is thus configured to perform a further authentication. The integrity protection for the previously mentioned authentication and key agreement is created by the further authentication. The previously mentioned authentication and key agreement is furthermore also known as "previous authentication and key agreement".

[0022] According to the present application, a further authentication (which can also be referred to as confirmation and / or verification) of the previous authentication and key agreement is thus additionally performed, in which in particular a third credential (authentication credential (private key)) is used. The third credential is different from the first authentication credential and from the second authentication credential, if present. Furthermore, a third cryptographic algorithm (or generally, a third authentication method) is used here, which is different from the first cryptographic algorithm and from the second cryptographic algorithm. This further authentication according to the present application is provided in the form of integrity-protected data and can also be referred to as AKA verification, since the further authentication additionally confirms the previous authentication and key agreement again, although said previous authentication and key agreement has already been authenticated by means of the first and, if necessary, second authentication credential and by means of the first and, if necessary, second cryptographic algorithm.

[0023] The provision unit of the verification unit is in particular integrated in the authentication unit or identical to the authentication unit.

[0024] The focus of research work on post-quantum secure security protocols so far has mainly been on hybrid key agreement, however not on authentication. The reason for this is that the confidentiality of a communication session can also be compromised ex post if recorded protocol messages are decrypted at a later point in time.

[0025] However, in general, PQ encryption algorithms or generally first generation encryption algorithms have not gained the same trust as the traditional encryption algorithms (RSA, ECC) which have been intensively researched over many years. It therefore makes sense to use a combination of several authentication methods when authenticating. This can be meaningful, in particular, in the case of certificate issuance via a secure communication channel (EST, SCEP) or in the case of an onboarding process or in the case of online banking.

[0026] Hybrid key agreement protocols are known. However, the hybrid key agreement protocols are directed at hybrid key agreement, but not at hybrid, multiple authentication in the case of authentication and key agreement (AKA).

[0027] The invention provides the advantage that it provides a protection with which a conventional, non-PQ-secure further authentication can be feasibly supplemented as an Add-On-System to an otherwise unaltered industrial automation system. In particular, if old devices or third-party components cannot be updated or cannot be quickly updated such that the old devices or third-party components themselves support PQ encryption algorithms, then a post-hoc implementation of a PQ-secure additional protection is thereby possible.

[0028] Intuitively, this can also be understood as a PQ-secure overlay, which as an additional protection is feasibly installable in a Brownfield environment. The invention thus provides a solution for a feasibly implementable additional protection in order to be able to supplement existing implementations and systems for secure, authenticated communication post-hoc with a PQ-secure authentication. This is sufficient only for PQ-secure authentication and integrity, but not for PQ-secure long-term applicable confidentiality protection. This type of protection is required, for example, in the case of the transmission of control commands and measurement data in industrial control systems.

[0029] Furthermore, a hybrid additional protection can thereby be implemented, which is required in Europe by the BSI and the ANSSI. That is, if an implementation only meets the current American requirements, but not the European requirements, then the hybrid protection required for Europe can feasibly be supplemented as an Add-on.

[0030] Furthermore, a general, abstract construction is described, in which a previous authentication and key agreement is protected using a further, cryptographically different protection, thus a general basic construction for hybrid authentication when authenticating and key agreement is described.

[0031] In a further refinement of the application, the authentication unit is configured as a signing unit, wherein the signing unit is configured to provide the integrity-protected data in signed form.

[0032] The integrity-protected data is thus configured in this embodiment as signed data.

[0033] The integrity-protected data in signed form is in particular protected with a PQ-secure digital signature or by a PQ-secure KEM method. That is, the previous authentication and key agreement is verified in particular in the case of a PQ-secure digital signature method or in the case of a PQ-secure KEM method. In contrast, in particular a classical encryption method is used for the previous authentication and key agreement, in particular an RSA signature, DSA, ECDSA. Post-quantum secure cryptography methods, also referred to as next-generation cryptography methods, in particular CRYSTALS-Dilithium, FALCON, SPHINCS+, LMS, XMSS, and lattice- or code-based key encapsulation methods (key encapsulation mechanisms, KEM), in particular Kyber, FrodoKEM or Classic McEliece.

