System, machine, method for configuring a system, and method for operating a machine
By issuing a unique sub-certificate to each device and using root certificate signature to ensure the identity of the device, the problem of fake sensor data and unknown sources in the machine is solved, the security and reliability of the machine operation are achieved, and fault diagnosis is simplified.
Patent Information
- Application Number
- CN202011164202.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-28
- Filing Date
- 2020-10-27
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2040-10-27
AI Technical Summary
In the prior art, there are problems in machines or industrial systems that are forged sensor data and cannot uniquely determine the source of data, which makes the machine unsafe operation and difficulty in troubleshooting, especially in industrial environments with high safety requirements.
Certificate devices are used to issue unique sub-certificates to each device, ensure device identity identification through root certificate signature, establish trust chains, ensure data source traceability and security, and prevent data manipulation.
It realizes a high degree of safety and reliability of machine operation, simplifies fault diagnosis, reduces unplanned downtime, and improves the anti-counterfeiting of the system and the accuracy of data use.
Smart Images

Figure CN112733124B_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a system, a machine, a method for configuring such a system, and a method for operating such a machine. Background Art
[0002] Machines or industrial systems have numerous devices that work together to solve a task. These devices exchange data, such as sensor data—actual values from machine operation—or control commands containing setpoint values for controlling drives. Furthermore, in some applications, data is transmitted to devices external to the machine or industrial system. These devices include, for example, higher-level control units or data management systems. These devices may also store and use data from other machines or industrial systems. Consequently, large amounts of data must be managed both within the machine and in external devices.
[0003] The problem is that external data is fed into the machine's devices, which, for example, falsifies data from the machine's sensors or specifies different, or in the worst case, incorrect, setpoint values. This allows the machine's operation to be manipulated. This can lead to at least undesirable consequences in the machine's operation or even dangerous machine states.
[0004] Another problem is that, for example, multiple identical sensors may be present in a machine. If there are also multiple identical machines, it's not always possible to determine which sensor generated the data or which sensor belongs to which machine. Tracking the origin of individual data may no longer be possible in some cases, or it may be extremely complex and expensive. Consequently, when a machine malfunctions, it's often difficult to determine the cause.
[0005] All of this is also unacceptable with regard to the safety of the machine, especially in an industrial environment where there are predetermined requirements for safety. Summary of the Invention
[0006] The object of the present invention is therefore to provide a system, a machine, a method for configuring such a system, and a method for operating such a machine that solve the above-mentioned problems. In particular, a system, a machine, a method for configuring such a system, and a method for operating such a machine should be provided that allow the machine to be operated with a high degree of safety and without long, unplanned downtimes.
[0007] The above object is achieved by a system according to claim 1. The system comprises at least one machine having at least one device for exchanging data with another device of the machine, with another machine for jointly solving a task, or with a superordinate device, and a certificate device designed to identify the at least one machine with a root certificate and to distribute a sub-certificate to at least one device of the machine, wherein the certificate device is designed to sign the sub-certificate with the root certificate of the machine in order to identify the device as belonging to the machine, and wherein the sub-certificate is issued uniquely for the device.
[0008] The system is designed to uniquely assign each device to a machine. The data exchanged between devices also includes information about the device that generated the data. This ensures traceability of the origin of all data related to the machine, thereby guaranteeing the security of the data and the operation of the machine.
[0009] As a result, these machines can also be integrated into a machine complex that also includes at least one other machine, allowing the origin of data from each machine to be easily and consistently determined. This also makes it possible to uniquely assign data, for example, from multiple industrial control devices for controlling peripherals that are connected to drives and / or at least one industrial control device via logic modules or drive units. This makes data manipulation at least more difficult than previously possible.
[0010] Furthermore, data from different devices can no longer be easily mixed. This facilitates the correct use of the data and thus contributes to machine safety.
[0011] Furthermore, certificates allow for the effortless use of cryptography. This also makes it possible, for example, to easily and automatically generate a forgery-proof representation of the communication relationship of the machine or machine complex. This improves the operability of the machine or machine complex. Furthermore, this also increases the security of the machine or machine complex, as errors can be discovered more quickly. This also helps to keep machine downtimes as few and as short as possible.
[0012] Overall, the above-described machine allows for very simple, safe, and reliable operation of the machine, a superordinate machine complex, or a superordinate industrial system. It also allows for rapid response to the machine's currently occurring operating conditions. All these characteristics result in highly efficient machine operation.
[0013] Advantageous further embodiments of the machine are described in the dependent claims.
[0014] The certificate device may have a private key having a public key, and wherein the certificate device is designed to sign a root certificate of the machine using the private key.
