Computer-implemented method for providing data, in particular for consistency tracking
By using blockchain technology in distributed peer-to-peer networks, data blocks are generated and verified to form blockchains, the problem of inefficient evidence and document management in the existing technology is solved, data non-forgery and automated processing are realized, and the security and consistency management of facilities and products are improved.
Patent Information
- Application Number
- CN201980034437.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-03-23
- Filing Date
- 2019-02-28
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2039-02-28
AI Technical Summary
In the prior art, the management of evidence and documents is carried out through manual and paper-based processes, resulting in inefficiency, easy loss, and difficult to automate, affecting the safety and consistency management of facilities and products.
By implementing blockchain technology in a distributed peer network, a computer-implemented method is provided for generating and verifying data blocks, forming a blockchain, and achieving consistency tracking. The method includes providing a data block, verifying permission verification proof, generating a blockchain and providing it in a peer-to-peer network, where the data block can be constructed as a smart contract for providing error handling measures and triggering functional verification.
It realizes the non-forgery of data, automated processing, data integrity in cooperation, improves data availability and access speed, enhances transparency and auditability, reduces costs and improves facility security.
Smart Images

Figure CN112119417B_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a computer-implemented method for providing data, in particular for consistency tracking. Background Art
[0002] Products and systems may contain potential hazards and are therefore subject to guidelines, regulations and laws, the compliance of which is monitored by authorities or through so-called notified bodies. This monitoring may cover design, manufacture, documentation, assembly, commissioning, operation and disposal or disassembly, that is to say the entire service life of the system or product.
[0003] The legislator has established an inspection and certification process for this purpose, which is carried out by a conformity assessment body with corresponding authority.
[0004] Depending on the industry, facility, system or product, areas or parts relevant for monitoring are identified during the design or planning process and valid requirements are proposed based on standards, guidelines, regulations and laws.
[0005] The basic and detailed designs are correspondingly carried out, documented, verified and approved for implementation.
[0006] During the construction phase and after its completion, the realized technical system / product prototype is tested against the approved planning and, based on the test results, the construction or market release is authorized (declaration of conformity, operating license).
[0007] In order to maintain compliant operations, repeated or random inspections (e.g. for facility or product safety) are carried out and documented where necessary. Likewise, evidence of professional disassembly and disposal is necessary at the end of the service life and documented accordingly.
[0008] In the case of a processing plant, for example, for each phase of the service life of a system there is documentation for the corresponding phase.
[0009] This procedure is the responsibility of the manufacturer or operator and their representatives.
[0010] The loss of this documentation or parts of it can lead to the revocation of operating permits, recalls, new construction, closure of facilities and thus to huge losses. Failure to comply with guidelines and laws can also lead to imprisonment if necessary.
[0011] The documentation for compliance with all laws and guidelines and the associated inspection certificates is an extensive and complex task at the present time, which involves at least three parties (manufacturer, inspector, operator) and many qualified personnel. The documentation must be archived for decades, but also revised so that it is available at any point in time, for example in the event of an audit or an operating accident. All cause analyses, corrective measures, and especially liability issues must include the latest information contained here.
[0012] Until now, evidence and documentation have been conducted through manual and paper-based processes. The resulting paper documents with verification stamps and signatures are extensive, complex, slow and inflexible.
[0013] Using physical stamps to approve documents is inadequate, unsafe to forge, and cannot be automated.
[0014] For example, acceptance of fail-safe controls, which already provide digital checksums in validated digital systems, is performed based on paper documents.
[0015] The use of traditional document formats hinders automation and forces the processing of larger units. Flexible, granular and modular processing of subsystems or the exchange of individual products of a larger system always requires a modification of the larger system, which involves corresponding costs.
[0016] The production of multiple originals is laborious in terms of distribution and archiving, and these originals are produced over decades with high administrative costs. Summary of the invention
[0017] Therefore, it is the task of the present invention to provide a remedy for the vector.
[0018] The object is achieved by a computer-implemented method for providing data in a distributed peer-to-peer network, in particular for consistency tracking, the method comprising the following steps:
[0019] - providing at least one first data block, in particular a first data block having data representing a consistency trace, for generating a blockchain having a first checksum by a first instantiation of a peer-to-peer network,
[0020] - provide at least one proof-of-authority for verifying another block of data,
[0021] - generating, by a further instantiation of the peer-to-peer network, a further data block representing the consistency track, the further data block having a further checksum and at least the first checksum,
[0022] - Check the authority verification certificate,
[0023] - in the event of a successful verification of the proof of authority, adding a further data block to the first data block in order to form a blockchain, and
[0024] - Provide blockchain in a distributed peer-to-peer network,
[0025] One of the data blocks is designed as a smart contract, which provides error handling measures based on the presence of a predetermined error situation and / or triggers a functional test based on the presence of a test trigger signal.
[0026] Instances can be assigned to different participants, such as, for example, suppliers, facility builders, quality managers and notification agencies. The first instance is an instance that starts the blockchain by forming the first data block. By using proof of authority verification, the required computing power is reduced in comparison with legalization by proof of work, and at the same time it is possible to update the blockchain faster by adding new data blocks. Here, the proof of authority verification gives the instance the ability to verify a transaction (transaction) (for example, by a so-called validator) and include the transaction in the block. The proof of authority verification can be provided by the first instance. Alternatively or additionally, it can also be provided that another instance can provide the proof of authority verification.
[0027] Here, the verification of the authority verification proof includes transmitting the data block added to the blockchain together with the authority verification proof to other instances, which check the authority verification proof and issue an approval to add the data block to the blockchain if the verification is successful. A criterion can be set for approval, for example, half of the instances issue approval.
[0028] The following advantages are achieved by the method according to the invention:
[0029] 1. Unforgeability: The unforgeability inherent in the blockchain architecture enables the digitization of certification stamps.
[0030] 2. Quality: Due to the conversion of workflows into digital processes and their automation, human errors are minimized.
[0031] 3. Integrity in collaboration: A high level of trust between agent participants is established by a high level of access authorization and regarding the unforgeability of stored data.
[0032] 4. Availability and access speed of data:
[0033] Digitization in distributed, automatically replicating databases enables speeds for these data that were previously unattainable.
[0034] 5. Transparency and auditability: The structuring and modularization of data in digital processes enables a better understanding of content and processes. Auditability is simplified, and facility risks can be calculated and reduced. Insurance premiums for operators fall.
[0035] 6. Speed up: Planning, construction and commencement can be greatly accelerated without the need to send documents and on-site acceptance. Measures can be taken immediately to maintain production.
[0036] 7. Reduced expenses and costs: Automation within blockchain provides all parties with additional efficiency gains in the workflow.
[0037] Furthermore, since the basic authentication process (verification of data by an inspector or a notified body) and the high-value authentication are retained, the effects of attacks against the human-machine interface are well identified and therefore limited.
[0038] Due to the complete digitalization, it is now also possible to exchange non-document-type data between the participants. This means that data formats of proprietary software can be exchanged and, for example, transferred for inspection purposes. For example, a created program for a fail-safe control can be transferred to the TÜV as a proprietary Simatic file (including the associated checksums), which can then check this file for errors, for example in an inspection simulation, without publishing its inspection mechanisms and tools. This increases the quality of the inspection and, therefore, also the safety of the facility.
[0039] This functionality can be greatly simplified through agreement and use of manufacturer-neutral data formats.
[0040] In addition, traditional documents in the form of PDF documents can also be stored in the blockchain, so that, for example, traditional paper documents can be generated from the blockchain at important milestones (design freeze, construction acceptance, temporary takeover, etc.).
[0041] Here, a smart contract is understood to be a software-based contract in which very different contractual conditions can be stored. During the course of the contract, certain associated activities (such as payment) can be automatically implemented when a corresponding trigger exists (such as the fulfillment of a contractual condition). Thus, for example, the blockchain can be used to provide error handling measures. If an error occurs in a component of an installation (such as, for example, a field device), an error signal corresponding thereto triggers a data block constructed as a smart contract, so that corresponding measures for error handling are then implemented, such as, for example, the deactivation of a defective field device and a notification for replacement.
[0042] For transparent and globally accepted application of the technology, smart contracts can be published as open source source code whenever possible. The release (git-hub) serves the review, verification and improvement of the technology, and therefore also the security of products and systems. By providing the source code including the associated checksum of the compiled smart contract, the use of the smart contract in the blockchain can be verified by users at any time, so that disputes can be reduced.
[0043] This results in the following advantages:
[0044] 1. New automated protective effects: By combining the current consistency state online in the blockchain, new autonomous protective effects can be triggered in the operation of the facility (for example, stopping the facility), which also include management aspects of security.
[0045] 2. Self-documentation: The integration of product-specific smart contracts enables the documentation and verification of safety-related properties during planning and implementation (e.g. configuration management according to the Safety Integrity Level SIL).
[0046] 3. New services in the field of facility security and compliance: The technology enables new digital services in the field of product and system security, which can be realized using the platform.
[0047] According to one embodiment, the test trigger signal requires a test signal. In other words, the smart contract has the effect of generating a test signal within a predetermined time period. Thus, the test trigger is automated.
[0048] According to a further embodiment, the test signal is provided by the smart contract. Thus, the test signal is generated by the smart contract itself. Thus, no further intervention is required, for example to manually trigger the test signal. Rather, the test signal is automatically generated.
[0049] According to a further embodiment, the smart contract provides a reset signal. This allows the system to be placed in a state corresponding to the state before the test in response to a successful test.
[0050] According to another embodiment, the smart contract provides a feedback signal. Thus, the blockchain is updated by the feedback signal, and successfully passed tests are archived and published.
[0051] According to another embodiment, the peer-to-peer network is a private network. Therefore, the blockchain is a federated blockchain or a consortium blockchain, that is, a non-public blockchain.
[0052] According to a further embodiment, the authority verification proof has at least one time-limited validity period. In this context, time-limited validity is understood to mean that the authority verification proof has an expiration date, and after the expiration date, one of the other instances can no longer be used to add further data blocks to the blockchain. Thus, for example, a situation can be constructed in which the verified proof must be generated within a predetermined time period. In addition, misuse is thus counteracted, since the authority verification proof does not have an infinite service life.
[0053] According to another embodiment, the authorization verification certificate has at least one validity in terms of content. The validity in terms of content is understood to mean that the authorization verification certificate only authorizes the predetermined input, such as, for example, confirming that a check has been carried out. In other words, the authorization verification certificate is object-related (sachgebunden). Therefore, misuse can also be resisted.
[0054] According to another embodiment, the authorization verification certificate has at least one user-related validity. User-related validity is understood to mean that the authorization verification certificate only authorizes the corresponding predetermined instance to be able to perform a predetermined input, such as, for example, confirming that a check has been carried out. In other words, the authorization verification certificate is personalized or user-related.
[0055] According to another embodiment, one of the data blocks is constructed as a smart contract, which provides a proof of authority verification based on the existence of a predetermined condition. Therefore, one of the data blocks can be constructed, for example, to provide a proof of authority verification based on the existence of a predetermined condition. Therefore, not only does the first instance generate a proof of authority verification, but when the predetermined conditions of the previous step, such as, for example, proof of an intermediate test or preliminary inspection, have been proven by entering into the blockchain, the corresponding proof of authority verification is generated and provided. Therefore, the generation of the proof of authority verification in a "reserve for backup" manner at the beginning and their secure archiving to prevent unauthorized access is eliminated, which improves security.
[0056] According to a further embodiment, a repair function for changing and / or marking at least one data block is provided. For this purpose, a smart contract can be provided, which names or identifies errors or erroneous data in response to the explicit consent of all participants. For example, it can then be possible to enable an interpretation in the case of erroneous content. In addition, such a system and a computer program product belong to the present invention. A first computer program product can be provided for a first instance, and a second computer program product can be provided for a further instance. The third computer program product can be a smart contract, which provides error handling measures based on the presence of a predetermined error situation and / or triggers a functional check based on the presence of a test trigger signal.