[0034] The integrity-protected data in signed form or in KEM-protected form can conversely also have a classical, non-PQ-secure digital signature, in particular an RSA signature, DSA, ECDSA, or be protected by a classical, non-PQ-secure KEM method. That is, the previous authentication and key agreement is verified in particular in the case of a classical digital signature method or a classical KEM method, for example in the case of RSA encryption. In contrast, a post-quantum method is used for the previous authentication and key agreement.

[0035] In a further refinement of the application, the signing unit is configured to protect the data by: - a post-quantum secure signature method or a post-quantum secure key encapsulation method, or - a classical cryptography digital signature method, in particular an RSA signature method, DSA or ECDSA The data is protected for integrity, whereby the integrity-protected data is provided in signed form and / or in integrity-protected form.

[0036] In an embodiment of the application, the data has: - at least one message that has been exchanged within an authentication and key agreement protocol procedure, also referred to as an exchanged AKA message and / or AKA protocol message, - a message portion of a message that has been exchanged within an authentication and key agreement protocol procedure, - control messages that have been exchanged within an authentication and key agreement protocol procedure in an industrial automation system, - a cryptographic hash value of messages that have been exchanged within an authentication and key agreement protocol procedure.

[0037] Preferably, the data have a plurality of messages and / or a plurality of message portions that have been exchanged within an authentication and key agreement protocol procedure. Here, the plurality of messages and / or the plurality of message portions can be messages and / or message portions that have been transmitted between the first and the second participant in opposite transmission directions. Furthermore, the data can have a plurality of messages and / or a plurality of message portions that have been exchanged between the first and the second participant within a multitude of authentication and key agreement protocol procedures or within a large number of authentication and key agreement protocol procedures. Furthermore, the data can have a plurality of messages and / or a plurality of message portions that have been exchanged between a plurality of different participants within a multitude of authentication and key agreement protocol procedures or within a large number of authentication and key agreement protocol procedures.

[0038] In a further refinement of the application, the data have parameters of an authentication and key agreement of the authentication and key agreement protocol procedure, in particular AKA parameters that are to be regarded as contained in the messages, wherein the parameters are configured as: - authentication credentials of the authentication and key agreement of the authentication and key agreement protocol procedure, - information about a communication partner of the authentication and key agreement protocol procedure, - an Identifizierkennung (identification, ID) of the communication partner of the authentication and key agreement protocol procedure, and / or - user data of the communication partner of the authentication and key agreement protocol procedure.

[0039] The parameters belong to the authentication and key agreement protocol procedure. The parameters can also be regarded as additional information that is derived and / or determined by means of an analysis of the authentication and key agreement protocol procedure. In particular, the parameters are configured as the mentioned authentication credentials, the mentioned information about the communication partner, the mentioned Identifizierkennung of the communication partner and / or the mentioned user data. The parameters make it easier to evaluate and / or check the content of the integrity-protected data, which can also be referred to as AKA verification.

[0040] In a further refinement of the application, the verification unit furthermore has: - a transmission unit, which is configured for transmitting the integrity-protected data.

[0041] The integrity-protected data, also referred to as AKA verification, can be transmitted here either out-of-band or in-band, i.e. outside or inside the cryptographically protected authenticated communication session between the first and second participants within the scope of the authentication and key agreement protocol procedure. In the case of in-band transmission, the transmission can take place within the security protocol itself, for example in the header, or the integrity-protected data can be transmitted by a superior transport protocol or application protocol arranged thereon, for example HTTP, CoAP, MQTT, XMPP. In-band transmission is particularly meaningful if one of the communication partners of the authentication and key agreement protocol procedure has a verification unit. Out-of-band transmission takes place outside the cryptographically protected authenticated communication session between the first and second participants, which is protected by the authentication and key agreement protocol procedure. However, the out-of-band transmission can take place, for example, by the same communication network or by the same communication path.

[0042] Out-of-band transmission has the advantage that the AKA verification, for example the additional authentication of PQ security, can be created independently of the original security protocol (IPsec / IKEv2, TLS, DTLS), can be transmitted and can be verified. Thereby it is possible to supplement the additional protection to unaltered, non-PQ-secure security protocols. Such additional protection alone can be sufficient, in particular in the case when the integrity of the data transmission and the trustworthiness of the communication participants should primarily be protected, for example in the case of the transmission of control messages in an industrial automation system. In such cases, PQ-secure encryption (and thus confidentiality) is often not required or the encryption of the data transmitted cryptographically protected is not required at all.