[0015] It is possible that the at least one device has a private key, the private key has a public key, wherein the at least one device is designed to send its public key to the certificate device, whereby the certificate device issues the sub-certificate, and wherein the certificate device is designed to sign the public key of the device using the root certificate of the machine to issue the sub-certificate of the device.
[0016] Optionally, one of the devices is a control device, and another of the devices is a drive device, a tool, or a transport device.
[0017] It is conceivable that at least one device of the machine is designed to allow data to be exchanged with another device of the machine or with another machine or with a higher-level device only if the data is provided with a subcertificate signed with the root certificate.
[0018] In a specific design, the data may be operating status data or control commands of a device.
[0019] In another specific design, the data includes parameters that can be used in controlling a drive of at least one element of the machine.
[0020] In yet another specific design, the data includes an IP address and / or name of the device.
[0021] The above system may further include a device arranged outside the at least one machine, wherein the device stores a root certificate of the at least one machine, and wherein the device is designed to use the root certificate of the at least one machine to check the credibility of data received from the device of the at least one machine.
[0022] The above object is also achieved by a machine according to claim 9. The machine has at least one device for exchanging data with another device of the machine or with another machine for jointly solving a task or with a superior device, and the machine has a certification device designed to issue a sub-certificate to the at least one device of the machine, wherein the certification device is designed to identify the device as belonging to the machine, the sub-certificate is signed using a root certificate of the machine issued by a superior certification device, and wherein the sub-certificate is issued uniquely for the device.
[0023] The aforementioned object is also achieved by a method for configuring a system according to claim 10. The system comprises at least one machine having at least one device for exchanging data with another device of the machine, with another machine for jointly solving a task, or with a higher-level device. Furthermore, the system comprises a certificate device. The method comprises the following steps: using the certificate device to identify the at least one machine with a root certificate, and using the certificate device to distribute a sub-certificate to at least one device of the machine by signing the sub-certificate with the machine's root certificate to identify the device as belonging to the machine, wherein the sub-certificate is issued uniquely for the device.
[0024] The aforementioned object is also achieved by a method for operating a machine according to claim 11. The machine has at least one device for exchanging data with another device of the machine, with another machine for jointly solving a task, or with a higher-level device, wherein the method comprises the following steps: preparing data for transmission to a device that is arranged outside the at least one machine and stores a root certificate of the at least one machine, adding a sub-certificate to the prepared data, wherein the sub-certificate is signed with a root certificate of the certificate device of the machine in order to identify the device as belonging to the machine, and wherein the sub-certificate is uniquely issued for the device, and the device uses the root certificate of the at least one machine to check the credibility of data received from the device of the at least one machine.
[0025] The method achieves the same advantages as mentioned above with respect to the machine.
[0026] Other possible implementations of the present invention also include combinations not explicitly mentioned of the features or implementations described above or below with respect to the embodiments. Here, those skilled in the art may also add various aspects as improvements or supplements to the corresponding basic forms of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The present invention will be described in more detail below based on embodiments with reference to the accompanying drawings.
[0028] Figure 1 A block diagram showing a system having a plurality of machines and a control device arranged outside the machines according to a first embodiment is shown;
[0029] Figure 2 A flowchart showing a method for configuring a machine according to a first embodiment; and
[0030] Figure 3 A flow chart of a method for operating a machine according to a first exemplary embodiment is shown.
[0031] In the figures, identical or functionally identical elements are provided with the same reference signs unless stated otherwise. DETAILED DESCRIPTION
[0032] Figure 1 A system 1 according to a first exemplary embodiment is schematically shown, in which an object 2 can be processed. The system 1 has a machine complex 3 with a first and a second machine 10, 20, which can exchange data 30 with one another. The system 1 also has a certification device 50 with a private key 51 having a public part, also referred to as a public key 52.
[0033] In the case of the first machine 10, an external device 4 is arranged, which is arranged outside the machine 10, 20. For reasons that will be explained in more detail below, the device 4 is not known in particular to the machine 10. Therefore, the machine 10 and the external device 4 cannot communicate with each other, as Figure 1 In contrast, each machine 10, 20 can exchange any data 41, 42 with the superior device 8, such as Figure 1 This is indicated by the dashed arrow in FIG and will be described in more detail below.
[0034] System 1 is particularly an industrial system. An industrial system is, for example, a disassembly and / or assembly system or other manufacturing system in which an object 2 consisting of at least one individual component is processed, for example, painted or polished, inspected optically or in some other way, cut into pieces, etc., or the object 2 is manufactured in some way, and / or an object 2 consisting of at least two components is assembled and / or disassembled. Various processing methods can be used, such as joining methods, in particular welding, screwing, riveting, nailing, etc., or techniques such as sawing, etching, punching, pressing, drilling, laminating, melting, printing, etc.
[0035] The machine complex 3 can be formed, for example, by a transport machine 10 for transporting components to the joining machine 20. Further examples are of course conceivable.
