Method and apparatus for processing data stored in a storage device

Through random or pseudo-randomly formed verification templates and verification variables, the problem of difficult to identify data changes or manipulation in the storage device in the prior art is solved, and effective detection and identification of data in the storage device is realized, and data integrity and security are improved.

CN113396384BActive Publication Date: 2025-06-06ROBERT BOSCH GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080014206.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-02-14
Filing Date
2020-01-30
Publication Date
2025-06-06
Estimated Expiration
2040-01-30

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify and detect changes or manipulation of data in a storage device, especially in the case of part of the storage area rather than the entire area.

Method used

By a random or pseudo-randomly formed verification template, the verification variables associated with a specific sub-region in the storage device are determined, thereby identifying changes or manipulation of the data. The method includes determining a verification template, forming a verification variable, and comparing the current verification variable with a reference verification variable to determine the integrity of the data.

Benefits of technology

Effective identification and detection of data in the storage device is realized, and the data can be quickly identified in the case of part of the storage area rather than the entire area, thereby improving the detection ability of data integrity and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113396384B_ABST
    Figure CN113396384B_ABST
Patent Text Reader

Abstract

A method for processing data stored in a storage device comprises the following steps: determining a randomly or pseudo-randomly formed verification template, wherein the verification template represents at least one first sub-region of a storage area of ​​the storage device, and forming a verification variable associated with data stored in the at least one first sub-region according to the verification template.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a method for processing data stored in a storage device.

[0002] The present disclosure also relates to an apparatus for processing data stored in a storage device. Summary of the invention

[0003] A preferred embodiment relates to a method for processing data stored in a storage device, comprising the following steps: determining a randomly or pseudo-randomly formed check template, which characterizes at least one first sub-area of ​​a storage area of ​​the storage device, and forming a check variable associated with the data stored in the at least one first sub-area according to the check template. In a further preferred embodiment, the storage device has at least one semiconductor memory component and is, for example, a volatile memory (for example a working memory, i.e. a RAM, a random access memory) or a non-volatile memory, for example a flash memory (for example a NOR flash memory or a NAND flash memory). By means of the randomly or pseudo-randomly formed check template, for example, the storage area on which the formation of the check variable is based can be selected or predetermined unpredictably and individually for a specific storage device. The check variable advantageously characterizes the data content of the first sub-area and enables a change, in particular a manipulation, of the data of the first sub-area to be detected, for example by comparison with a reference check variable.

[0004] In a further particularly preferred embodiment, a device for carrying out a method according to an embodiment can be provided. In a further particularly preferred embodiment, the device has at least one computing device, to which, for example, the above-mentioned storage device can be assigned, in particular for at least temporarily storing at least one computer program and / or data, in particular data to be processed by means of the device. More preferably, a computer program can be stored in the storage device for controlling the operation of the device, in particular for carrying out a method according to an embodiment.

[0005] In another preferred embodiment, the computing device has at least one of the following elements: a microprocessor, a microcontroller, a digital signal processor (DSP), a programmable logic module (e.g., FPGA, field programmable gate array), an ASIC (application-specific integrated circuit). In another preferred embodiment, a combination of these is also conceivable.

[0006] In a further preferred embodiment, in addition to the storage device already described above, at least one further storage device may be assigned to the device, the further storage device having at least one of the following elements: a volatile memory, in particular a working memory (RAM), a non-volatile memory, in particular a flash memory, such as a flash EEPROM or a NOR flash memory or a NAND flash memory. If at least one optional further storage device is provided, a computer program designed to control the operation of the device, in particular to execute the method according to the embodiment, may also be stored in the at least one further storage device as an alternative or in addition.

[0007] In another preferred embodiment, the first sub-area does not correspond to the entire storage area, but corresponds, for example, only to a part of the entire storage area. In other words, in another preferred embodiment, it is correspondingly provided that the verification template does not completely cover the storage area. In another preferred embodiment, the verification template covers, for example, 50% (percentage) or less, in particular 20% or less, of the storage area of ​​the storage device. In another preferred embodiment, a coverage rate greater or less than, for example, 50% is also possible.

[0008] In another preferred embodiment, the first sub-region of the storage area, for example, represents an address region (or a part of the address region) of the storage device. In another preferred embodiment, the first sub-region represents a continuous address region of the storage device, wherein the first sub-region can be described, for example, by a) a starting address and an ending address and / or b) a starting address and a length of the first sub-region and / or c) an ending address and a length of the first sub-region.