[0057] According to a further aspect, the invention relates to a computer-implemented method for checking a technical system, in particular for consistency tracking, the method comprising the following steps:
[0058] - Load and / or implement test control transactions, where
[0059] o Especially load testing control transactions from web applications,
[0060] o Test control transactions including control commands and reference data;
[0061] -Control test module, where
[0062] o the control commands operate the test module in such a way that test signals are generated for the subsystems of the technical system;
[0063] - Detection of measurement data of the subsystem as a reaction to the test signal, wherein
[0064] o The measurement data is detected by the test module,
[0065] o In particular, the detection of measurement data by sensors of the test module;
[0066] -Calculate the inspection results based on the measured data and reference data;
[0067] - controlling a technical system as a function of the test result and / or carrying out a control function as a function of the test result.
[0068] According to a further embodiment, the test trigger signal (37) requires loading and / or executing a test control transaction.
[0069] According to further embodiments, the activities of the system and / or the test modules are logged and stored in log files or data records or transactions.
[0070] According to further embodiments, the test control transaction comprises or is a smart contract.
[0071] According to a further embodiment, a reset signal (42) is provided for the subsystem depending on the test result, or the control function provides a reset signal (42) for the subsystem depending on the test result.
[0072] According to a further embodiment, a feedback signal (40) is provided to the subsystem depending on the test result, or the control function provides a feedback signal (40) to the subsystem depending on the test result.
[0073] According to another embodiment, the inspection result is stored in the confirmation transaction, for example. Alternatively or additionally, the measurement data is stored in the measurement data transaction, for example. Alternatively or additionally, the inspection result is calculated based on the measurement data of the measurement data transaction, for example. Alternatively or additionally, for example, the confirmation transaction and / or the measurement data transaction and / or the test control transaction are protected by means of corresponding authority verification certificates. For example, the confirmation transaction and / or the measurement data transaction are protected by means of the authority verification certificate of the technical system, subsystem or facility operator. For example, the test control transaction is protected by means of the authority verification certificate of the entity, the trusted entity (such as TÜV) or the third party. Alternatively or additionally, for example, the confirmation transaction and / or the measurement data transaction and / or the test control transaction are stored in the corresponding data block. Alternatively or additionally, for example, additional / metadata for inspection is stored in the confirmation transaction. Alternatively or additionally, for example, the corresponding data block includes the corresponding authority verification certificate of the corresponding transaction.
[0074] According to further embodiments, the network application is implemented in a peer-to-peer network (1) or by a peer-to-peer network (1), wherein in particular the peer-to-peer network (1) is a private network.
[0075] According to a further embodiment, the authorization verification certificate ( 10 ) has at least one time-limited validity period.
[0076] According to a further embodiment, the authority verification certificate ( 10 ) has at least one validity in terms of content.
[0077] According to a further embodiment, the authorization verification certificate ( 10 ) has at least one user-related validity.
[0078] According to a further embodiment, the data block (4a, 4b, 4c) is designed as a smart contract which provides an authorization verification certificate (10) based on the existence of a predetermined condition.
[0079] According to a further embodiment, a repair function is provided for modifying and / or marking at least one of the data blocks (4a, 4b, 4c).
[0080] According to a further aspect, the invention relates to a system for providing data, comprising means for implementing the steps of the method according to one of claims 1 to 12.
[0081] According to a further aspect, the invention relates to a device or a system for checking a technical system / the technical system, in particular for consistency tracking, the device or the system having:
[0082] - For example, loading a module where
[0083] o For example, load modules are set up to load and / or perform test control transactions,
[0084] o For example, load test control transactions from a web application,
[0085] o For example, a test control transaction includes control commands and reference data;
[0086] - For example, a test module, where
[0087] o For example, the test module is set up to be controlled by means of control commands,
[0088] o For example, the control commands operate the test module in such a way that a test signal is generated for a subsystem of the technical system;
[0089] - For example, a detection module, wherein
[0090] o For example, a detection module is set up to detect measurement data of a subsystem as a reaction to a test signal,
[0091] o For example, the measurement data is detected by the test module,
[0092] o For example, the measurement data is detected by the sensors of the test module;
[0093] o For example, the detection module is a sensor;
[0094] For example, a calculation module, wherein the calculation module is configured to calculate a test result based on the measurement data and the reference data;
[0095] For example, a control module, wherein for example the control module is designed to control the technical system as a function of the test result and / or to carry out a control function as a function of the test result.
[0096] According to a further aspect, the invention relates to a computer program product comprising instructions causing the computer to carry out at least one of the steps of claims 1 to 12 when the program is carried out by a computer, wherein the computer is assigned to the first instance (5a).
[0097] According to a further aspect, the invention relates to a computer program product comprising instructions causing the computer to carry out at least one of the steps of claims 1 to 12 when the program is carried out by a computer, wherein the computer is assigned to one of the further instances (5b, 5c).
[0098] The technology of blockchains or "distributed ledgers" is currently a hotly discussed technology, which can be implemented in particular as a distributed database system or as a network application. In addition to the application of decentralized payment systems, new application possibilities have been developed in the financial industry. In particular, transactions between companies can be implemented in a manipulation-resistant manner without intermediaries or clearing houses. This enables new business models without trusted intermediaries, which reduces transaction costs and allows new digital services to be offered flexibly without having to set up a specially established infrastructure and trust relationships for this purpose. The transaction data records (or transactions for short) protected by the blockchain include, for example, program code, which can also be referred to as so-called "smart contracts".
[0099] Unless otherwise indicated in the following description, the terms "implement", "calculate", "computer-aided", "calculate", "determine", "generate", "configure", "reconstruct", etc. preferably relate to an act and / or a process and / or a processing step of changing and / or generating data and / or converting data into other data, wherein the data can be represented or present in particular as physical variables, for example as electrical impulses. In particular, the expression "computer" should be interpreted as broadly as possible in order to cover in particular all electronic devices with data processing properties. Thus, a computer can be, for example, a personal computer, a server, a programmable memory controller (SPS), a handheld computer system, a pocket PC device, a mobile radio device and other communication devices, processors and other electronic devices for data processing that can process data in a computer-aided manner.
[0100] Within the context of the present invention, “computer-assisted” may be understood to mean, for example, an implementation of the method, wherein in particular a processor carries out at least one method step of the method.
[0101] In the context of the present invention, a processor can be understood as, for example, a machine or an electronic circuit. The processor can be, in particular, a main processor (Central Processing Unit, CPU), a microprocessor or a microcontroller, such as an ASIC or a digital signal processor, which may be combined with a memory unit for storing program commands, etc. The processor can also be, for example, an IC (Integrated Circuit), in particular an FPGA (Field Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit) or a DSP (Digital Signal Processor) or a Graphic Processing Unit GPU (Graphic Processing Unit). The processor can also be understood as a virtualized processor, a virtual machine or a soft CPU. It can also be, for example, a programmable processor, which is equipped with a configuration step for implementing the method according to the present invention or is configured using a configuration step so that the programmable processor implements the method, components, modules or other aspects and / or sub-aspects of the present invention.
[0102] In the context of the present invention, a “memory unit” or “memory module” etc. may be understood to mean a volatile memory, for example in the form of a working memory (Random Access Memory, RAM) or a permanent memory, such as a hard disk or a data carrier.
[0103] In the context of the present invention, "module" can be understood as a processor and / or memory unit, for example, for storing program commands. For example, a processor is specially set up to implement program commands so that the processor implements functions to execute or implement the method according to the present invention or the steps of the method according to the present invention. A module can also be, for example, a node of a distributed database system and / or a network application, which, for example, implements specific functions / features of a corresponding module. The corresponding module can also be, for example, constructed as a separate or independent module. For this purpose, the corresponding module can, for example, include other elements. These elements are, for example, one or more interfaces (for example, database interfaces, communication interfaces, such as network interfaces, WLAN interfaces) and / or evaluation units (such as processors) and / or memory units. With the aid of the interface, data can be exchanged (for example, received, transmitted, sent or provided). With the aid of the evaluation unit, data can be compared, checked, processed, distributed or calculated, for example, in a computer-aided and / or automated manner. With the aid of a memory unit, data can be stored, retrieved or provided, for example, in a computer-aided and / or automated manner.
[0104] Within the context of the present invention, “comprising”, in particular with regard to data and / or information, may be understood as, for example, the (computer-aided) storage of corresponding information or corresponding data in a data structure / data record (which in turn is stored, for example, in a memory unit).
[0105] In the context of the present invention, "assignment", in particular with regard to data and / or information, may be understood to mean, for example, a computer-aided assignment of data and / or information. For example, for this purpose, second data are assigned to first data by means of a memory address or a unique identifier (UID), for example, by storing the first data together with the memory address or the unique identifier of the second data in a data record.
[0106] In the context of the present invention, "providing", in particular with regard to "providing" data and / or information, can be understood as, for example, computer-assisted providing. For example, the providing takes place via an interface (e.g. a database interface, a network interface, an interface to a memory unit). Via the interface, for example, the corresponding data and / or information can be transmitted and / or sent and / or retrieved and / or received during the providing.
[0107] In the context of the present invention, "providing" may also be understood as, for example, loading or storing, for example, a transaction with corresponding data. This may be performed, for example, on or by a memory module. "Providing" may also be understood as, for example, transferring (or sending or transmitting) corresponding data from one node of a blockchain or distributed database system (or its infrastructure) or a network application to another node.
[0108] In the context of the present invention, "checksum", such as data block checksum, data checksum, node checksum, transaction checksum, connection checksum, etc., can be understood as, for example, cryptographic checksum or cryptographic hash or hash value, which is formed or calculated by cryptographic hash function about one or more and / or sub-areas of data blocks in data records and / or data and / or transactions (for example, block headers of blocks of blockchain or data block headers of data blocks of distributed database systems (or network applications) or only a part of transactions of data blocks). The checksum can be, in particular, (one or more) checksums or hash values (one or more) of hash trees (for example, Merkle trees, Patricia trees). In addition, it can also be understood as a digital signature or a cryptographic message authentication code. With the help of checksums, cryptographic protection / anti-manipulation protection for transactions and data (records) stored therein can be implemented, for example, at different levels of the database system. If, for example, high security is required, then, for example, a checksum is generated and checked at the transaction level. If lower high security is required, then, for example, a checksum is generated and checked at the block level (for example, by the entire data block or only by a part of the data block and / or a part of the transaction).
[0109] In the context of the present invention, a "block checksum" may be understood as a checksum calculated, for example, over a portion or all of the transactions of a block. The node may then, for example, verify / determine the integrity / authenticity of the corresponding portion of the block by means of the block checksum. Additionally or alternatively, the block checksum may also be formed, in particular, by means of transactions of a preceding block / predecessor block of the block. The block checksum may also be implemented, in particular, by means of a hash tree, such as a Merkle tree [1] or a Patricia tree, wherein the block checksum is in particular the root checksum of a Merkle tree or a Patricia tree or a binary hash tree. In particular, transactions are protected by means of another checksum from a Merkle tree or a Patricia tree (for example, in the case of using a transaction checksum), wherein in particular the other checksum is a leaf in a Merkle tree or a Patricia tree. Thus, the block checksum may, for example, protect transactions by forming a root checksum from another checksum. The block checksum may in particular be calculated for transactions of a specific block in a block. In particular, such a data block checksum may be included in a subsequent data block of a particular data block, in order to link the subsequent data block, for example, with its preceding data block and in particular thereby to make the integrity of the distributed database system (or network application) verifiable. Thus, the data block checksum may, for example, assume the function of a link checksum or be included in a link checksum. The header of a data block (e.g. a new data block or a data block for which a data block checksum has already been formed) may, for example, include a data block checksum.
[0110] In the context of the present invention, a "transaction checksum" may be understood as a checksum formed in particular by a transaction of a data block. In addition, for example, the calculation of a data block checksum of a corresponding data block may be accelerated, since for this purpose, for example, an already calculated transaction checksum may be immediately used as a leaf of a Merkle tree, for example.