[0036] Machines 10, 20 and devices 8 can be connected via a bus system, either wired or wirelessly. In particular, machines 10, 20 and devices 8 are connected via the Internet, an intranet, or the like. Device 8 can be, for example, a company's higher-level control system and / or a company's data management system and / or a company's central computing system, which are connected to multiple company locations where various machine complexes 3 with machines 10, 30 and / or individual machines 10, 20 are located. Alternatively, device 8 can be a cloud. Data from other machines or industrial systems can also be stored and used in device 8, if necessary. Consequently, large amounts of data must be managed in each machine 10, 20 and in externally located devices 8.
[0037] The first machine 10 has a local certificate device 11 with a certificate authority and a machine component 12 with at least one device 121, 122, ..., 12N-1, 12N. As described previously using examples, the devices 121, 122, ..., 12N-1, 12N can be of the same type or have different structures and / or functions.
[0038] The local certificate device 11 may be formed, for example, by a control device that controls at least one of the devices 121 to 12N. The local certificate device 11 is responsible for issuing certificates for all devices 121 to 12N. However, as described below, the local certificate device 11 also relies on a slightly more global certificate device 50.
[0039] Machine 10 has a root certificate 101. At least one private key 1100 of local certificate device 11 is stored and securely maintained in local certificate device 11. Each private key 1100 has a public portion, a so-called public key 1110. Device certificates 111 to 11N are available for devices 121 to 12N. This will be described in more detail below.
[0040] Device 121 has a module 131 in which at least one private key 141 of device 121 is stored and securely stored. Devices 122, ..., 12N-1, 12N also have modules 132, ..., 13N-1, 13N, respectively, in which at least one private key 142 of an associated device 122, ..., 12N-1, 12N is stored and securely stored. The at least one private key 141 to 14N is protected from being read from the associated module 131 to 13N. The purchaser or operator of a device 121 to 12N can generate their own private key 141 to 14N in the desired module 131 to 13N and use it for their own purposes. Each private key 141 to 14N has a public portion, referred to as a public key.
[0041] Devices 121 to 12N work together to solve at least one task, such as drilling an opening in at least one component so that two components can be assembled to form an object 2 in alignment with the opening. To this end, a robot, such as device 121, is to be controlled and driven to hold the component in a predetermined position and to actuate a tool to produce the opening, for example, by drilling, milling, punching, and / or etching, and / or other suitable methods. At least two of devices 121 to 12N exchange data 15, 16, and 17 with one another, such as sensor data, i.e., actual values from the operation of the robot, such as its position in space, and / or actual values from the operation of the tool. Furthermore, data such as control commands with setpoint values for controlling the drives of the robot or tool are exchanged as data 15, 16, and 17. The sensor data may include at least one physical variable detected during the operation of machine 10.
[0042] If the device 121 to 12N is not required to send data to the apparatus 8 or machine 20, it is not necessary to issue a sub-certificate to the device 121 to 12N, as described below for other devices 121 to 12N. However, in order to create a seamless chain of trust, it is advantageous to distribute a sub-certificate to each device 121 to 12N.
[0043] The second machine 20 optionally has a local certificate device 21 with a certificate authority. In any case, the second machine 20 has a machine component 22 with at least one device 221, 222, ..., 22N-1, 22N. As described previously using examples, the devices 221, 222, ..., 22N-1, 22N can be of the same type or have different structures and / or functions.
[0044] Local certificate device 21 can be formed, for example, by a control device of machine 20, which controls at least one of devices 221, 222, ..., 22N-1, and 22N. Machine 20 has a root certificate 201. At least one private key 2100 of local certificate device 21 is stored and securely within local certificate device 21. Each private key 2100 has a public portion, a so-called public key 2110. Device certificates 211 through 21N can be used for devices 221, 222, ..., 22N-1, and 22N. This will be described in more detail below.
[0045] Device 221 has a module 231 in which at least one private key 241 of device 221 is stored and securely stored. Devices 222, ..., 22N-1, and 22N also have modules 232, ..., 23N-1, and 23N, respectively, in which at least one private key 241 of an associated device 222, ..., 22N-1, and 22N is stored and securely stored. The at least one private key 241 through 24N is protected from being read from the associated module 231 through 23N. A purchaser or operator of a device 221 through 22N can generate their own private key 241 through 24N in a desired module 231 through 23N and use it for their own purposes. Each private key 241 through 24N has a public portion, referred to as a public key.
[0046] Devices 221 to 22N work together to solve at least one task. This can be accomplished in a manner similar to that described above for devices 121 to 12N of machine 10. At least two of devices 221 to 22N exchange data 25, 26, and 27 with one another, such as sensor data, i.e., actual values from the operation of the robot, such as its position in space, and / or actual values from the operation of the tool. Furthermore, data such as control commands with setpoint values for controlling the drives of the robot or tool are exchanged as data 25, 26, and 27. The sensor data may include at least one physical variable detected during the operation of machine 20.