[0043] In a further refinement of the application, the verification unit furthermore has: an encryption unit, which is configured to provide the integrity-protected data in encrypted form.

[0044] Generally, the provision of the integrity-protected data in encrypted form and / or the encrypted (in-band or out-of-band) transmission has the advantage that the AKA verification using the third credential is encrypted and thus unreadable at the attacker side, which makes attacks on the third credential, for example side-channel attacks, difficult. In contrast, the advantage of the unencrypted transmission is that the AKA verification can be implemented again outside the two participants if necessary and does not have to be additionally protected, which on the one hand can save some computing performance and latency and on the other hand avoids a partially speculatable data set, which is protected using secret credentials, which can make attacks easier if protocol weaknesses are discovered.

[0045] In another refinement of the application, the authentication and key agreement belonging to the authentication and key agreement protocol procedure comprises: - classical cryptography algorithms, in particular Diffie-Hellman key exchange or Elliptic Curve Diffie-Hellman key exchange, - classical cryptography authentication methods, in particular RSA signature, DSA, ECDSA, - post-quantum secure cryptography methods, also referred to as next generation cryptography methods, in particular lattice- or code-based key encapsulation methods (KEM), in particular Kyber, FrodoKEM or Classic McEliece, or - hybrid methods consisting of classical cryptography algorithms and post-quantum secure cryptography methods.

[0046] In another refinement of the application, the confirmation criterion defines a predefinition, under which the creation unit is configured for deriving the data, wherein the predefinition relates to the following items of the authentication and key agreement belonging to the authentication and key agreement protocol procedure: - the security protocol, - the authentication and key agreement method, and / or - the authentication credentials.

[0047] The confirmation criterion (AKA attestation policy) thus determines for which AKA processes an AKA verification should be formed.

[0048] In another refinement of the application, the confirmation criterion defines a condition, under which the creation unit is configured for deriving the data, wherein the condition comprises the following items within the scope of the authentication and key agreement protocol procedure, respectively: - connection establishment, - update of a session key within an already established connection, (update following the connection establishment), and / or - resumption of a previously existing (previous) connection.

[0049] The condition can thus also be understood as a current situation, state, or framework condition between the communication partners.

[0050] A fixed or predefinable AKA verification policy (AKA attestation policy) thus specifies whether only one complete AKA procedure conducted in the context of connection establishment should be detected and verified, or whether also the following Session-Key-Updates or also the reuse of already established Security context in the context of Session Resumption should be detected and verified.

[0051] The application furthermore comprises a device having a verification unit according to the application.

[0052] The verification unit can be embodied as a separate component. The verification unit can also be embodied as an additional component of a device, as in this embodiment. The device is in particular also configured for performing an authentication and key agreement protocol procedure and acting as a communication partner for a further device.

[0053] Such an AKA verification can thus be issued by the first participant (device) and / or by the second participant (further device), or the AKA verification can be issued by a third node (proxy node, attestation node, separate component) which determines the messages or message parts issued in the context of the authentication and key agreement between the first and second participant, for example by network monitoring, and verifies them independently of the first and second node.

[0054] In a further refinement of the application, the device furthermore has: - a negotiation unit configured for performing an authentication and key agreement, whereby a session key is created, and - a communication unit configured for utilizing the session key for protecting a communication, in particular with a further device, in the context of an authentication and key agreement protocol procedure.

[0055] The communication comprises an exchange of data. Data exchanged within the context of an authentication and key agreement protocol procedure thus belong to the authentication and key agreement protocol procedure. The data in particular comprise messages or message parts, AKA messages exchanged - also referred to as AKA protocol messages - and / or control messages in an industrial automation system.

[0056] Furthermore, data belonging to the authentication and key agreement protocol procedure in particular are AKA parameters configured to be contained in messages, cryptographic hash values of AKA messages and / or information about the communication partners participating, in particular devices, participants, in particular user data of a communication participant, an identifier ID of a communication participant and / or authentication credentials used by a communication participant for authentication and key agreement.

[0057] The application furthermore comprises a method for providing integrity protected data, with the steps of: - detecting an authentication and key agreement protocol procedure, - deriving data from the authentication and key agreement protocol procedure, wherein the data belong to the authentication and key agreement protocol procedure, taking into account confirmation criteria, - protecting the data against integrity, thereby forming integrity protected data, and - providing the integrity protected data.