[0009] In another preferred embodiment, the first sub-area represents a non-continuous address area of ​​the storage device, wherein correspondingly a plurality of start addresses and / or end addresses and / or length information can be used to describe the first sub-area. As an alternative or supplement to the above information (start address, end address, length), in another preferred embodiment, an address mask, in particular a bit mask or a byte mask, can also be used to define the first sub-area. In another preferred embodiment, within the scope of randomly or pseudo-randomly forming a check template, for example, at least one of the above information (start address, end address, length, bit mask or byte mask) can be randomly and / or pseudo-randomly selected. In another preferred embodiment, preferably multiple, in particular all the information required to describe the first sub-area (start address, end address, length, bit mask or byte mask) is selected or formed randomly and / or pseudo-randomly.

[0010] In a further preferred embodiment, it is provided that the method further comprises: at least temporarily storing the check variable, so that the check variable can be used later, for example as a reference check variable, to determine whether the data of the first sub-area have been manipulated (i.e. intentionally changed) and / or unintentionally changed.

[0011] In a further preferred embodiment, it is provided that the method further comprises: comparing the check variable with a reference check variable for the at least one first sub-area. For example, the reference check variable may have been determined during the manufacture of the memory device and / or the programming of the memory device and / or in some other case, in particular using a method according to an embodiment, and if necessary at least temporarily stored for later use, preferably in a secure memory, so that the reference check variable can be used for the comparison. If the (currently formed) check variable deviates from the corresponding reference check variable, it can be inferred, for example, that the data of the associated sub-area or sub-areas for which the reference check variable has been formed have been (unintentionally) changed or manipulated. If the currently formed check variable is consistent with the corresponding reference check variable, it can be inferred that there has been no (unintentional) change or manipulation of the data in question.

[0012] In another preferred embodiment, it is provided that the determination of the verification template has at least one of the following elements: a) forming the verification template randomly or pseudo-randomly, b) receiving the verification template from an external unit, c) reading the verification template from the storage device and / or another (i.e., different) storage device, d) deriving the verification template from verification template basic data.

[0013] In a further preferred embodiment, the check template can be formed using, for example, a pseudo-random generator or a random generator, which is assigned to a device for carrying out the method according to the embodiment, the device having, for example, a microcontroller or being configured as a microcontroller. In a further preferred embodiment, for example, a noise signal of the device can be used as a random variable for randomly forming the check template, which noise signal can be determined, for example, at an analog input of the device (e.g. a microcontroller).

[0014] In a further preferred embodiment, the randomly or pseudo-randomly formed verification template can also be received from an external unit, such as a computing device of a manufacturing device for a device provided for carrying out the method according to the embodiment. In this case, in a further preferred embodiment, the verification template is transmitted to the device via a secure communication channel.

[0015] In another preferred embodiment, the verification template or at least one verification template can be stored in the storage device and / or in the at least one other (optional) storage device. In another embodiment, multiple verification templates are also stored if necessary, so that a device constructed to perform the method according to the embodiment can read the relevant verification template from the corresponding storage device when necessary.

[0016] In another preferred embodiment, instead of a complete verification template, for example, randomly or pseudo-randomly formed verification template basic data can also be provided and transmitted to the device according to the embodiment and / or stored in at least one storage device, the verification template basic data not representing a complete verification template. In another preferred embodiment, at least one verification template can be formed by the device according to the embodiment based on the verification template basic data, in particular also dynamically (during operation of the device).

[0017] In a further preferred embodiment, at least one verification template or the verification template basic data is stored in a secure storage device or in a secure storage area of ​​the storage device, for example, only the device configured to perform the method according to the embodiment can access the secure storage area, but other (especially external) units cannot. This can be achieved, for example, by allocating a further storage device to the device according to the embodiment, the further storage device is preferably integrated into the device, the further storage device can only be read by the device and has no data interface to external units, for example. In a further preferred embodiment, the further storage device can also be integrated into a hardware security module, for example, which is also configured to perform a cryptographic method or a cryptographic algorithm or at least some parts thereof, which can be used in a further preferred embodiment to form the verification variable, for example.

[0018] In a further preferred embodiment, it is provided that the formation of the verification template comprises the following steps: providing a random or pseudo-random, preferably binary, digital sequence, determining the at least one first sub-area based on at least one first part of the digital sequence, wherein the start address of the first sub-area in the storage area is formed based on the first part of the digital sequence. In a further preferred embodiment, alternatively or additionally, the end address of the first sub-area and / or the length of the first sub-area can also be formed based on the digital sequence, in particular based on a part of the digital sequence that is different from the first part.

[0019] In a further preferred embodiment, for example, the starting address of the first sub-area can be determined based on the first part of the digital sequence, and the length of the first sub-area can be determined based on a second part of the digital sequence that is different from the first part of the digital sequence. If in a further preferred embodiment, further sub-areas are provided to form the verification template, see below, the further sub-areas can preferably be determined in a similar manner.

[0020] In another preferred embodiment, for example, a start address of the first sub-area can be determined according to the first part of the digital sequence, and for example, an end address of the first sub-area can be determined according to the second part of the digital sequence.