[0047] As described above, the certificate device 50 has a private key 51. Private key 51 has a public portion, the so-called public key 52. Based on private key 51, the certificate device 50 issues a root certificate 101 for the first machine 10 in response to a request from the machine complex 3 or machine 10 and transmits the root certificate to the machine 10. The certificate device 50 generates the root certificate 101 based on its private key 51. To do this, the certificate device 50 signs the request from the machine complex 3 or machine 10 with its private key, thereby creating the root certificate 101. Consequently, the root certificate 101 is a trustworthy certificate 101 for the machine 10.
[0048] The root certificate 101 of the machine 10 is stored and / or installed in particular in a data server or local certificate device 11 of the machine 10. Furthermore, the certificate device 50 provides the device 8 with the root certificate 101 of the machine 10. If the machines 10, 20 are to exchange data 30, the certificate device 50 optionally provides the machine 20 with the certificate 101.
[0049] The certificate device 50 then sends a request to the local certificate device 11, requesting the identity of the certificate device 11. In response, the local certificate device 11 sends a certificate request to the certificate device 50, which verifies or signs the certificate request using the root certificate 101 of the machine 10. Consequently, a sub-certificate 110 is issued to the local certificate device 11. The sub-certificate 110 is stored in the local certificate device 11.
[0050] The local certificate device 11 can then send a request to all devices 121 to 12N to request the identity of each device 121 to 12N. In response, the corresponding device among the devices 121 to 12N sends a certificate request to the local certificate device 11, and the certificate device 11 verifies or signs the certificate request with the sub-certificate 110 of the certificate device 11. A sub-certificate 111 to 11N is thereby issued to each of the devices 121 to 12N. As previously mentioned, each device 121 to 12N stores its sub-certificate 111 to 11N. Alternatively, the certificate device 11 can use the root certificate 101 of the machine 10 to verify or sign the certificate request from at least one device 121 to 12N. In this case, the root certificate 101 of the machine 10 must also be available in the local certificate device 11, in particular stored and / or installed in the local certificate device 11.
[0051] Additionally, the certificate device 50 issues a root certificate 201 for the second machine 20 based on its private key 51. For the machine 20, this is done in the same way as described above for the first machine 10.
[0052] The root certificate 201 of the machine 20 is stored in particular on a data server or other secure memory of the machine 20 and / or installed in other secure components of the machine 20. Furthermore, the certificate device 50 provides the device 8 with the root certificate 201 of the machine 20. If the machines 10, 20 are to exchange data 30, the certificate device 50 optionally provides the certificate 201 to the machine 10.
[0053] If a local certificate device 21 is present in the case of machine 20, certificates 210 to 21N are created as described above with respect to machine 10. A sub-certificate 210 is thereby issued for local certificate device 21. Sub-certificate 210 is stored in local certificate device 21. In this case, local certificate device 21 is responsible for issuing certificates 211 to 21N for all devices 221 to 22N. However, as described below, local certificate device 21 also relies on a slightly more global certificate device 50.
[0054] Conversely, if a local certificate device 21 does not exist for at least one device 221 to 22N, certificates 210 to 21N are created as follows. In this case, the certificate device 50 sends a request to all devices 221 to 22N for which no local certificate device 21 is available. In response, these devices 221 to 22N send a certificate request to the certificate device 50, which then verifies or signs the certificate request using the root certificate 201 of the machine 20. Consequently, a sub-certificate 211 to 21N is issued to each of the devices 221 to 22N. As previously described, each device 221 to 21N stores its sub-certificate 211 to 21N.
[0055] During operation of each machine 10, 20 or machine complex 3, devices 121 to 12N exchange data 15, 16, 17 with one another using certificates 111 to 11N. Each device 121 to 12N assigns its associated certificate 111 to 11N to the data 15, 16, 17 sent by that device, thereby uniquely identifying the sent data 15, 16, 17. Each certificate 111 to 11N is unique to each device. Each certificate 101, 110 to 11N is unique and is generated and issued for anti-counterfeiting purposes. Therefore, each certificate 101, 110 to 11N exists only once and is distinct from all other certificates 101, 111 to 11N. Each certificate 101, 110 to 11N is validated by an official or trusted authority and is therefore not limited to a local, self-signed signature. For example, device 121 uses associated certificate 111 to identify data 15 to be sent to device 122. Thus, even if the data 15 is to be forwarded as data 16 to the device 12N- 1 , for example, the data 15 is later identified as data of the device 121 .