[0111] In the present invention, for example, a checksum (for example a transaction checksum) is based on a pre-standardized or pre-given function for security (for example, a function or a security function for testing a subsystem or a subsystem). Such a function for security is, for example, the same throughout the installation (for example, a technical system) and is preferably adapted specifically to the installation. In the case of an installation-specific adaptation, for example, a new checksum for the function is derived for the corresponding adapted function for security. The adapted function for security and / or the associated checksum are used, for example, throughout the service life of the installation and / or as a reference for changes. For example, the structure of the installation and / or the function for security are constructed with the aid of a Merkle tree and its structure.
[0112] In the context of the present invention, a “join checksum” can be understood as a checksum of a previous data block of a distributed database system (or network application) (often referred to as a “previous block hash” in the professional literature in particular) [1] which describes or refers to a corresponding data block of the distributed database system (or network application). For this purpose, a corresponding join checksum is formed in particular for the corresponding previous data block. For example, a transaction checksum or a data block checksum of a data block (that is, an existing data block of the distributed database system or network application) can be used as a join checksum in order to join a new data block to an (existing) data block of the distributed database system (or network application). However, it is also possible, for example, for the checksum to be formed over the header of the previous data block or over the entire previous data block and to be used as a join checksum. This can also be calculated, for example, for multiple or all previous data blocks. It is also possible, for example, to form a join checksum over the header of the data block and the data block checksum. However, the corresponding data blocks of the distributed database system (or network application) preferably include a respective join checksum, which is calculated for the preceding data block of the corresponding data block, especially more preferably the directly preceding data block, or relates to the preceding data block of the corresponding data block, especially more preferably the directly preceding data block. For example, it is also possible to form the corresponding join checksum only by a part of the corresponding data block (for example the preceding data block). Thus, for example, a data block including an integrity-protected part and an unprotected part can be realized. Therefore, for example, the following data block can be realized, the integrity-protected part of the data block is unchanged and the unprotected part of the data block can still be changed later (so that, for example, data related to personnel can also be stored in the unprotected part). Integrity protection is here especially understood as, by means of the checksum, the change to the integrity-protected data can be determined.
[0113] For example, the data stored in the transaction of the data block can be provided in different ways. Instead of data, for example user data, such as measurement data or data / ownership relationships related to the asset, for example, the transaction of the data block can only include the checksum of these data. The corresponding checksum can be implemented in various ways. This can be, for example, the corresponding data block checksum of the data block (with corresponding data) of another database or distributed database system (or network application), the transaction checksum of the data block with corresponding data (of the distributed database system / network application or another database), or the data checksum formed by the data.
[0114] Furthermore, the corresponding transaction may also include a reference or description of a memory location (e.g. the address of a file server and a description of where the corresponding data can be found on the file server; or the address of another distributed database / network application that includes the data). The corresponding data may then also be provided, for example, in a further transaction of a further data block of the distributed database system / network application (e.g. when the corresponding data and the associated checksum are included in different data blocks). However, it is also conceivable, for example, to provide these data via another communication channel (e.g. via another database and / or a cryptographically secure communication channel).
[0115] For example, in addition to the checksum, additional data records (e.g., references or descriptions of memory locations) can be stored in the corresponding transaction, which in particular describe the memory locations from which data can be retrieved. This is particularly useful for keeping the data size of the blockchain or distributed database system / network application as small as possible.
[0116] In the context of the present invention, "security protection" can be understood as, for example, protection that is achieved, in particular, by cryptographic methods. For example, this can be achieved by using a distributed database system (or a network application) for providing or transmitting or sending the corresponding data / transactions. This is preferably achieved by combining different (cryptographic) checksums in such a way that these checksums interact, in particular, in a coordinated manner, in order to, for example, improve the security or cryptographic security of the transaction data. In other words, in the context of the present invention, "security protection" can also be understood as, in particular, "cryptographic protection" and / or "protected against manipulation", wherein "protected against manipulation" can also be referred to as "integrity protection".
[0117] Within the context of the present invention, "a connection of data blocks of a distributed database system / network application" can be understood, for example, as a data block including information (such as a connection checksum) that refers to or references another data block or multiple other data blocks of the distributed database system (or network application) [1][4][5].
[0118] In the context of the present invention, "insertion into a distributed database system / network application" etc. can be understood, for example, to mean that, in particular, one or more transactions or data blocks with their transactions are transmitted to one or more nodes of the distributed database system / network application. If these transactions are, for example, successfully verified (for example, by one / more nodes), these transactions are linked to at least one existing data block of the distributed database system / network application as new data blocks [1][4][5]. For this purpose, the corresponding transaction is stored, for example, in the new data block. In particular, this verification and / or linking can be performed by a trusted node (for example, a mining node, a blockchain Orakel (blockchain oracle) or a blockchain platform). In particular, a blockchain platform can be understood here as a blockchain as a service, as proposed in particular by Microsoft or IBM. In particular, the trusted node and / or the node can respectively store a node checksum (for example, a digital signature) in the data block (for example, in the data block verified and generated by it, which is then linked) in order to in particular enable the identifiability of the creator of the data block and / or enable the identifiability of the node. In this case, the node checksum indicates which node has, for example, linked the corresponding data block to at least one other data block of the distributed database system (or network application).
[0119] In the context of the present invention, a "transaction" or "multiple transactions" may be understood, for example, as a smart contract [4][5], a data structure or a transaction data record, wherein the smart contract [4][5], the data structure or the transaction data record may in particular include one or more transactions respectively. In the context of the present invention, a "transaction" or "multiple transactions" may in particular also be understood as transaction data of a data block of a blockchain. A transaction may in particular include, for example, a program code for implementing a smart contract. For example, in the context of the present invention, a transaction may also be understood as a control transaction and / or a confirmation transaction. Alternatively, a transaction may in particular be a data structure for storing data (e.g., control commands and / or contract data and / or other data such as video data, user data, measurement data, etc.).
[0120] In particular, "storage of transactions in data blocks", "storage of transactions", etc. are understood to be direct storage or indirect storage. Direct storage can be understood here, for example, that the corresponding data block (of the distributed database system / network application) or the corresponding transaction (of the distributed database system / network application) includes the corresponding data. Indirect storage can be understood here, for example, that the corresponding data block or the corresponding transaction includes a checksum of the corresponding data and optionally an additional data record (for example, a reference or description to a memory location), and the corresponding data is therefore not directly stored in the data block (or transaction) (that is, only the checksum of these data instead). In particular, these checksums can be verified, for example, when the transaction is stored in the data block, as explained in "insertion into the distributed database system / network application".
[0121] In the context of the present invention, "program code" (e.g., smart contract or chain code) can be understood, for example, as one program command and / or multiple program commands, which are in particular stored in one or more transactions. The program code is in particular executable and is implemented, for example, by a distributed database system / network application. This can be achieved, for example, with the aid of an implementation environment (e.g., a virtual machine), wherein the implementation environment and the program code are preferably fully Turing-compatible. The program code is preferably implemented by the infrastructure of the distributed database system / network application [4][5]. Here, for example, a virtual machine implemented by the infrastructure of the distributed database system (or network application).
[0122] In the context of the present invention, a "smart contract" may be understood as, for example, an executable program code [4] [5] (see in particular the definition of "program code"). The smart contract is preferably stored in a transaction of a distributed database system / network application (e.g. a blockchain), for example in a data block of a distributed database system (or network application). For example, a smart contract may be implemented in the same manner as explained in the definition of "program code" (in particular in the context of the present invention).
[0123] Within the context of the present invention, a “smart contract process” may be understood as in particular the execution of program code (eg control commands) in a process by a distributed database system / web application, wherein for example a corresponding infrastructure of the distributed database system / web application implements the program code.
[0124] In the context of the present invention, "proof of work" may be understood as, for example, the solution of a computationally intensive task, which task depends inter alia on the data block content / content of a specific transaction to solve [1][4][5]. Such computationally intensive tasks are, for example, also known as cryptographic puzzles.
[0125] In the context of the present invention, a "network application" may be understood as, for example, a decentralized distributed database, a distributed database system, a distributed database, a peer-to-peer application, a distributed memory management system, a blockchain, a distributed ledger, a distributed memory system, a system (DLTS) based on distributed ledger technology (DLT), a database system with a revised security, a cloud, a cloud service, a blockchain in the cloud or a peer-to-peer database. For example, different implementations of a blockchain or a DLTS may also be used, such as, for example, a blockchain or a DLTS implemented with the aid of a directed acyclic graph (DAG), a cryptographic puzzle, a hash graph or a combination of said implementation variants [6][7]. For example, different consensus methods (consensus algorithms) may also be implemented. This may be, for example, a consensus method with the aid of a cryptographic puzzle, gossip about gossip, virtual voting or a combination of said methods (e.g. gossip about gossip combined with virtual voting) [6][7]. If, for example, a blockchain is used, then the blockchain may in particular be implemented with the aid of an Ethernet-based implementation [1][4][5]. A “distributed database system” or “web application” can also be understood as, for example, a distributed database system or a web application, wherein at least part of its nodes and / or devices and / or infrastructure is implemented by the cloud. For example, the corresponding components are implemented as nodes / devices in the cloud (for example as virtual nodes in a virtual machine). This can be done, for example, with the aid of a VM system (VM-Ware), Amazon Web Services or Microsoft Cloud (Microsoft Azure). Due to the high flexibility of the explained implementation variants, sub-aspects of the implementation variants can also be combined with one another, for example by using a hash map as a blockchain, wherein the blockchain itself can also be blockless, for example.
[0126] If, for example, a directed acyclic graph (DAG) is used (e.g. IOTA or Tangle), in particular the blocks or nodes of a transaction or graph are connected to one another via directed edges. This means in particular that (all) edges (always) have the same direction, similar to, for example, the case of time. In other words, it is in particular not possible for a block or node of a transaction or graph to start or jump backwards (that is, in the opposite direction to the same common direction). Acyclic in this context means in particular that there are no loops when running through the graph.
[0127] The distributed database system / network application may be, for example, a public distributed database system / public network application (e.g., a public blockchain) or a closed (or private) distributed database system / closed network application (e.g., a private blockchain).
[0128] If, for example, a public distributed database system / public web application is involved, this means that new nodes and / or devices can join the distributed database system / web application or be accepted by the distributed database system without requiring proof of authorization or authentication or registration information or credentials. In particular, in this case, the operators of the nodes and / or devices can remain anonymous.
[0129] If the distributed database system / network application is, for example, a closed distributed database system, then new nodes and / or devices require, for example, valid authorization certificates and / or valid authentication information and / or valid registration information in order to be able to join the distributed database system / network application or be accepted by the distributed database system.
[0130] A distributed database system / network application can also be, for example, a distributed communication system for data exchange. This can be, for example, a network or a peer-to-peer network.
[0131] The distributed database system may also be, for example, a decentralized distributed database system and / or a decentralized distributed communication system.
[0132] A "network application" may also be, for example, a network application infrastructure, or a network application includes a corresponding network application infrastructure. The infrastructure may, for example, include nodes and / or a communication network and / or a data interface and / or other components to implement or implement the network application. The network application may, for example, be a distributed network application (e.g., a distributed peer-to-peer application or a distributed database system), which is implemented, for example, on multiple nodes of the network application infrastructure.