[0021] In a further preferred embodiment, determining the start address and / or the end address and / or the length according to the relevant part of the digital sequence also includes multiplying the digital value represented by the relevant part of the digital sequence by a corresponding predeterminable factor (in a further preferred embodiment, different factors can also be selected for different parts of the digital sequence). The use of the corresponding factors advantageously makes it possible to determine a relatively large storage area or storage address from a relatively short part of the digital sequence. In a further preferred embodiment, the corresponding factors can be (pseudo) randomly determined or selected to be constant or variable (for example, depending on at least one operating parameter of the device according to the embodiment). In a further preferred embodiment, as an alternative or in addition to the mentioned use factors, it can also be provided that the previously used values ​​(start address and / or end address and / or length, etc.) are adapted.

[0022] In another preferred embodiment, for example, the start address of the first sub-area may also be interpreted as an address interval (offset) between the first sub-area and a start address of a storage area of ​​the storage device.

[0023] In another preferred embodiment, it is provided that the verification template also characterizes at least one second sub-region, preferably a plurality of other sub-regions, in addition to the first sub-region, wherein the second sub-region, in particular the at least one other sub-region, is preferably not directly adjacent to the first sub-region. This means that the starting address of the second sub-region or another sub-region in the address space of the storage device does not directly follow the end address of the first sub-region or another other sub-region, thereby contributing to the distribution of the sub-regions forming the verification variable on the storage area of ​​the storage device. It is thus advantageously possible to check a larger area of ​​the storage device by forming and evaluating the verification variable without having to consider the amount of data corresponding to the entire storage area of ​​the storage device. On the contrary, it is sufficient to consider a storage area characterized by at least one first sub-region or, if necessary, another optional sub-region. This consideration is based on the fact that, due to the random or pseudo-random formation of the verification template, it is extremely difficult or impossible to manipulate the storage area that is not covered by one or more sub-regions according to the embodiment in the sense of forming the verification variable in a targeted manner without knowing the verification template. Therefore, in another preferred embodiment, it is sufficient that at least one first sub-region or an optional other sub-region does not cover the entire storage area of ​​the storage device. Furthermore, the checking of the memory area is thereby accelerated compared to variants in which all data of the entire memory area are taken into account to form the check variable, since in a particularly preferred embodiment less data than all data of the entire memory area are processed to form the check variable.

[0024] In a further preferred embodiment, it is provided that the method further comprises at least one of the following elements: a) determining the second sub-area based on a second part of the digital sequence that is different from the first part of the digital sequence, wherein in particular a starting address of the second sub-area in the storage area is formed based on the second part of the digital sequence, b) determining the further sub-area based on a corresponding corresponding further part of the digital sequence, which is in particular different from the first part of the digital sequence and / or the second part of the digital sequence, wherein in particular a starting address of the corresponding further sub-area in the storage area is formed based on the corresponding further part of the digital sequence. In a further preferred embodiment, the aspects described above with respect to the determination of the first sub-area can also be applied in a corresponding manner to the second sub-area and / or to at least one further storage area.

[0025] In a further preferred embodiment, it is provided that all sub-areas have the same length. In a further preferred embodiment, in this case, the start address or the end address of the sub-area concerned can be determined pseudo-randomly or randomly, for example.

[0026] In a further preferred embodiment, it is provided that at least some of the sub-areas have different lengths. In a further preferred embodiment, in this case, the length of the sub-area concerned (and, if necessary, the start address and / or the end address) can be determined pseudo-randomly or randomly, for example.

[0027] In a further preferred embodiment, it is provided that the formation of the check variable has at least one of the following elements: a) application of a hash function, in particular a cryptographic hash function, in particular to data stored in at least one first sub-area, b) formation of a checksum based on the data stored in at least one first sub-area, c) formation of a signature, in particular based on a first secret (in particular asymmetric private) key and the data stored in at least one first sub-area (in a further preferred embodiment, the signature can also be formed by a hash value (see element a) above), d) formation of a message authentication code (MAC, message authentication code), in particular based on a second secret (in particular symmetric) key and the data stored in at least one first sub-area.

[0028] In a further preferred embodiment, provision is made that the formation of the test variable comprises the following steps: forming a primary test variable based on data stored in at least one first sub-area, preferably based on data stored in a plurality of sub-areas, and forming a secondary test variable at least based on the primary test variable.

[0029] In a further preferred embodiment, the formation of the primary test variable comprises, for example, the formation of a checksum, in particular a CRC checksum, and / or the evaluation of a hash function, for example an MD5 (Message Digest 5) hash function.