[0056] The data 15 , 16 , 17 may include parameters that can be used when controlling at least one element of the machine 10 , such as a pivot or a drive shaft, or a drive of equipment 121 to 12N of the machine 10 , such as a robot, a conveyor belt, etc.
[0057] Additionally or alternatively, the data 15 , 16 , 17 include an IP address and / or a name of at least one device 121 to 12 N. This allows the data 15 , 16 , 17 to be specified even more precisely.
[0058] Furthermore, the device 121 can send the data 15 as data 41 to the apparatus 8 and / or as data 30 to the machine 20. The same applies to the communication between the other devices 121 to 12N of the machine 10 and / or to the device 8 and / or to the machine 20.
[0059] Furthermore, during the operation of machine 20 or machine complex 3, devices 221 to 22N exchange data 25, 26, and 27 with one another using certificates 221 to 22N. Each device 221 to 22N assigns its associated certificate 211 to 21N to the data 25, 26, and 27 sent by that device, thereby uniquely identifying the sent data 25, 26, and 27. Each certificate 211 to 21N is unique to each device 221 to 22N. Each certificate 211 to 21N is unique and generated and issued for anti-counterfeiting purposes. Therefore, each certificate 211 to 21N can only exist once and is distinct from all other certificates 201, 210 to 21N. Each certificate 201, 210 to 21N is validated by an official or trusted authority, meaning it is not limited to a local or private signature. For example, device 221 uses associated certificate 211 to identify data 25 to be sent to device 222. Thus, even if data 25 should be forwarded as data 26 to, for example, device 22N- 1 , data 25 may later be identified as data for device 221 .
[0060] The data 25 , 26 , 27 may include parameters that can be used when controlling at least one element of the machine 20 , such as a pivot or a drive shaft, or a drive of equipment 221 to 22N of the machine 10 , such as a robot, a conveyor belt, etc.
[0061] Additionally or alternatively, the data 25, 26, 27 include an IP address and / or a name of at least one device 221 to 22N. This allows the data 25, 26, 27 to be specified even more precisely.
[0062] Furthermore, the device 221 can send the data 25 as data 42 to the apparatus 8 and / or as data 30 to the machine 10. The same applies to the communication between the other devices 221 to 22N of the machine 20 and / or to the apparatus 8 and / or to the machine 10.
[0063] Thus, in the system, the certificate device 50 or local device 11, 12 issues a certificate for each new device that is bound to the associated machine 10, 20 at startup. The certificates 111 to 11N of the devices 121 to 12N of the machine 10 are child certificates of the certificate 101 of the machine 10. The certificates 211 to 21N of the devices 221, 222, ..., 22N-1, 22N of the machine 20 are child certificates of the certificate 201 of the machine 10.
[0064] Therefore, when device 12N-1 is activated on machine 10, machine 10, for example, has already issued certificate 11N-1 to device 12N-1. Only after certificate 11N-1 has been distributed can device 12N-1 communicate with other devices 121, 122, ..., 12N. Furthermore, only then can device 12N-1 communicate with machine 20. The same applies to communication with appliance 8. In order for device 12N-1 to communicate with appliance 8, certificate 11N-1 must be issued using root certificate 101 of machine 101. Otherwise, certificate 110 of the local certificate device must also be stored on appliance 8.
[0065] The certificate 101 of the first machine 10 and the certificate 201 of the second machine 20 are stored in the device 8. Therefore, data represented by the sub-certificates 111, 112, ..., 11N-1, 11N of the devices 121, 122, ..., 12N-1, 12N from the first machine 10 can be uniquely identified as data 15, 16, 17 from the devices 121, 122, ..., 12N-1, 12N of the first machine 10. In addition, data 25, 26, 27 represented by the sub-certificates 211, 212, ..., 21N-1, 21N of the devices 221, 222, ..., 22N-1, 22N from the second machine 20 can be uniquely identified as data 25, 26, 27 from the devices 221, 222, ..., 22N-1, 22N of the second machine 20.
[0066] , 12N- 1 , 12N, 221 , 222 , . . . , 22N- 1 , 22N, which machine 10 , 20 , which machine complex 3 (eg factory) etc. the data 15 , 16 , 17 , 25 , 26 , 27 come from.
[0067] A chain of trust can thereby be ensured. Thus, manipulation of the data 15 to 17 , 30 , 41 by external devices such as the device 4 is at least made more difficult or, in the best case, impossible.
[0068] As a result, first machine 10, with its certificate 101, can be externally identified as a logical unit. Furthermore, second machine 20, with its certificate 201, can be externally identified as a logical unit. Here, it is sufficient to store only the machine identity of the respective machine 10, 20 in the form of a root certificate 101, 201 on device 8. It is not necessary to store a certificate on device 8 for each trusted participant or device 11, 12, 121 to 12N, 221 to 22N of machine 10, 20. This makes trusted communication within machine complex 3 and with external devices 8 significantly simpler than in a variant in which a certificate is stored on device 8 for each device 11, 12, 121 to 12N, 221 to 22N and then checked.