[0133] In the context of the present invention, a "data block", which may also be referred to as a "link" or "block" depending on the context and implementation, may be understood to be, for example, a data block of a distributed database system / network application (e.g., a blockchain or a peer-to-peer database), which is implemented in particular as a data structure and preferably includes one or more of the transactions. In one implementation, the database (or database system) may be, for example, a distributed ledger technology (DLT)-based system (DLT) or a blockchain, and the data block may be a block of the blockchain or DLT. The data block may, for example, include a description of the size of the data block (data size in bytes), a data block header (Blockheader in English), a transaction counter and one or more transactions [1]. The data block header may, for example, include a version, a join checksum, a data block checksum, a timestamp, a proof of work and a nonce (a one-time value, a random value or a counter for proof of work) [1][4][5]. The data block may also, for example, be just a specific memory area or address area of the total data stored in the distributed database system / network application. Therefore, for example, blockless distributed database systems / network applications such as IoT Chain (ITC), IOTA and Byte Ball can be realized. In this case, in particular, the functions of the blocks of transactions and blockchains are combined with each other so that, for example, the transaction itself protects (that is, is stored in a secure manner in particular) the sequence or chain of transactions (of the distributed database system / network application). To this end, the transactions themselves can be linked to each other, for example, using a connection checksum, in which case a separate checksum or a transaction checksum of one or more transactions is preferably used as a connection checksum, and the connection checksum is also stored in the corresponding new transaction when the new transaction is stored in the distributed database system / network application. In such an embodiment, a data block can also include one or more transactions, wherein in the simplest case, for example, one data block corresponds to one transaction.
[0134] In the context of the present invention, a "random number" may be understood to mean, for example, a cryptographic random number (an abbreviation for "used only once" [2] or "number used once" [3]). In particular, a random number designates an individual number or letter combination that is preferably used only once in the corresponding context (e.g., transaction, data transfer).
[0135] In the context of the present invention, "the preceding data block of a (specific) data block of a distributed database system / network application" can be understood as, for example, a data block of a distributed database system / network application, which is especially directly in front of a (specific) data block. Alternatively, "the preceding data block of a (specific) data block of a distributed database system / network application" can also be understood as, in particular, all data blocks in front of a specific data block of a distributed database system / network application. Thus, a join checksum or a transaction checksum can, for example, be formed, in particular, only by a data block (or its transaction) directly in front of a specific data block or by all data blocks (or its transaction) in front of a first data block.
[0136] In the context of the present invention, a "blockchain node", "node", "node of a distributed database system / network application" or the like may be understood as a device (e.g. a field device, a mobile phone), a computer, a smartphone, a client or a subscriber, which (together with a distributed database system / network application (e.g. a blockchain)) performs operations [1][4][5]. Such a node may, for example, implement transactions of the distributed database system / network application or its data blocks, or insert or link new data blocks with new transactions into the distributed database system / network application with the aid of new data blocks. In particular, such verification and / or linking may be performed by a trusted node (e.g. a mining node) or only by a trusted node. A trusted node is, for example, a node with additional security measures (e.g. a firewall, access restrictions to the node or similar measures) in order to prevent manipulation of the node. Alternatively or additionally, when a new data block is linked to the distributed database system / network application, the trusted node may, for example, store a node checksum (e.g. a digital signature or a certificate) in the new data block. Thus, it is possible, in particular, to provide proof that the corresponding data block was inserted by a specific node or that it originated. The device (e.g. corresponding device) is, for example, a device of a technical system and / or an industrial facility and / or an automation network and / or a production device, which is in particular also a node of a distributed database system / network application. Here, the device can be, for example, a field device or a device in the Internet of Things, which is in particular also a node of a distributed database system / network application. The node can also include, for example, at least one processor, in order to, for example, implement the computer-implemented functions of the node.
[0137] In the context of the present invention, a "blockchain Orakel" or the like can be understood, for example, as a node, device or computer having a security module, which includes, for example, a software protection mechanism (e.g. a cryptographic method), a mechanical protection device (e.g. a lockable housing) or an electrical protection device (e.g. a tamper-proof protection or a protection system that erases the data of the security module in the case of unauthorized use / processing of the blockchain Orakel). The security module can include, for example, the cryptographic keys necessary for calculating a checksum (e.g. a transaction checksum or a node checksum).
[0138] In the context of the present invention, a "computer" or "device" can be understood as, for example, a computer (system), a client, a smart phone, a device or a server, which is respectively arranged outside the blockchain or is not a subscriber of a distributed database system / network application (e.g., a blockchain) (that is, it does not perform operations with the distributed database system / network application, or only inquires about it but does not perform transactions, insert data blocks or calculate proof of work verification). Alternatively, a computer can also be understood as a node of a distributed database system / network application. In other words, a device can also be understood as a node of a distributed database system / network application, or it can also be understood as a device outside the blockchain or distributed database system / network application. Devices outside the distributed database system / network application can, for example, access data (e.g., transactions or control transactions) of the distributed database system / network application and / or be manipulated by a node (e.g., by means of a smart contract and / or blockchain Orakel). If, for example, the manipulation or control of a device (e.g., a device constructed as a node or a device outside the distributed database system / network application) is implemented by a node, this can be done, for example, by means of a smart contract, which is especially stored in the transaction of the distributed database system / network application. A computer or a device may also be part of an infrastructure, for example, which implements, realizes or includes a network application or a distributed database system, for example.
[0139] Furthermore, within the context of the present invention, the following terms may be understood, for example, as follows.
[0140] A "fail-safe control" (which may also be referred to as a safety-related system) may be understood as a system (e.g. in accordance with DIN EN 61508-4:2002-11) which both implements the required safety functions in order to achieve or maintain a safe state for the EUC and is configured to achieve the safety integrity necessary for the required safety functions itself or together with other safety-related systems and other risk reduction measures.
[0141] A fail-safe control may for example be a programmable electronic system for protection or for monitoring. Such a control may for example include one or more programmable electronic devices, for example including one or more or all elements of the system, such as for example supply supplies, sensors and other input devices, data connections and other communication paths, and actuators and other output devices.
[0142] In the context of the present invention, “EUC” (English: equipment under control) can be understood as a device, machine, instrument or facility, for example, which is used for production, material processing, transportation, medical treatment or other activities.
[0143] In the context of the present invention, a "safety function" or "protection circuit" (English: safety function) can be understood, for example, as a function which is implemented, for example, by a safety-related system or other risk reduction measure and which is configured to achieve or maintain a safe state for the EUC taking into account determined dangerous accidents.
[0144] Within the context of the present invention, “protection logic” (which may be referred to as safety-related software, for example) may be understood to mean, for example, software and / or program code and / or applications, which are used to carry out safety functions and / or additionally to carry out test functions in safety-related systems and / or in fail-safe control.
[0145] In the context of the present invention, a “safe state” is to be understood as a state, for example a EUC, in which safety (for example a predefined operational safety of the technical system) is achieved.
[0146] In the context of the present invention, a "test module" may be understood as, for example, a test device or a test harness or, for example, a device capable of simulating the operating environment of software or hardware during development (to a reasonable degree) by applying test cases to the software and recording the responses. A test module may also include, for example, a test case generator and a device for reviewing the test results (either automatically against values assumed to be correct or by manual analysis).
[0147] Within the context of the present invention, a “control signal” is to be understood as a signal which is transmitted between the software and / or hardware components involved, for example, in order to carry out a test.
[0148] In the context of the present invention, a "trigger" may be understood to mean, for example, a trigger which, for example, stimulates and / or references a safety-related function and / or a test device according to settings and / or reference data. A trigger may, for example, be a person who triggers a safety-related function or software which acts, for example, by simulation in a sensor (e.g., the so-called HART function of an intelligent field device).
[0149] Within the context of the present invention, “reference data” may be understood to mean settings and / or requirements which are predetermined for the protective circuit, for example by an entity (eg a notification authority), such as for example the duration between triggering and reaching a safe state. BRIEF DESCRIPTION OF THE DRAWINGS
[0150] A preferred embodiment of the method according to the present invention is explained below with reference to the attached schematic diagram.
[0151] Figure 1 shows a schematic diagram of a peer-to-peer network,
[0152] Figure 2 Shown in Figure 1 A schematic illustration of a blockchain used in a peer-to-peer network as shown in,
[0153] Figure 3 shows a schematic diagram of memory expansion for improving performance,
[0154] Figure 4 A schematic diagram of the method flow is shown,
[0155] Figure 5 A schematic illustration of a further method sequence for use in a system in a processing or production facility within the scope of facility planning is shown.
[0156] Figure 6 shows a schematic representation of a method sequence for a functional test,
[0157] Figure 7 shows a schematic representation of a further method sequence for a functional test,
[0158] Figure 8 shows a schematic representation of a further method sequence for a functional test,
[0159] Fig. 9 and Fig.10 Further embodiments of the invention are shown. DETAILED DESCRIPTION
[0160] First reference Figure 1 .
[0161] A distributed peer-to-peer network 1 is shown, which is designed to implement a computer-implemented method for providing data, in the present embodiment for consistency tracking of a system or an installation.
[0162] In this embodiment, the peer-to-peer network 1 includes four nodes 2a, 2b, 2c, and 2d.
[0163] In this case, a peer-to-peer network 1 is understood to be a computer network in which, in contrast to a computer network with a client-server architecture, all nodes 2 a , 2 b , 2 c , 2 d have equal rights.
[0164] A computer or a cloud computer can be connected to each node 2a, 2b, 2c, 2d. The computing power of the overall system thus generated forms the hardware basis.
[0165] For consistent tracking of a system or facility, only a limited and specifically authorized group of users needs access to the data. Therefore, in this embodiment, as explained in detail later, a private blockchain is formed.
[0166] exist Figure 1 In the scenario shown in , the first node 2a is assigned to the supplier, the second node 2b is assigned to the manufacturer or facility builder, the third node 2c is assigned to the inspector or notified body, and the fourth node 2d is assigned to the operator.
[0167] In addition to the hardware components, each node 2a, 2b, 2c, 2d also contains a software component in the form of a computer program product, which is the blockchain software (stack), the tasks and functions of which are explained in detail below.
[0168] Furthermore, for example, a user interface can be provided for consistency tracking or incorporated into existing planning, engineering or execution software. In the latter case, the user interface of the existing software (e.g. COMOS - the unified database platform for facility builders) is adapted so that the required information for consistency can be published together with the corresponding metadata in the distributed ledger or can be read back if necessary in order to enable further work steps.
[0169] A distributed ledger is understood to be a special form of electronic data processing and storage. A decentralized database that allows shared read and write authorization for network subscribers is called a "distributed ledger". In contrast to centrally managed databases, in this network no central instance is required to make new entries in the database. New data records can be added at any time by the subscribers themselves. The subsequent update process ensures that all subscribers have the latest status of the database. A special form of distributed ledger is the blockchain3.
[0170] Now additionally refer to Figure 2 .
[0171] A blockchain 3 is shown. A blockchain 3 is understood here to be a continuously extensible list of data records that are linked to one another by cryptographic methods. Each block typically contains a cryptographically secure checksum of the previous block and, if necessary, a timestamp and further transaction data.
[0172] In the present embodiment, the blockchain 3 has a first data block 4a with a first data record and a second data block 4b with a second data record, as well as a third data block 4c with a third data record. In the process of consistency tracking, the first data block 4a is first generated in a first step, and the blockchain 3 starts with the first data block 4a. In a further step, the second data block 4b with the second data record and the third data block 4c with the third data record are added, and the blockchain 3 is thereby expanded.
[0173] Each of the data blocks 4a, 4b, 4c is assigned a respective checksum 6a, 6b, 6c, such as, for example, a hash value. To determine the checksum 6a, 6b, 6c, for example, a hash function such as, for example, the SHA-256 algorithm (Secure Hash Algorithm) may be used.
[0174] The data records of the corresponding data blocks 4a, 4b, 4c respectively have block numbers 7a, 7b, 7c representing the corresponding positions in the blockchain 3, one or more digital signatures 8a, 8b, 8c representing the corresponding users, data 9a, 9b, 9c about consistency tracking, such as, for example, verification certificates, and the corresponding checksums 6a, 6b, 6c of the previous data blocks 4a, 4b.
[0175] Thus, the first data block 4a (because it is the first data block 4a) has no checksum of the preceding block, whereas the second data block 4b has the first checksum 6a of the first data block 4a and the third data block 4b has the second checksum 6b of the second data block 4b.
[0176] The first data block 4a is assigned to a first instance 5a, in the present embodiment a supplier 11, while the second data block 4b is assigned to a second instance 5b, for example a manufacturer / facility builder 12, and the third data block 4c is assigned to a third instance 5c, for example a notification authority 14. Other assignments are possible in contrast.