[0058] Before the authentication and key agreement protocol procedure, an authentication and key agreement for setting up a symmetric session key between two participants takes place. The symmetric session key is used for the cryptographic protection of user data which is transmitted between the participants within the scope of the authentication and key agreement protocol procedure (e.g. IPsec, TLS Record Layer, IEEE 802.1AE). The authentication and key agreement is authenticated by means of a first authentication credential (private key) of a first participant (device) by means of a first cryptographic algorithm which is assigned to the first authentication credential. Optionally, in the case of mutual authentication (two-way authentication), the (first) authentication and key agreement is additionally authenticated by means of a second authentication credential (private key) of a second participant (further device) by means of a second cryptographic algorithm which is assigned to the second authentication credential.

[0059] Generally, the first cryptographic algorithm and the second cryptographic algorithm are identical, i.e. the first participant (device) and the second participant (further device) use the same cryptographic algorithm for the authentication, respectively (in particular RSA (classical), ECC (classical), KEM (classical or post-quantum)).

[0060] In one refinement of the application, the method according to the application has the further steps of: - performing an authentication and key agreement, thereby creating a session key, and - communicating within the authentication and key agreement protocol procedure with the session key in order to protect the communication (in particular with the further device).

[0061] In another refinement of the application, the method according to the application has the further step of: - checking the integrity protected data.

[0062] The integrity protected data (also referred to as AKA verification) can be checked by the first and / or second communication participant (device and / or further device). The integrity protected data can also be checked by a special monitoring node (separate component / unit) in order to identify when a non-PQ secure legacy authentication can have been tampered with. If such a monitoring node is used, it can also advantageously be used as a "PQ proxy" in a variant of the application, if the second participant is a non-PQ supported legacy device in the same network as the monitoring node: a non-PQ secure algorithm can be used for the communication session while the PQ secure AKA verification of the first participant is checked by the monitoring node; the monitoring node can subsequently confirm to the second participant (using a non-PQ secure method) that the first participant has successfully authenticated PQ securely with respect to the monitoring node and that the communication is allowed to continue, based on the check of the PQ secure AKA verification of the first participant. This confirmation can be made internally, i.e. by an interface that is not reachable from the outside, if necessary.

[0063] The AKA verification can be checked directly in order to, for example, terminate or block or restrict the communication connection involved (for example by the participant nodes) that is identified as being tampered with. It is also possible to match the rights in the application protocol transmitted via the authenticated and cryptographically secure communication connection to the existence of at least one valid AKA authentication (Attestierung), preferably a multitude of consistent AKA authentications, for this communication session. Access or certificate issuance can therefore only be made via EST / SCEP when the additional check of the AKA verification is successful. It is also possible to match the rights for device configuration via NETCONF / YANG according to the check of the AKA verification. For example, only when the AKA verification for the communication session (for example TLS, ssh) that exists for protecting the NETCONF / YANG transmission has existed and been checked, can security-critical operations be released, such as importing or updating cryptographic keys via NETCONF / YANG to protect TSN communication.

[0064] It is however also possible to evaluate the AKA verification at a later point in time ex post, for example after the communication connection between the first and second participant is disconnected. An alarm can then be generated in the case of invalid, untrustworthy or contradictory AKA verification, for example, or a certificate that has been required or provided via the authenticated communication connection involved can be revoked, or a configuration change of the device configuration or in a database can be rolled back, i.e. the changes made, agreed, can be withdrawn. BRIEF DESCRIPTION OF DRAWINGS

[0065] The features and advantages of the present application can be seen from the following exposition of several embodiments according to the schematic drawings.

[0066] wherein: Figure 1 shows a device according to the prior art, Figure 2 shows a verification unit as an additional component to the device, Figure 3 shows a schematic diagram of integrity protected data belonging to an authentication and key agreement protocol procedure (AKA verification), and Figure 4 shows a schematic diagram of an AKA verification being evaluated. DETAILED DESCRIPTION

[0067] Figure 1 shows a device 1 according to the prior art, wherein an application 11 (App 11) can be protected by a communication module 13 (Communication Protocol 13) by means of a security protocol 12 (Security Protocol 12). The security protocol 12 performs an authentication 121 and a key agreement 121, wherein a session key 1212 is established for the protection 122 of user data of the application 11 for transmission, and wherein the device 1 is authenticated with respect to a communication partner by means of authentication credentials 1211 (Auth-Cred 1211).