[0069] like Figure 2 As shown, during configuration and / or startup of machines 10, 20, as described above, a root certificate 101, 201 is provided for machines 10, 20 by the certificate device 50 in step S1. The attributes of the machine complex 3 can be based, for example, on the IP address and associated subnet. Specifically, the certificate device 50 receives a request to generate or request a machine identity. This is accomplished via a web front-end or a subsequent request (command). The certificate device 50 then generates a machine root certificate 101, 201 based on its private key. Furthermore, the root certificate 101, 201 can be transmitted to the device 8 and / or the corresponding other machines 20, 10. The process then proceeds to step S2.
[0070] In step S2, during configuration and / or startup of the individual devices 121 to 12N, 221 to 22N of machines 10, 20, the corresponding certificates 111 to 11N, 211 to 21N of each device 121 to 12N, 221 to 22N are distributed and stored in the devices 121 to 12N, 221 to 22N. To this end, the certificate device 50 automatically sends a request to all network participants of the machine complex 3 via a broadcast or a residual request (Representational State Transfer) requesting their identities. Then, at the instigation of the certificate device 50, the relevant machine components or the aforementioned devices 11, 12, 121 to 12N, 221 to 22N send a certificate signing request, which the certificate device 50 verifies / signs using the root certificate 101, 201, as previously described. Thus, sub-certificates 110 to 11N, 210 to 21N are issued for the machine components or devices 11, 12, 121 to 12N, 221 to 22N. Therefore, machine affiliation can be easily proven using the machine root certificates 101 and 201. Additionally, the unique device identity can be verified based on the individual sub-certificates 110 to 11N, 210 to 21N of the devices 11, 12, 121 to 12N, 221 to 22N, as needed. The process then proceeds to step S3.
[0071] In step S3, the respective devices 121 to 12N, 221 to 22N of machines 10 and 20 are configured so that when exchanging data 15 to 17, 25 to 27, 30, 41, and 42 with another device 121 to 12N, 221 to 22N of machine 10 and 20, or with another machine 20 and 10, or with a higher-level device 8, the data 15 to 17, 25 to 27, 30, 41, and 42 are only allowed to be exchanged if the data 15 to 17, 25 to 27, 30, 41, and 42 are provided with a sub-certificate 111 to 11N, 211 to 21N. Sub-certificates 111 to 11N, 211 to 21N must have been issued by certificate device 11 and 21. The process then returns to step S2.
[0072] If the certificates 111 to 11N, 211 to 21N have been set to all devices 121 to 12N, 221 to 22N, the method ends.
[0073] The distribution of certificates within the machine complex 3 is thus automated. Furthermore, not only are the certificates 101, 110 to 11N, 201, 210 to 21N automatically created, but they are also automatically distributed and updated.
[0074] Therefore, in order to trust the entire machine 10, 20 or its machine complex 3, the machine certificate 101, 201 data is transferred to a higher-level or superordinate system in response to the aforementioned requirement to generate or request a machine identity. This can be done manually by a user specifically downloading the machine identity from the certificate device 50. Such a user is typically the person who starts or maintains the machine 10, 20. Alternatively, the machine identity can be automatically reported to the certificate device 50. This automatic reporting can be accomplished via a corresponding interface, particularly a web interface.
[0075] like Figure 3 As shown, in a method for operating a machine (e.g., machine 10), after the method is started in step S11 using a device (specifically, device 122), operating status data is detected as data 16, for example, and prepared for transmission. The operating status data may specifically be the position of a robot in space, the steam pressure in a boiler, the position of a valve piston, the magnitude of an electric current, an offset from an alignment mark, or any other physical variable. The process then proceeds to step S12.
[0076] In step S12, the certificate of the device that detected the operating status data is set to the operating status data. In the above example, the device 122 sets the certificate 112 to its operating status data, that is, for example, data 16. The process then proceeds to step S13.
[0077] In step S13 , the data represented in step S12 is sent to device 12N, for example as data 16 , so that drive control device A1 of device 12N can use data 16 when controlling actuator A2 . The process then proceeds to step S14 .
[0078] In step S14, device 12N receives data 16 and checks data 16 to determine whether data 16 is trustworthy. If data 16 is provided with certificate 112, device 12N accepts data 16 as trustworthy. Otherwise, device 12N discards data 16 as untrustworthy. For example, device 12N discards data from external device 4 as untrustworthy because external device 4 cannot attach a certificate indicating that machine 10 is trustworthy to its data. The process then proceeds to step S15.