[0177] The first instance 5a, ie the instance starting the blockchain 3 with the first data block 4a, is configured in the present embodiment to issue the authority verification certificate 10. In other words, the first instance 5a can be regarded as a source or base instance.
[0178] The authority verification proof 10 is transmitted to the other instances 5b, 5c. The authority verification proof 10 enables the other instances 5b, 5c to add further data blocks 4b, 4c to the blockchain 3.
[0179] The authority verification certificate 10 may have a time-limited validity and / or a content-limited validity and / or a user-related validity.
[0180] In this context, a time-limited validity is understood to mean that the authority verification certificate 10 has an expiration date and after which it is no longer possible for one of the further instances 5b, 5c to add a further data block 4b, 4c to the blockchain 3. Thus, for example, a situation can arise in which a verification certificate must be provided within a predetermined period of time. Furthermore, misuse is thus counteracted since the authority verification certificate 10 does not have an unlimited service life.
[0181] Validity in terms of content is understood to mean that the authorization verification certificate 10 only authorizes the predetermined input, such as, for example, confirming that a check has been carried out. In other words, the authorization verification certificate 10 is object-related. This can also resist misuse.
[0182] User-related validity is understood to mean that the authorization verification certificate 10 only authorizes the corresponding predetermined instance 5a, 5b, 5c to make a predetermined input, such as, for example, confirming that a check has been carried out. In other words, the authorization verification certificate 10 is personalized or user-related.
[0183] It can also be provided that one of the data blocks 4a, 4b, 4c is designed as a smart contract. Here, a smart contract is understood to be a software-based contract in which different contract conditions can be stored. During the contract process, certain associated actions (such as payment) can be independently implemented when corresponding trigger conditions (such as fulfillment of contract conditions) exist.
[0184] Therefore, one of the data blocks 4a, 4b, 4c can be constructed to provide the authorization verification certificate 10 based on a predetermined condition. Therefore, instead of only the first instance 5a generating the authorization verification certificate 10, the corresponding authorization verification certificate 10 is generated and provided only when the predetermined conditions of the previous step, such as, for example, the proof of a temporary test or preliminary inspection, have been verified. Therefore, the generation of the authorization verification certificates 10 in a "reserve for backup" manner at the beginning and their safe archiving to prevent unauthorized access is eliminated, which improves security.
[0185] Furthermore, one of the data blocks 4a, 4b, 4c can be configured to provide error handling measures based on the presence of a predetermined error situation. Thus, for example, the blockchain 3 can be used to provide error handling measures. If an error occurs in a component of the installation (such as, for example, a field device), an error signal corresponding thereto triggers a data block 4a, 4b, 4c configured as a smart contract, so that corresponding measures for error handling, such as deactivation and replacement notification of the defective field device, are then implemented.
[0186] Furthermore, a repair function is provided for changing one or more data blocks 4a, 4b, 4c.
[0187] Due to the limited number of known participant actions, a self-owned smart contract with a repair function can be implemented in the technical implementation to "repair" the error, which names or identifies the error or the erroneous data with the explicit consent of all participants. This can be used advantageously in the first phase of the implementation. In the case of data reduction or migration due to technical reasons, the data can be transferred to the newly launched blockchain 3.
[0188] Now additionally refer to Figure 3 .
[0189] A large amount of data processing for performance improvement is shown. For this purpose, a replication system 24 can be used, such as, for example, IPFS, where, for example, a pointer to a corresponding memory area of the replication system 24 is archived in encrypted form in the blockchain 3. This can be regarded as an operating system or a distributed, highly available execution environment.
[0190] Now additionally refer to Figure 4 To explain an embodiment of the method flow.
[0191] The method process is divided into three phases, the first phase I is compliance design and planning, the second phase II is compliance construction, and the third phase III is compliance operation, maintenance and care.
[0192] In the first phase I, in the present exemplary embodiment, the supplier 11 , the facility builder 12 , the quality manager 13 and the notified body 14 are involved.
[0193] In the second phase II, in the present exemplary embodiment, a plant construction company 15 and a further notification authority 16 are involved.
[0194] In the third phase III, in the present exemplary embodiment, the operator 17 , further notification bodies 18 and the supervisory authority 19 are involved.
[0195] After the distributed peer-to-peer network 1 has been set up, in the first phase I of the present embodiment, the supplier 11 as the first instance 4a creates, for example, a first data block 4a of the blockchain 3 with a first checksum 6a. In addition, the supplier 11 as the first instance 4a creates an authority verification certificate 10.
[0196] In contrast to the present embodiment, the blockchain can also be initiated by the operator 17 or a supervisory authority 19 of the operator 17, such as, for example, the TÜV, since the operator 17 must be the first in time to ensure the consistency of the facility. Thus, at the beginning the operator 17, then the supervisory authority 19 such as the TÜV or another authority, then the facility builder 12, then its suppliers 11 and then various further participants are authorized to feed data into the blockchain 3. The operator 17 or the supervisory authority 19 can manage who is authorized to publish and / or read data when. The order in which the data is provided depends on the respective official regulations, the necessary technical systems and many other facility-specific boundary conditions.
[0197] In a further step, the installation builder 12 generates, as a second instance 5b, a further data block 4b, for example with a further checksum 6b, and in a further step, the quality manager 13 generates a further data block 4c with a further checksum 6c.
[0198] Here, the checksums 6a, 6b of the preceding data blocks 6a, 6b are inserted into the respective subsequent data blocks. Thus, the checksum 6a of the first data block 4a is inserted into the further data block 4b and the further checksum 6b is inserted into the further data block 4c.
[0199] The further data blocks 4 b , 4 c are only added to the blockchain 3 after the facility builder 12 and the quality manager 13 as the second instance 5 b have authenticated 10 with the corresponding rights.
[0200] Thereafter, the blockchain 3 is available to all mentioned participants and furthermore copies of the blockchain 3 are distributed to all nodes 2a, 2b, 2c, 2d.
[0201] In a further step, after checking the documents filed in the blockchain 3, the notification authority 14 creates a certificate 20 and, after the notification authority has been authorized with the corresponding authority verification 10, adds the certificate 20, for example, as a document, such as, for example, as a pdf document, to the blockchain 3. The certificate 20 is thus now also available to all the mentioned participants. In addition, a copy of the blockchain 3 is distributed to all nodes 2a, 2b, 2c, 2d.
[0202] In a second phase II, the circle of participants is expanded, to be more precise by a group of installation builders 15 and further notification agencies 16 , which are provided with corresponding authorization verification certificates 10 for this purpose.
[0203] The installation builder combination 15 generates a further data block with a further checksum and adds the further data block to the blockchain 3 after the installation builder combination has authorized it with its corresponding authority verification certificate 10. Subsequently, after the notification subject 16 has authorized it with its authority verification certificate 10, the notification authority 16 adds the certificate 21 to the blockchain 3 after checking the documents filed in the blockchain 3. Alternatively, this can also be carried out by the installation builder, for example instead of the notification authority.
[0204] In the third phase III, the circle of participants is expanded again, namely to include operators 17 , further notification bodies 18 and supervisory authorities 19 , which are provided with corresponding authorization certificates 10 for this purpose.
[0205] If necessary, the operator 17 generates further data blocks (not shown), for example documentation for correct maintenance and inspection.
[0206] Subsequently, after the further notification bodies 18 and the supervisory authority 19 have verified with their competence that the certificate 10 is authorized, they add the further certificates 22 , 23 to the blockchain 3 after a corresponding check of the documents filed in the blockchain 3 .
[0207] Blockchain 3 thus provides a distributed, replicated and therefore highly available data storage and operating environment that is virtually immutable, in which consistency tracking can now be performed automatically.
[0208] Now additionally refer to Figure 5 , in order to explain a further embodiment relating to an application in the case of a system in a process or production facility within the scope of facility planning.
[0209] In the case of a processing facility, the blockchain 3 and the data that can be stored therewith are an integral part of the processing facility, comparable to the conventional inspection documents to be maintained with the facility. The blockchain 3 is maintained, for example, by the responsible owner / proprietor or operator 17 or as a functional step further than the current first instance 5a. In other words, the participants can change their roles, i.e. the role or function of the first instance 5a is transferred from the supplier 11 to the operator 17.
[0210] To this end, the operator 17 initiates the formation or maintenance of the blockchain 3 and manages the required smart contracts 29a, 29b, 29c. The required participants, such as the facility builder 12, its suppliers 11, the notification body 14, the supervisory authority 19, etc., are authorized to contribute information according to their roles. Authentication is provided by the blockchain 3 and can also be extended, if necessary, for example by two-factor authentication or public multi-party keys.
[0211] The selection and execution of the necessary / desired smart contracts 29a, 29b, 29c can be initiated and controlled by a responsible party, for example the operator 17. If necessary, the responsible party can turn to competent partners, such as, for example, the notification authority 14, which verifies and approves these smart contracts.
[0212] At the beginning of the process, operators 17 and planners, such as facility builders 12, for example, specify the relevant requirements for the blockchain 3 of the plant / facility, such as requirements regarding functional safety, pressurized components, explosion protection, emissions, CE marking and further requirements together with supervisory authorities 19 and notified bodies 14. Subsequent expansion by adding further smart contracts is contemplated.
[0213] Implement these processes independently and autonomously.
[0214] A manufacturer 25 of products, such as fail-safe controls, publicly offers standardized smart contracts 29a, 29b, 29c for its product types 26a, 26b, 26c together with corresponding product documentation 30a, 30b, 30c, for example in an online catalog 31, which contains suitability documents such as, for example, inspector certificates.
[0215] The authentication of the product types 26 a , 26 b , 26 c can also be achieved here already by the notification authority 14 via the blockchain 3 .
[0216] Smart contracts 29a, 29b, 29c enable automated verification of repeatable checks of planning, implementation and support within the scope of consistency tracking.
[0217] The manufacturer of the planning tool loads these smart contracts 29 a , 29 b , 29 c as library components into its planning system 28 , such as, for example, COMOS or Teamcenter, via a suitable interface.
[0218] Firstly, safety-relevant properties, such as a previous certificate 20 , are thus made available and the correct integration of the product in the planning system 28 or tool is ensured.
[0219] The product-specific authenticated smart contracts 29a, 29b, 29c are encrypted, but the source code is visible and can be verified by checksums (not shown), such as, for example, hashes, even in the planning system 28 (or later during consistency tracking in the blockchain 3). This ensures transparency and auditability.
[0220] The integration of the products takes place within the planning of the installation by the installation constructor 12 adhering to the predefined properties of the products. The planning system 28 ensures correct use.
[0221] When a product is instantiated for a particular facility, an assignment of a unique facility-related reference designation is performed in the planning system 28 .
[0222] For approval of the solution configured in the planning system 28, the configuration 28 of the product is now released from the planning system 28 in the consistency track. The configuration 32 previously checked by the planning system 28 can also be checked and approved by the notification authority 14 and provided with a certificate 33 if necessary.
[0223] The associated smart contracts 29a, 29b, 29c have now reached the "Approved Planning" milestone and are therefore ready for confirmation of compliant implementation.
[0224] The actual products / devices are classified so that they can now make the required implementation codes available through a readable key or through a suitable identification at the component. This can be, for example, a combination of the suitability for the required safety requirement level (SIL level), instance number / serial number, manufacturer and product type, which have been transmitted to the product together during manufacturing. These codes are read out from the implemented facilities and transmitted to the blockchain 3 for recording. Smart contracts 29a, 29b, 29c check this and confirm the consistency autonomously. If necessary, a final check is carried out by the notification agency 14.
[0225] Thus, self-certifying and automated configuration management is provided that ensures correct usage of the product.
[0226] Now additionally refer to Figures 6 to 8 To explain the method used for functional testing.
[0227] Now first refer to Figure 6 .
[0228] The protection logic 34 of the fail-safe control 41 and the blockchain 3 embedded in the operating environment 35 and the smart contract 36 are shown.