[0068] Figure 2 shows an embodiment of the present application for implementing the present application, wherein a verification unit 2 as an additional component 2 (AKA Notary Module 2, AKA Verification System 2) to the device 1 (containing the components shown in Figure 1 forms 23 and provides 24 the verification of an authentication and key agreement protocol procedure.

[0069] It is in principle possible that the communication partner is authenticated using a digital certificate, for example according to X.509, or that the communication partner is authenticated by means of verifiable credentials or by means of a verifiable presentation. For this purpose, the decentralized identifier of the communication partner can be saved in a decentralized transaction data (Distributed Ledger, Blockchain, for example Hyperledger Indy).

[0070] The AKA procedure involved is detected by a detection unit 21 (AKA-Capture- Einheit 21) in the communication protocol procedure and provided to a creation unit 22 (AKA-Notarization-Builder-Komponente 22), which forms an unsigned AKA verification data structure (data belonging to the authentication and key agreement protocol procedure) with the AKA information to be verified.

[0071] The formed AKA verification data structure is then digitally signed by an authentication unit 23 using a verification key 231 (Notary-Cred 231). The digitally signed AKA verification 232 is provided by a providing unit 24. Instead of a digital signature, a KEM method can also be used for verification protection.

[0072] The AKA verification data structure can be checked, for example, by the AKA verification system 2 (AKA-Notarization-Module 2) or by the communication partner. Thereby, a signal or message can be provided to the communication partner, so that the communication partner can correspondingly match its functionality. Instead of a conventional digital signature, the AKA verification 232 can also generally be configured as a verifiable credential or a verifiable representation. Here, the AKA verification unit 2 (AKA-Notarization-Module 2) can be authenticated, for example, by means of a digital certificate, for example according to X.509, or by means of a decentralized identifier, which is saved in a decentralized transaction database (distributed ledger, blockchain, for example Hyperledger Indy).

[0073] The AKA-Notarization-Module 2 can also be integrated in the device 1 (or respectively as shown). In the integrated case, the AKA-Notarization-Module can be arranged, for example, between the security protocol unit 12 and the communication module 13, or the AKA-Notarization-Module can be integrated into the security protocol unit 12. Here, the AKA verification 232 can also be transmitted "in-band", i.e. to the communication partner (for example as part of the user data or as part of the header data of the security protocol 12 or of the communication protocol used for its transmission).

[0074] Figure 3An example for an AKA verification 232 is shown, which comprises the AKA messages (AKA-Message, user data transmitted between the participants) exchanged between the communication partners in the AKA procedure. In the shown example four AKA messages 2321a, 2321b, 2321c, 2321d are shown. Generally, for example, also two, three, five, six or ten AKA messages 2321a, 2321b, 2321c, 2321d can be exchanged in the AKA procedure. Furthermore, the AKA verification 232 comprises a time stamp 2322 and a notary signature 2323.

[0075] Instead of the original AKA messages 2321a, 2321b, 2321c, 2321d, only the cryptographic hash value of each AKA message 2321a, 2321b, 2321c, 2321d, respectively, can also be included in the verification 232. It is also possible to include a hash value formed by the exchanged AKA messages 2321a, 2321b, 2321c, 2321d of the AKA procedure.

[0076] Figure 4 An example for an AKA verification 232 for content evaluation is shown. The AKA verification comprises, in addition to the specification of the used AKA method 2324 (e.g. RSA, DSA, ECDSA, DH, ECDH, KEM, e.g. Kyber, FrodoKEM or Classic McEliece), a time stamp 2322 (or the start time point and the end time point of the AKA procedure), a notary signature 2323 and information 2325a, 2325b about the participating communication partners (each their identifier ID and the authentication credentials Auth-Cred used by them).

[0077] Although the present application has been illustrated and described in detail by embodiments, the application is not limited to the disclosed examples, but rather, other variations can be derived therefrom by a person skilled in the art without departing from the scope of the present application.