[0079] In step S15, the data 16 represented in step S12 are sent to the device 8, for example as data 41, so that the data 16 can be evaluated in the device 8, for example by means of a display device. The process then proceeds to step S16.
[0080] In step S16, device 8 checks the certificate provided with data 16 using the root certificate of machine 101. Thus, in this example, device 8 checks certificate 112 using root certificate 101 of machine 10. Because certificate 112 is provided with root certificate 101 of machine 10, device 8 accepts data 16 as trustworthy. Data 16 can therefore be further processed. Otherwise, data 16 is discarded, and device 8 outputs a warning message to the user of device 8 and / or to machine complex 3.
[0081] The method then ends.
[0082] According to the second embodiment, a certification level is additionally added for the machine complex 3 and / or system 1. Thus, in the second embodiment, Figure 1 The root certificate 101 , 201 will be a child certificate of the machine complex 3 and / or system 1 .
[0083] Thus, the machine complex 3 and / or the system 1 can also be identified as a “unit”.
[0084] Otherwise, the system 1 according to the present embodiment is constructed in the same manner as described above with respect to the first embodiment.
[0085] All of the above-described embodiments of the system 1, the machine complex 3, the machines 10, 20, and the methods that can be performed therewith and described above can be used individually or in all possible combinations. In particular, all features and / or functions of the above-described embodiments can be combined in any desired manner. Furthermore, the following modifications are particularly conceivable.
[0086] The components shown in the drawings are shown schematically and may differ in exact design from that shown in the drawings as long as their above-described functions are ensured.
[0087] For example, the communication in the system 1, in other words, the exchange of data 15, 16, 17, 25, 26, 27, 30, can be at least partially wired or at least partially wireless. Alternatively or additionally, means for implementing near-field communication and / or far-field communication can be provided, which can be selected during basic parameterization of at least one of the devices 121 to 12N, 221 to 22N, and the radio radius of this communication can be set by means of configurable radio module parameters.
Claims
1. A system (1) comprising at least one machine (10; 20), the at least one machine having at least one device (121 to 12N; 221 to 22N) for exchanging data (15 to 17; 25 to 27) with another device (121 to 12N; 221 to 22N) of the machine (10; 20) or with another machine (20; 10) for jointly solving a task or with a superior device (8), and a certificate device (50) designed to identify the at least one machine (10; 20) with a root certificate (101; 201) and to distribute sub-certificates (111 to 11N; 211 to 21N) to at least one device (121 to 12N; 221 to 22N) of the machine (10), wherein the at least one device (121 to 12N; 221 to 22N) has a private key (141 to 14N), the private key having a public key, wherein the at least one device (121 to 12N; 221 to 22N) is designed to send its public key to the certificate device (50), whereby the certificate device (50) issues the sub-certificate (111 to 11N; 211 to 21N), The certificate device (50) is designed to sign the sub-certificate (111 to 11N; 211 to 21N) using the root certificate (101; 201) of the machine (10; 20) so as to identify the device (121 to 12N; 221 to 22N) as belonging to the machine (10; 20), and the sub-certificate (111 to 11N; 211 to 21N) is uniquely issued for the device (121 to 12N; 221 to 22N), wherein the certificate device (50) is designed to sign the public key of the device (121 to 12N; 221 to 22N) using the root certificate (101; 201) of the machine (10; 20) so as to issue the sub-certificate (111 to 11N; 211 to 21N) of the device (121 to 12N; 221 to 22N).
2. The system (1) according to claim 1, wherein The certificate device (50) has a private key (51) having a public key (52), and wherein the certificate device (50) is designed to use the private key (51) to sign a root certificate (101; 201) of the machine (10; 20).
3. System (1) according to any one of the preceding claims, wherein One of the devices (121 to 12N; 221 to 22N) is a control device, and another of the devices (121 to 12N; 221 to 22N) is a drive device or a tool or a transport device.
4. System (1) according to any one of the preceding claims, wherein Each device (121 to 12N; 221 to 22N) of the machine (10; 20) is designed to allow the exchange of data (15 to 17; 25 to 27; 30; 41; 42) only when the data (15 to 17; 25 to 27; 30; 41; 42) is provided with a subcertificate (111 to 11N; 211 to 21N) signed by the root certificate (101; 201).
5. The system (1) according to claim 4, wherein The data (15 to 17; 25 to 27; 30; 41; 42) are operating state data or control commands of the device (121 to 12N; 221 to 22N).
6. System (1) according to claim 4 or 5, wherein The data (15 to 17; 25 to 27; 30; 41; 42) include parameters that can be used when controlling the drive of at least one element of the machine (10; 20), and / or wherein the data (15 to 17; 25 to 27; 30; 41; 42) include an IP address and / or a name of the device (121 to 12N; 221 to 22N).