[0229] In operation, the test trigger signal 37 triggers the smart contract 36, which then generates a test signal 38, which is connected to the protection logic 34. As a result, a trigger signal 39 is available.
[0230] Furthermore, a feedback signal 40 is generated for updating the blockchain 3 .
[0231] In response to the feedback signal 40 , the test result is archived in the blockchain 3 .
[0232] Now additionally refer to Figure 7 .
[0233] Figure 7 The scene shown in Figure 6The scenario shown in FIG. 1 differs in that the test trigger signal 37 must be provided manually within a time window predetermined by the smart contract 36 and acts on a sensor 43, such as, for example, an emergency shut-off button of the safety circuit 27. The safety circuit 27 is thus monitored, which in the present embodiment additionally has an actuator 44, such as, for example, a servo drive of a steam valve, and a sensor 45, such as, for example, a sensor for sensing an end position.
[0234] Additionally, a reset signal 42 is generated by the smart contract 36 for resetting the protection logic 34. With the reset signal 42, the protection logic 34 is brought back to the state it had before the functional test.
[0235] Furthermore, a feedback signal 40 is generated for updating the blockchain 3 .
[0236] Now additionally refer to Figure 8 .
[0237] More expensively implemented plants partly provide prefabricated test devices, such as, for example, the test logic 46 , so that the test can also be repeated during the operating period of the plant (mostly when stopped).
[0238] Figure 8 The scene shown in Figure 7 The scenario shown in FIG. 1 differs in that the smart contract 36 itself provides the test signal 38 and connects it to the verification logic 46 of the protection logic 34 .
[0239] Thus, within the scope of the functional test, the correct interaction of the individual components such as, for example, sensors 43, 45, transmission, detection, protection logic 34, trigger signal 39, transmission and actuator 44 can be ensured. This takes place for the first time before acceptance.
[0240] By means of the trigger signal 39, which can be recorded in the blockchain 3, the functional test and the storage of the signal and the devices involved, a successful and compliant functional test can also be carried out automatically and recorded or confirmed in the blockchain 3. For this purpose, a suitable logic is required in the control system (master control system), which is suitable for this purpose (usually certified and approved by the TÜV).
[0241] Furthermore, components for fail-safe control are required that can transmit events to the blockchain 3. These are protection triggering events (inputs) and, if necessary, states in the process and output settings.
[0242] These states are transmitted directly to the blockchain 3 together with the required metadata (automated device, time stamp, etc.), so that an evaluation and documentation of the results is possible. The transmission can take place, for example, in encrypted form.
[0243] In conjunction with an active fail-safe program code, which can be clearly identified in the blockchain 3 by means of checksums 6a, 6b, 6c, an uninterrupted recording of the process is entirely possible.
[0244] The checksums 6a, 6b, 6c are preferably separate checksums and / or individual checksums which have already been formed for the corresponding program code, for example.
[0245] Alternatively or additionally, in conjunction with the documentation of the fail-safe program code active at the time of the test, which is protected from being altered, for example, in a protection system by its own checksum, an uninterrupted documentation of the process can be achieved completely by storing this checksum in the blockchain.
[0246] In order to (also physically) detect the complete protection logic 34, such as the closing of a valve, in some cases additional measurements must be included in the functional test. This may be a stop in the flow, a drop in pressure or feedback on the end position of a fitting.
[0247] Since the fail-safe components with so-called channel drivers form the transition to the corresponding input and output cards, the physical implementation of the entire fail-safe system - including input and output cards, cabling, bus systems, field devices - cannot be automatically read out and recorded without new functions in the control system. In the case of intelligent field devices (HART, Profibus), it is at least possible to include these areas. For this purpose, the control system can, for example, be able to read out the encrypted identification of the device and record these encrypted identifications together with the test values of the fail-safe control in the blockchain 3.
[0248] If still required, the notified body 14 can now support the evaluation of the data available in the blockchain 3 and issue a formal approval.
[0249] Responsibility and higher-level management of the cooperation (management of smart contracts 29a, 29b, 29c, authorization and role allocation) and initiation of the necessary measures remain essentially the responsibility of the operator 17.
[0250] The implementation of the repeated function test can be implemented in the main control system of the power plant by a proven fail-safe system. Here, the main control system is programmed so that the repeated test is started independently after an adjustable time or manually triggered by a switching action of an authorized operator.
[0251] A successful test result (here, for example, the triggering of a test stop operation by the emergency stop button) is recorded in a forgery-proof manner by means of a smart contract 29 a , 29 b , 29 c in the blockchain 3 .
[0252] If the functional check fails or is not triggered within the required check interval, the blockchain 3 can automatically interrupt the facility operation (automatic stop) or trigger a corresponding official notification after expiration of the corresponding defined time (see also IEC 61508-1 Chapter 6.2.5).
[0253] Another function that can be automated is the comparison of the planning of the approved implementation with the actual implementation in the area of the machine components (eg pressurized components).
[0254] By using corresponding data formats, such as 3D data of the implementation plan, an automatic comparison of the desired and actual state (actual implementation recorded or 3D zoomed) can trigger an automated start-up approval. For this purpose, a certified camera (certified = camera product or software tested and approved for this purpose by TÜV) can be used based on blockchain technology, which provides a forgery-proof photo in the blockchain 3.
[0255] exist Fig. 9 and Fig.10 Further embodiments are shown in .
[0256] In particular, a computer-implemented method and / or system for checking a technical system is shown, wherein the method or system is particularly suitable for consistency tracking of technical installations. Here, for example, a subsystem, such as an actuator (e.g., a pneumatic servo drive 44 of a steam quick-closing valve of a technical system) or a plurality of devices are tested in order to determine whether they meet predefined requirements. Devices and / or subsystems can be, for example, a protection circuit of a technical system and / or a part of a protection circuit to be tested of a technical system and / or a protection logic 34.
[0257] The system comprises a test module (e.g., a test device) of a fail-safe control 41 and an operating environment 35 in the form of a network application (e.g., a blockchain) and a test control transaction 36, which is at least partially implemented as a smart contract, for example. The test module can be implemented, for example, by a protection logic 34, or as a component of a network application or as a smart contract. Alternatively, the protection logic 34 can include the test module or correspond to the test module. Alternatively, the test module includes the protection logic 34.
[0258] In operation, a test trigger signal 37 triggers a test control transaction 36. This can occur, for example, from a first entity AT1 via a data interface I. The entity AT1 can be, for example, a blockchain Orakel, which provides the corresponding trigger or transmits it to a network application. Alternatively, the entity AT1 can also be a person, a test user or software for automated testing of a technical system.
[0259] The trigger may have been triggered, for example, by a sensor value exceeding a predefined threshold value, or may have been triggered based on a time control. For example, there may be a plurality of types of triggers, which carry out different tests or checks on the equipment of the installation. Correspondingly, the triggers are coded for which equipment is to carry out which test. For example, the type and / or scope of the permissible tests are predefined by a corresponding (authorized) entity (e.g. a notification authority), which can here, for example, predefine the required triggers and / or corresponding reference data.
[0260] The test control transaction 36 comprises control commands and / or reference data in order to check a corresponding device of a technical system (eg an installation, a processing facility, an automation system).
[0261] For example, a plurality of tests or checks of a device can be encoded / included in a test control transaction 36 or in another test control transaction. For this purpose, the corresponding test control transaction includes corresponding device-specific and / or test-specific control commands and / or reference data, wherein the corresponding device-specific and / or test-specific control commands and / or reference data are selected by means of a trigger. In other words, the corresponding test control transaction can encode device-specific and / or test-specific tests and / or checks for a device of the technical system, wherein the selection of the corresponding test and / or check is carried out by means of the data included or encoded by the trigger.
[0262] The test control transaction 36 that is important for the test or verification is loaded by the trigger. The test control transaction 36 can be loaded into the test module, for example, or the network application or the test control transaction 36 or the smart contract generates the control signal. The network application and / or the test control transaction 36, the smart contract or the protection logic 34 and / or Fig. 9 The further components of the system shown in may completely or partially comprise the test module, depending on which component, for example which function, of the test module is implemented.
[0263] Depending on which of the components generates the signal and to which component the signal is transmitted, the control signal can be implemented differently. If, for example, a network application or a test control transaction 36 or a smart contract generates the control signal, the control signal can be implemented as a test signal 38. If the protection logic 34 generates the control signal, the control signal can be implemented as a trigger signal 39.
[0264] If, for example, a test signal 38 is generated, this is connected to the protection logic 34. As a result, for example, a trigger signal 39 is then available.
[0265] In this case, the control signal generated during the test or during the check is preferably specific to the test or check of the function of the devices participating in the protection circuit and / or the device itself integrated in the protection circuit.
[0266] The protection circuit comprises sensors 43 and / or 45, wherein the sensors 43 and / or 45 deliver measurement data 40a and 40b. The sensor 43 delivers, for example, measurement data from the process to be monitored, which can also be simulated for a corresponding test, for example. The sensor 45 delivers, for example, measurement data, which can be detected as a reaction to a control signal (for example a test signal) and / or the occurrence of a protection effect.
[0267] In this case, these measurement data 40a, 40b are detected by a test module, wherein sensors 43, 45 are communicatively connected to the test module, for example via a bus or an input and output module IF, or sensors 43, 45 transmit the measurement data 40a, 40b directly to the test module, for example. For such data communication or other communication between components of a system, technical system, network application, the system shown comprises a plurality of data interfaces IF in order to enable corresponding data exchange.
[0268] For example, with the trigger signal 39, the pneumatic servo driver 44 is activated, and the steam fast closing valve is closed.
[0269] Alternatively or additionally, the trigger signal 39 or the control signal actuates an entity, with the aid of which the pneumatic actuating drive 44 or a corresponding test can be carried out.
[0270] In another variant, the test is semi-automatically performed in that the entity is a computer which indicates to the test user that the protective effect of the "overspeed" protection circuit should be tested. To this end, the test user handles and detects the servo drive of the quick-closing valve by means of a sensor 45 (e.g., a position indicator).
[0271] Subsequently, the inspection result is determined based on the measurement data and the corresponding reference data. This determination can be performed, for example, by a test module or a test control transaction 36. In this inspection, it is determined, for example, whether the measurement data complies with, is lower than or is higher than the reference data. If the measurement data is consistent with the reference data, the corresponding test or inspection is considered to have passed. If the measurement data deviates from the reference data, for example, by an allowed tolerance value, the corresponding test or inspection can be evaluated as passed and stored in the inspection result. If the measurement data deviates from the reference data and / or exceeds the corresponding tolerance value, for example, the corresponding test or corresponding inspection is considered to have not passed and is preferably stored in the inspection result.
[0272] Depending on the test results, the technical system and / or the control device is controlled and / or the control function is implemented. If the device, for example, meets the settings predetermined by the reference data, the technical system and / or the device is placed in an operating state. In other words, if the test passes, the technical system and / or the device is, for example, put into operation, or the operating mode of the device or the technical system is released for use by means of the control function, or the operating authorization is extended for a further interval.
[0273] In a variant of the invention, a plurality of checks or tests can also be performed on the equipment of the technical system and / or other equipment and stored in the test results. The technical system and / or the control equipment and / or the control function are controlled and / or the control function is performed only when, for example, a predetermined number of checks or tests (for example, 100% of all checks or tests or 80% of all tests) and / or a predetermined specific test or test (for example, a safety-critical test must pass 100%) are met. For example, only in this way is the technical system and / or the equipment placed in an operating mode (for example, normal operation) that allows its use. This can, for example, be the release of the control function that allows the power plant to be started in the case of a power plant facility, so that the power plant can also be operated at full load or enter normal grid operation.
[0274] The measurement data 40a, 40b of the sensors 43, 45 can be, for example, corresponding feedback signals. The measurement data 40a, 40b can encode or include corresponding feedback signals or be constructed or realized as corresponding feedback signals.