Claims

1. A verification unit (2) having: - a detection unit (21) configured for detecting an authentication and key agreement protocol procedure, - a creation unit (22) configured for deriving, in consideration of a confirmation criterion (211), data belonging to the authentication and key agreement protocol procedure from the authentication and key agreement protocol procedure, - an authentication unit (23) configured for protecting the data against integrity, thereby forming integrity-protected data (232), wherein the authentication unit (23) being configured as a signing unit (23), wherein the signing unit (23) is configured to provide the integrity-protected data (232) in a signed form, wherein the signing unit (23) is configured to protect the data against integrity by: ■ a post-quantum secure signature method or a post-quantum secure key wrapping method, or ■ a classical cryptography digital signature method to provide the integrity-protected data (232) in the signed form and / or in an integrity-protected form, and - a providing unit (24) configured for providing the integrity-protected data (232).

2. The verification unit (2) according to claim 1, wherein the data having: - at least one message (2321a, 2321b, 2321c, 2321d) that has been exchanged within the authentication and key agreement protocol procedure, - a message part of a message (2321a, 2321b, 2321c, 2321d) that has been exchanged within the authentication and key agreement protocol procedure, - a control message (2321a, 2321b, 2321c, 2321d) that has been exchanged within the authentication and key agreement protocol procedure in an industrial automation system, - a cryptographic hash value of a message (2321a, 2321b, 2321c, 2321d) that has been exchanged within the authentication and key agreement protocol procedure.

3. The verification unit (2) according to any one of the preceding claims, wherein the data having parameters (2325a, 2325b) of an authentication and key agreement (121) belonging to the authentication and key agreement protocol procedure, wherein the parameters (2325a, 2325b) are configured as: - authentication credentials (1211) of the authentication and key agreement (121) belonging to the authentication and key agreement protocol procedure, - information about a communication partner of the authentication and key agreement protocol procedure, - an identification of a communication partner of the authentication and key agreement protocol procedure, and / or - user data of a communication partner of the authentication and key agreement protocol procedure.

4. The verification unit (2) according to any one of the preceding claims, the verification unit further having: - a transmission unit (24) configured for transmitting the integrity-protected data (232).

5. The verification unit (2) according to any one of the preceding claims, further having: - an encryption unit, the encryption unit being configured for providing the integrity-protected data (232) in an encrypted form.

6. The verification unit (2) according to any one of the preceding claims, wherein, the authentication and key agreement (121) belonging to the authentication and key agreement protocol procedure comprises: - a classical cryptography algorithm, in particular a Diffie-Hellman key exchange or an Elliptic Curve Diffie-Hellman key exchange, - a classical cryptography authentication method, in particular RSA signature, DSA, ECDSA, - a post-quantum secure cryptography method, in particular a lattice- or code-based key encapsulation method, in particular Kyber, FrodoKEM or Classic McEliece, or - a hybrid method consisting of a classical cryptography algorithm and a post-quantum secure cryptography method.

7. The verification unit (2) according to any one of the preceding claims, wherein the confirmation criterion (211) defines a predefinition, under which the creation unit is configured for deriving the data, wherein the predefinition relates to the authentication and key agreement (121) belonging to the authentication and key agreement protocol procedure with respect to: - a security protocol (12), - an authentication and key agreement method, and / or - an authentication credential (1211).

8. The verification unit (2) according to any one of the preceding claims, wherein the confirmation criterion (211) defines a condition, under which the creation unit (22) is configured for deriving the data, wherein the condition comprises, respectively within the scope of the authentication and key agreement protocol procedure: - a connection establishment, - an update of a session key (1212) within an already established connection, and / or - a resumption of a previously existing connection.

9. A device (1) having a verification unit (2) according to any one of the preceding claims.

10. The device (1) according to claim 9, the device furthermore has: - a negotiation unit, the negotiation unit being configured for performing the authentication and key agreement 121, thereby creating a session key (1212), and - a communication unit (13), the communication unit being configured for protecting a communication within the authentication and key agreement protocol procedure with the session key (1212).

11. A method for providing integrity-protected data (232), the method has the steps of: - detecting an authentication and key agreement protocol procedure, - data derived by the authentication and key agreement protocol flow taking into account the confirmation criteria (211), wherein, the data belonging to the authentication and key agreement protocol procedure, - protecting the data with respect to integrity, thereby forming integrity-protected data (232), and - providing the integrity-protected data (232).

12. The method according to claim 11, the method has the further steps of: - performing an authentication and key agreement, thereby creating a session key (1212), and - communicating within the authentication and key agreement protocol procedure with the session key (1212) for protecting the communication.

13. The method according to claim 11 or 12, The method has the further step of: - checking the integrity-protected data (232).