7. The system (1) according to any of the preceding claims, further comprising a device (8) arranged externally to the at least one machine (10), wherein the device (8) stores a root certificate (101; 201) of the at least one machine (10), and wherein the device (8) is designed to use the root certificate (101; 201) of the at least one machine (10) to check the trustworthiness of data (15 to 17; 25 to 27; 30; 41; 42) received from the devices (121 to 12N; 221 to 22N) of the at least one machine (10).
8. A machine (10; 20) comprising at least one device (121 to 12N; 221 to 22N) for exchanging data (15 to 17; 25 to 27) with another device (121 to 12N; 221 to 22N) of the machine (10; 20) or with another machine (20; 10) for jointly solving a task or with a superior device (8), and comprising a device designed to communicate data to the at least one device of the machine (10; 20). A certificate device (11; 21) for issuing a sub-certificate (121 to 12N; 221 to 21N) to a device (121 to 12N; 221 to 22N), wherein at least one of the devices (121 to 12N; 221 to 22N) has a private key (141 to 14N), the private key having a public key, wherein the at least one device (121 to 12N; 221 to 22N) is designed to send its public key to the certificate device (50), whereby the certificate device ( 50) issues the sub-certificate (111 to 11N; 211 to 21N), wherein the certificate device (50) is designed to identify the device (121 to 12N; 221 to 22N) as belonging to the machine (10; 20), the sub-certificate (111 to 11N; 211 to 21N) is signed using the root certificate (101; 201) of the machine (10; 20) issued by the superior certificate device (50), and wherein the sub-certificate ( 111 to 11N; 211 to 21N) is uniquely issued for the device (121 to 12N; 221 to 22N), wherein the certificate device (50) is designed to use the root certificate (101; 201) of the machine (10; 20) to sign the public key of the device (121 to 12N; 221 to 22N) to issue a sub-certificate (111 to 11N; 211 to 21N) of the device (121 to 12N; 221 to 22N).
9. A method for configuring a system (1), the system comprising at least one machine (10; 20), the at least one machine comprising at least one device (121 to 12N; 221 to 22N) for exchanging data (15 to 17; 25 to 27) with another device (121 to 12N; 221 to 22N) of the machine (10; 20) or with another machine (20; 10) for jointly solving a task or with a superordinate device (8), and the system comprising a certificate device (50), wherein the at least one device (121 to 12N; 221 to 22N) comprises a private key (141 to 14N) comprising a public key, wherein the method comprises the following steps: identifying said at least one machine (10; 20) with a root certificate (101; 201) using said certificate device (50), receiving the public key of the at least one device (121 to 12N; 221 to 22N) by means of the certificate device (50), using the certificate device (50) to distribute a sub-certificate (111 to 11N; 211 to 21N) to at least one device (121 to 12N; 221 to 22N) of the machine (10; 20), the sub-certificate being signed by the certificate device (50) using the public key, The certificate device (50) signs the sub-certificate (111 to 11N; 211 to 21N) using the root certificate (101; 201) of the machine (10; 20) to identify the device (121 to 12N; 221 to 22N) as belonging to the machine (10; 20), wherein the sub-certificate (121 to 12N; 221 to 21N) is uniquely issued for the device (121 to 12N; 221 to 22N), wherein the certificate device (50) signs the public key of the device (121 to 12N; 221 to 22N) using the root certificate (101; 201) of the machine (10; 20) to issue the sub-certificate (111 to 11N; 211 to 21N) of the device (121 to 12N; 221 to 22N).
10. The method according to claim 9, further comprising the steps of: Using the at least one device (121 to 12N; 221 to 22N), data (15 to 17; 25 to 27) are prepared (S11) to be sent to an apparatus (8) arranged outside the at least one machine (10) and storing a root certificate (101; 201) of the at least one machine (10), and a sub-certificate (111 to 11N; 211 to 21N) is added to the prepared data (15 to 17; 25 to 27), wherein the sub-certificate (111 to 11N; 211 to 21N) is authenticated with the root certificate (101; 201) of the certificate device (11; 21) of the machine (10; 20). The device (121 to 12N; 221 to 22N) is signed to identify the device (121 to 12N; 221 to 22N) as belonging to the machine (10; 20), and wherein the sub-certificate (111 to 11N; 211 to 21N) is uniquely issued for the device (121 to 12N; 221 to 22N), and the device (8) uses the root certificate (101; 201) of the at least one machine (10; 20) to check the authenticity of data (15 to 17; 25 to 27; 30; 41; 42) received from the device (121 to 12N; 221 to 22N) of the at least one machine (10; 20).
Citation Information
Patent Citations
Secure industrial control system
US20150046701A1
Post-manufacture certificate generation
US20190074980A1