[0275] In a variant, the measurement data 40a, 40b are detected and used to update the network application (e.g., blockchain 35) in that, for example, the corresponding measurement data 40a, 40b are stored in a feedback signal 40 and transmitted from the protection logic 34 or the test module to the test control transaction 36 or the network application. To this end, the measurement data 40a, 40b can be transmitted to the protection logic 34 or the test module, for example. The protection logic 34 or the test module stores the measurement data 40a and / or the measurement data 40b and / or the verification result in the feedback signal 40 and transmits the feedback signal to, for example, the test control transaction 36 or the network application.
[0276] Information accompanying the test (eg identification of the operating environment 41 of the protection logic and diagnostic data) may also be contained in the feedback signal 40 or in the communication between the protection logic 34 and the test control transaction 36 and / or the network application, for example for documentation and archiving purposes.
[0277] In a further variant, as a reaction to the measurement data 40 a , 40 b , the test results (which can also be referred to as verification results) are archived in a network application (eg blockchain 3 ).
[0278] In other variants, the verification result is stored in the confirmation transaction, for example. Additionally or alternatively, the measurement data is stored in the measurement data transaction, for example. Additionally or alternatively, the verification result is calculated based on the measurement data of the measurement data transaction, for example. Additionally or alternatively, the confirmation transaction and / or the measurement data transaction and / or the test control transaction are protected, for example, by means of corresponding authority verification certificates. Additionally or alternatively, the confirmation transaction and / or the measurement data transaction and / or the test control transaction are stored in corresponding data blocks, for example. Additionally or alternatively, the corresponding data blocks include, for example, corresponding authority verification certificates for the corresponding transactions.
[0279] The verification result can be stored, for example, by means of a corresponding confirmation transaction and can be transmitted, for example, as a message P or as a confirmation transaction to a corresponding entity (for example, an institution to be notified or a trusted entity) (for example, in a Fig.10 of step S13 or the data of step S13).
[0280] In a further variant, the system comprises a monitoring module, wherein the monitoring module is configured to store activities of the system and / or the test module in a log file or data record or in a transaction.
[0281] For example, the invention can be used as follows: Since a time limit for a renewed inspection of a technical system (eg a power plant facility) according to regulations by the TÜV has expired, it is necessary to prove that a renewed functional test was successful.
[0282] There is a smart contract (e.g., test control transaction 36) assigned to the protection circuit, which can handle the requirements regarding the trigger signal and the protection effect as well as the time settings and, if necessary, factors (e.g., interference-free protection system) according to the settings of the certification body (TÜV). For this purpose, the test control transaction 36 includes the control commands and reference data required for this purpose. In addition, the test control transaction 36 can include a test module or an actuation test module.
[0283] In the initial state, the test control transaction 36 has not set the trigger of the protection logic (S1). The feedback of the protection logic to the smart contract is: protection not responding (S1a). Therefore, the facility is not blocked and is ready for functional testing.
[0284] Inspection process:
[0285] An authorized tester AT1 , for example an employee of a certification body, or a test software activates the test mode via a data interface I (for example a network interface) (test trigger signal 37 ).
[0286] The smart contract (also referred to as program code, program command or chain code) active for the overspeed protection of the test control transaction 36 activates a timer (e.g., a 30-minute test window) and waits for feedback that the protection has responded (the "speed>X" measurement data 40a of the sensor 43) and the occurrence of a protection effect (the "quick-closing valve feedback closed" measurement data 40b of the sensor 45). For this purpose, for example, a smart contract or a test control transaction 36 with a smart contract can be implemented and the test module can be controlled as described above.
[0287] In addition, the smart contract and / or the test control transaction 36 and / or the test module checks, based on the time stamps of the measurement data 40 a , 40 b , whether the reaction was effected within the reference data, ie within a predefined reference time (eg 10 seconds).
[0288] For example, another entity AT2 (eg a person, a controlled device or a software component) can trigger the protection ( S2 ) by actually generating a critical process state during a plant shutdown or by a simulation at the sensor 43 .
[0289] The trigger signal (S3) recorded in the protection logic 34 is transmitted to the smart contract and / or the test control transaction 36 and / or the test module (S4). The protection logic 34 responds and triggers the protection command (S5 command "close" signal 39). Therefore, in order to reduce the speed of the turbine, the valve should be closed / closed in such a way that the protection command is transmitted to the actuator 44 (for example, to the servo drive of the steam quick closing valve) (S5). In addition, the protection logic transmits the trigger (S6) that occurs to the test control transaction 34. The steam quick closing valve is closed (zufahren), and the position indicator 45 feeds back "closed" (S7 = measurement data 40b) to the control logic and / or the test control transaction 36 and / or the test module (S8). Therefore, the feedback on whether the safety state has been requested and achieved is detected by the sensors 43, 45 and the corresponding measurement data 40a, 40b. This can also be transmitted to the smart contract and / or the test control transaction 36 and / or the test module, for example, depending on the selected implementation. The smart contract and / or the test control transaction 36 and / or the test module then calculates the verification result with the inclusion of the reference data.
[0290] The following results may be produced during the checking or calculation, which are preferably stored in the test results and / or the technical system is controlled and / or a control function is carried out as a function of the test results:
[0291] success:
[0292] Documentation (with time stamp) of a successful check (S13) occurs if the trigger (measurement data 40a) and the protective effect (measurement data 40b) change from 0 to 1 in the correct sequence within a predetermined reference time (e.g. 20 seconds) - in other words, the measurement data 40a, 40b prove compliance with the settings (reference data). This evaluation is preferably performed by a test module.
[0293] The functional approval of the protection circuit is retained by the smart contract and / or the test control transaction 36 and / or the test module until the next repeated test. For this purpose, the approval is set in the protection logic (S9). This is preferably controlled by implementing a control function according to the test result.
[0294] Inspection not completed:
[0295] If the time of the test window (e.g. 30 minutes) has elapsed and no trigger signal (38 or 40a) has been recorded in the smart contract and / or in the test control transaction 36 and / or in the test module (S4), the documentation of the past test occurs (e.g. by generating or storing a corresponding transaction in the network application) (S13). The test can, for example, be repeated (37). If the successful test (S10) is not notified in time by the smart contract and / or the test control transaction 36 and / or the test module, for example (e.g. after a predetermined time period for storing a successful test has been exceeded), the other entity AT3 (e.g. a certification body) receives a corresponding message and becomes active (S13). If the repeated test is successful, the other entity is notified of the success of the repeated test (S13). This can be performed and / or recorded, for example, with the help of a corresponding transaction of the network application. The other entity AT3 can, for example, be a person of a software or certification body, which, if necessary, controls the technical system and / or implements or approves control functions for the technical system based on the test results.
[0296] Test failed:
[0297] If the test is not completed correctly, one measure can be that the protection command remains continuously triggered by the smart contract so that the quick closing valve can no longer be moved to open (AUF). This can be achieved, for example, by implementing a control function based on the test results (S10), which strengthens the protection effect (quick closing valve command "close"). Therefore, the facility is blocked by the protection logic 34, for example. This state is transmitted, for example, to the test control transaction 36 and / or the test module (S12) and recorded or monitored there.
[0298] For example, in order to cancel the protection command ( S11 ), the installation can now be authorized again by a reset mechanism in the smart contract and / or in the protection logic and / or in the test control transaction 36 and / or in the test module.
[0299] Because unsuccessfully tested messages are stored in the blockchain and transmitted to the responsible party (e.g., entity AT3), error searching and error correction can be performed under supervision.
[0300] The smart contract and / or the test control transaction 36 and / or the test module can be represented, for example, so that a reset in the smart contract and / or in the test control transaction 36 and / or in the test module is only possible by the assigned department or by the certification authority (for example, another entity AT3) (key management and authorization in the blockchain). This can occur and / or be recorded, for example, by means of a corresponding transaction of the network application.
[0301] In a further variant, the sensor 43 and / or the sensor 45 comprises a processor or a microcontroller in order to generate simulated sensor data 40a, 40b and to test the technical system, the device or the reaction of the technical system or device to the simulated sensor data 40a, 40b. A sensor with a processor or a microcontroller may also be referred to as an intelligent sensor, for example. In other words, this variant relates to a computer-implemented method, for example, in which the test signal 38 or the control signal is provided by a smart contract and / or a test control transaction 36 and / or a test module, wherein preferably the test control transaction 36 and / or the test module comprises a smart contract.
[0302] The test signal or control signal is generated, for example, by the smart contract itself. Therefore, no further intervention is required, for example to manually trigger the test signal. Rather, the test signal is generated automatically.
[0303] For example, the sensor 43 can be replaced by an intelligently constructed sensor 43, such as, for example, an intelligent pressure measuring device with analog functions. Thus, for example, the safety circuit 27 can be monitored, which in the present embodiment additionally comprises an actuator, such as, for example, a steam fast closing valve, and has a sensor 45, such as, for example, a sensor for detecting the end position.
[0304] In another embodiment, the test is automatically triggered by the smart contract:
[0305] In a suitable state of the technical system (e.g. stopped), which is signaled from the protection logic to the smart contract, a test trigger signal 37 automatically triggers the smart contract 36. With the help of the smart contract or the test control transaction, the protection logic and / or the test module are controlled in such a way that a test signal 38 is generated. As a result, protection is then triggered by the protection logic 34, if necessary. A successful protection effect is recorded in the protection logic and / or the test module, and the corresponding measurement data are then stored, for example, in a network application (e.g. a blockchain).
[0306] The function test of the overspeed protection with automatic triggering by means of an intelligent sensor can be carried out as follows:
[0307] Initial state:
[0308] Since the time for re-testing according to regulations by the TÜV has expired, a successful renewed functional test must be demonstrated.
[0309] There is a smart contract assigned to the protective circuit or device, which can handle the requirements regarding the trigger signal and the protective effect as well as the time settings and, if necessary, factors (e.g., non-interfering protective systems and stopped technical systems) according to the settings of the certification body (TÜV). This is preferably encoded in the reference data and control commands of the test control transaction. Correspondingly, the test control transaction can include the smart contract or correspond to it.
[0310] In the initial state, the smart contract has not set the protection logic or the triggering of the device. The feedback from the protection logic to the smart contract is: protection not responded. Therefore, the facility is not blocked and is ready for functional testing.
[0311] Inspection process expires:
[0312] An authorized tester, for example an employee of a certification body (for example entity AT1 ), activates the test mode via a data interface I (for example a communication interface) with a corresponding signal 37 .
[0313] The smart contract triggers, for example, a simulation 38 in a sensor 45 (e.g., designed as a smart sensor) for triggering protection via the protection logic, and simultaneously sets a timer (e.g., a test window of 10 minutes), which monitors the test process and cancels the simulation after the expiration of a defined time or after the end of the test. The sensor 45 now delivers measurement data simulating an impermissible process state to the protection logic and / or the test module. The protection logic reacts to these simulated measurement data, and the reaction of the protection system to these simulated measurement data is monitored as described above.
[0314] The smart contract therefore now monitors, based on the feedback, whether the protection has responded (“speed>X” signal 40 a ) and whether the protection effect has occurred (“quick-closing valve feedback closed” signal 40 b ).
[0315] In addition, the smart contract monitors, based on the timestamp of the signal, whether the reaction has arrived within a predefined time.
[0316] For example, a trigger signal 39 caused in the protection logic is also transmitted to the smart contract. The protection logic responds and triggers a protection command (command "close" 39). The steam quick closing valve closes and "close" (signal 40b) is fed back to the protection logic. This is also transmitted to the smart contract.
[0317] success:
[0318] If the trigger (40a) and the protection effect (40b) change from 0 to 1 in the correct order within the pre-given time, a successfully verified document (with a timestamp) occurs. The smart contract sets the functional approval of the protection circuit. The simulation in the functional logic is reset.
[0319] For example, electrical measured values can be generated in a sensor or in a test module for simulation (HART simulation). Here, the speed of the turbine = 0. However, the indicator or corresponding sensor delivers, for example, 12 mA or, for example, 10,000 R / Min, and this triggers a protection or corresponding safety function.
[0320] The functional approval of the protection circuit is retained by the smart contract 36 until the next re-inspection.
[0321] Test failed:
[0322] If the cause and effect are not realized in the correct order and time interval, or if the time of the verification window (10 minutes) has passed and no trigger signal 40a has been recorded in the smart contract, there is an error, because, for example, the simulation has not yet responded. These corresponding settings can be stored, for example, in the reference data.
[0323] One measure could be that the protection command is continuously triggered by the smart contract so that the quick-closing valve can no longer be moved to open. After the error has been eliminated, the facility must be authorized again by a reset mechanism in the smart contract and / or in the protection logic.
[0324] Because unsuccessfully tested messages are stored in the blockchain and transmitted to the responsible party, error searching and error correction can be carried out under supervision.
[0325] Smart contracts can be represented such that a reset in the smart contract is only possible by an assigned department or by a certification authority (key management and authorization in blockchain).
[0326] Further embodiments are shown below:
[0327] Device or system for checking a technical system / the technical system, in particular for consistency tracking, comprising:
[0328] - For example, loading a module where
[0329] o For example, load modules are set up to load and / or perform test control transactions,
[0330] o For example, load test control transactions from a web application,
[0331] o For example, a test control transaction includes control commands and reference data;
[0332] - For example, a test module, where
[0333] o For example, the test module is set up to be controlled by means of control commands,
[0334] o For example, the control commands control the test module in such a way that a test signal is generated for a subsystem of the technical system;
[0335] - For example, a detection module, wherein
[0336] o For example, a detection module is set up to collect measurement data of a subsystem in response to a test signal,
[0337] o For example, the measurement data is detected by the test module,
[0338] o For example, the measurement data is detected by the sensors of the test module;
[0339] o For example, the detection module is a sensor;
[0340] For example, a calculation module, wherein the calculation module is configured to calculate a test result based on the measurement data and the reference data;
[0341] For example, a control module, wherein for example the control module is designed to control the technical system as a function of the test result and / or to carry out a control function as a function of the test result.
[0342] The load module and / or the test module and / or the calculation module and / or the control module can be implemented, for example, as separate hardware and / or software modules. Alternatively or additionally, these modules are constructed as smart contracts and can be fully or partially implemented, for example, by protection logic and / or test control transactions.
[0343] In a further variant, the detection module is formed by the sensors 43 , 45 .
[0344] In a further variant, the calculation module and / or the control module (explained in the previous embodiments) is formed by the test module and / or the protection logic.
[0345] In further variations, the load module is implemented by a test module and / or a web application (explained in the previous embodiments).
[0346] In a further variant, the system or device comprises a monitoring module, wherein the monitoring module is configured to store activities of the system and / or the test module in a log file or data record or in a transaction.
[0347] The device or system (or other embodiments and variants thereof) may, for example, additionally comprise further components or a plurality of further components, such as, for example, a processor, a memory unit, a further communication interface (e.g., Ethernet, WLAN, USP, fieldbus, PCI), an input device (in particular a computer keyboard or a computer mouse) and a display device (e.g., a monitor). The processor may, for example, comprise a plurality of further processors, which may be used, in particular, to implement further embodiments.
[0348] A further exemplary embodiment relates to a computer-implemented method for providing data in a distributed peer-to-peer network (1), in particular for consistency tracking, comprising the following steps:
[0349] - providing at least one first data block (4a), in particular having data representing a consistency trace, for generating a blockchain (3) having a first checksum (6a) by means of a first instance (5a) of the peer-to-peer network (1),
[0350] - providing at least one authority verification proof (10) for verifying the further data block (4b, 4c),
[0351] - generating, by a further entity (5b, 5c) of the peer-to-peer network (1), a further data block (4b, 4c) representing the consistency track, the further data block (4b, 4c) having a further checksum (6b, 6c),
[0352] - Check the authority verification certificate (10),
[0353] - in the event of successful verification of the authority verification certificate (10), adding the further data block (4b, 4c) to the first data block (4a) in order to form a blockchain (3), and
[0354] - providing a blockchain (3) in a distributed peer-to-peer network (1),
[0355] One of the data blocks (4a, 4b, 4c) is designed as a smart contract (36, 29a, 29b, 29c) which provides error handling measures based on the presence of a predetermined error situation and / or triggers a functional test based on the presence of a test trigger signal (37).
[0356] In a variation of this embodiment, the computer-implemented method requires that the test trigger signal (37) is a test signal (38).
[0357] In a variant of this embodiment, the verification signal ( 38 ) is provided by a smart contract ( 36 , 29 a , 29 b , 29 c ).
[0358] In a variation of this embodiment, the smart contract (36, 29a, 29b, 29c) provides a reset signal (42).
[0359] In a variation of this embodiment, the smart contract (29a, 29b, 29c) provides a feedback signal (40).
[0360] In a variation of this embodiment, the peer-to-peer network ( 1 ) is a private network.
[0361] In a variant of this embodiment, the authorization verification certificate ( 10 ) has at least one time-limited validity period.
[0362] In a variant of this embodiment, the authority verification certificate ( 10 ) has at least one validity in terms of content.
[0363] In a variant of this embodiment, the authorization verification certificate ( 10 ) has at least one user-related validity.
[0364] In a variant of this embodiment, the data block (4a, 4b, 4c) is constructed as a smart contract, wherein the smart contract provides a proof of authority verification (10) based on the existence of predetermined conditions.
[0365] In a variant of this embodiment, a repair function is provided for modifying and / or marking at least one of the data blocks (4a, 4b, 4c).
[0366] A further implementation paradigm relates to a system for providing data, wherein the system comprises means for implementing the steps of the method according to one of the aforementioned embodiments and / or variants thereof.
[0367] A further embodiment relates to a computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out at least one of the steps of one of the embodiments and / or variants thereof, wherein the computer is assigned to the first example (5a).
[0368] A further embodiment relates to a computer program product comprising instructions for causing the computer to carry out at least one of the steps of the embodiment when the program is carried out by a computer, wherein the computer is assigned to one of the further examples (5b, 5c).
[0369] Another embodiment relates to a computer program product comprising instructions that, when the program is executed by a computer, cause the computer to implement at least one of the steps of one of the embodiments and / or smart contracts (29a, 29b, 29c) thereof.
[0370] By scanning or photographing and image processing, a large number of features (material identification, production marks, etc.) can be detected, which can be automatically checked or authenticated using smart contracts 29a, 29b, 29c.
[0371] Although the present invention has been more particularly illustrated and described in detail by means of preferred embodiments, the present invention is not limited to the disclosed examples and other variations may be derived therefrom by those skilled in the art without departing from the scope of protection of the present invention. [1]
[0373] Andreas M. Antonopoulos "Mastering Bitcoin: Unlocking Digital Cryptocurrencies", O'ReillyMedia, December 2014 [2]
[0375] Roger M. Needham, Michael D. Schroeder “Using encryption for authentication in large networks of computers” ACM: Communications of theACM. Volume 21, December 12, 1978 [3]
[0377] Ross Anderson “Security Engineering. A Guide to Building DependableDistributed Systems” Wiley, 2001 [4]
[0379] Henning Diedrich “Ethereum: Blockchains, Digital Assets, SmartContracts, Decentralized AutonomousOrganizations”, CreateSpace IndependentPublishing Platform, 2016 [5]
[0381] “The Ethereum Book Project / Mastering Ethereum”
[0382] https: / / github.com / ethereumbook / ethereumbook as of October 5, 2017 [6]
[0384] Leemon Baird
[0385] "The Swirlds Hashgraph Consensus Algorithm: Fair, Fast, ByzantineFault Tolerance",
[0386] Swirlds Tech Report SWIRLDS-TR-2016-01, May 31, 2016 [7]
[0388] Leemon Baird
[0389] “Overview of Swirlds Hashgraph”,
[0390] May 31, 2016 [8]
[0392] Blockchain Oracles
[0393] https: / / blockchainhub.net / blockchain-oracles /
[0394] As of March 14, 2018.
Claims
1. A computer-implemented method for testing a technical system, comprising the following steps: Load and / or implement test control transactions, where Testing control transactions including smart contracts or smart contracts, The test trigger signal (37) requests the loading and / or execution of the test control transaction, Load test control transactions from the web application, Test control transactions include control commands and reference data; Control test module, where The control command controls the test module so that a test signal for a subsystem of the technical system is generated; The measurement data of the detection subsystem as a reaction to the test signal, where The test module detects the measurement data. The measurement data is detected by the sensor of the test module; The test results are calculated based on the measured data and the reference data, where The smart contract and / or test control transaction calculates the test result in the presence of reference data; The technical system is controlled as a function of the test result and / or a control function is carried out as a function of the test result. 2 . The computer-implemented method of claim 1 , wherein the technical system is configured for consistency tracking.
3. A computer-implemented method according to any one of claims 1 to 2, in, A reset signal (42) is provided for the subsystem depending on the test result, or the control function provides a reset signal (42) for the subsystem depending on the test result.
4. A computer-implemented method according to any one of claims 1 to 2, in, A feedback signal (40) is provided to the subsystem depending on the test result, or the control function provides a feedback signal (40) to the subsystem depending on the test result.
5. The computer-implemented method of claim 1 , wherein The verification results are stored in the confirmation transaction, and / or The measurement data is stored in a measurement data transaction, and / or Calculate inspection results based on the measurement data of the measurement data transaction, and / or The confirmation transaction and / or the measurement data transaction and / or the test control transaction is protected by means of corresponding authorization verification certificates, and / or Confirmation transactions and / or measurement data transactions and / or test control transactions are stored in corresponding data blocks, and / or Additional data / metadata for verification is stored in the confirmation transaction, and / or The corresponding data block includes the corresponding authority verification proof of the corresponding transaction.
6. The computer-implemented method of claim 1 , wherein The network application is implemented in or by the peer-to-peer network (1), Peer-to-peer networks (1) are private networks.
7. The computer-implemented method according to any of the preceding claims 5 to 6, wherein the authority verification certificate (10) has at least one time-limited validity period.
8. A computer-implemented method according to any one of the preceding claims 5 to 6, in, The authority verification certificate (10) has at least one content validity.
9. A computer-implemented method according to any one of the preceding claims 5 to 6, in, The authority verification certificate (10) has at least one validity associated with a user.
10. The computer-implemented method according to any one of the preceding claims 5 to 6, wherein the data blocks (4a, 4b, 4c) are configured as smart contracts that provide a proof of authorization verification (10) based on the existence of a predetermined condition.
11. The computer-implemented method according to any one of the preceding claims 5 to 6, wherein a repair function is provided for changing and / or marking at least one data block (4a, 4b, 4c).
12. A device for inspecting a technical system, having: a loading module, wherein the loading module is configured to load and / or execute a test control transaction that includes a smart contract, a test trigger signal (37) requests the loading and / or execution of the test control transaction, the test control transaction is loaded from a network application, the test control transaction includes control commands and reference data; a test module, wherein the test module is configured to be controlled by means of the control commands, the control commands manipulate the test module such that test signals for subsystems of the technical system are generated; a detection module, wherein the detection module is configured to detect measurement data of the subsystems as a response to the test signals, the measurement data is detected by the test module, the measurement data is detected by sensors of the test module; the detection module is a sensor; a calculation module, wherein the calculation module is configured to calculate an inspection result based on the measurement data and the reference data; a control module, wherein the control module is configured to control the technical system depending on the inspection result and / or to execute a control function depending on the inspection result, wherein the smart contract and / or the test control transaction calculate the inspection result in the presence of the reference data.
13. The device according to claim 12, wherein the test control transaction is a smart contract.
14. The device according to claim 12, wherein the technical system is provided for consistency tracking.
15. A computer program product comprising instructions that, when the program is executed by a computer, cause the computer to perform all steps of the method according to any one of claims 1 to 11, wherein the computer is assigned to a first instance (5a).
16. A computer program product comprising instructions that, when the program is executed by a computer, cause the computer to perform all steps of the method according to any one of claims 1 to 11, wherein the computer is assigned to one of the other instances (5b, 5c).
Citation Information
Patent Citations
Test environment for automation tasks
DE102017121296A1