[0030] In a further preferred embodiment, it is provided that the formation of the test variable comprises the following steps: selecting a first number sub-range of the storage area of ​​the storage device, selecting a second number sub-range of the storage area of ​​the storage device, the second number being in particular different from the first number, forming a primary test variable or the primary test variable for the first number sub-range of the storage area, forming a secondary test variable or the secondary test variable for the second number sub-range of the storage area, wherein optionally, a secondary test variable is additionally formed for at least a part of the primary test variable. This advantageously allows different test variables to be formed for different sub-ranges (e.g. also by means of different methods), thereby advantageously allowing, for example, the computational effort and / or the resistance to manipulation to be controlled flexibly, in particular also dynamically. For example, in a further preferred embodiment, it can be provided that the first number sub-range is associated with a test variable that can be determined with a lower computational effort, and the second number sub-range is associated with a second test variable that requires a greater computational effort. By selecting the first number and the second number or the ratio of the first number to the second number, the computational effort and / or the resistance to manipulation can be advantageously controlled.

[0031] Further preferred embodiments relate to the use of the method according to the embodiments before and / or after and / or during at least one of the following operating phases of a computing device, which is configured to access the storage device: a) starting the computing device from a shut-down state, b) starting the computing device from a power-saving state, in particular from a suspend-to-RAM state, c) starting the computing device from a reset state (reset), in particular from a soft reset, d) normal operation.

[0032] Thus, for example, before or during startup ("booting") from a shutdown state or starting or waking up from a suspend to a RAM state, or during normal operation, it is also possible to advantageously check whether the storage content of the storage device has a prescribed content, which can also be referred to as "runtime manipulation detection", i.e., recognition of manipulation during runtime.

[0033] Another preferred embodiment relates to a device for processing data stored in a storage device, wherein the device is constructed to perform the following steps: determining a randomly or pseudo-randomly formed verification template, which characterizes at least one first sub-area of ​​a storage area of ​​the storage device, and forming a verification variable associated with the data stored in the at least one first sub-area based on the verification template.

[0034] In a further preferred embodiment, it is provided that the device is designed to carry out a method according to one embodiment.

[0035] A further preferred embodiment relates to a method for forming a verification template, which characterizes a storage device for storing data or at least a first sub-area of ​​a storage area of ​​the storage device, wherein the verification template is formed randomly or pseudo-randomly. In a further preferred embodiment, it is provided that the method for forming the verification template is performed by the above-mentioned device according to the embodiment. However, in a further preferred embodiment, the method for forming the verification template can (also) be performed by other units, which then provide the formed verification template to, for example, the device according to the embodiment, preferably via a secure channel, for example in a protected manufacturing environment, in which the device according to the embodiment is manufactured.

[0036] Further features, application possibilities and advantages of the invention are apparent from the following description of the embodiments of the invention shown in the figures of the accompanying drawings. All features described or shown here form the subject matter of the invention individually or in any combination, regardless of how they are summarized in the claims or their references, and regardless of how they are expressed or shown in the description or drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In the attached picture:

[0038] Figure 1A Schematically shows a simplified block diagram of a storage device according to a preferred embodiment,

[0039] Figure 1B Schematically shows a simplified block diagram of a storage device according to another preferred embodiment,

[0040] Figure 2A Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0041] Figure 2B Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0042] Figure 3 Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0043] Figure 4A schematically shows a sequence of digits according to a further preferred embodiment,

[0044] Figure 4B Schematically shows the Figure 4A The data content of the table,

[0045] Figure 5A schematically shows a sequence of digits according to a further preferred embodiment,

[0046] Figure 5B Schematically shows the Figure 5A The data content of the table,

[0047] Fig. 6A schematically shows a sequence of digits according to a further preferred embodiment,

[0048] Figure 6B schematically shows a multiplier arrangement according to a further preferred embodiment,

[0049] Figure 6C Schematically shows the Fig. 6A , 6B The data content of the table,

[0050] Fig. 7A Schematically shows a simplified block diagram of a storage device according to another preferred embodiment,

[0051] Figure 7B Schematically shows a simplified block diagram of a storage device according to another preferred embodiment,

[0052] Fig. 8A Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0053] Figure 8B Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0054] Fig. 9 Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0055] Fig.10 Schematically shows a simplified flow chart of a method according to a further preferred embodiment,

[0056] Fig.11A , 11B , 11C schematically show simplified flow charts of methods according to other preferred embodiments, respectively,

[0057] Fig.12 schematically shows a simplified block diagram of a device according to a further preferred embodiment, and

[0058] Fig.13 A simplified block diagram according to a further preferred embodiment is schematically shown. DETAILED DESCRIPTION

[0059] Figure 1ASchematically shows a simplified block diagram of a memory device 100 according to a preferred embodiment. The memory device 100 has, for example, at least one semiconductor memory element and is, for example, a volatile memory (e.g., a working memory, RAM, random access memory) or a non-volatile memory, such as a flash memory. A memory area 110 is defined between a start address SA and an end address EA.

[0060] Another preferred embodiment relates to a method for processing data D stored in a storage device 100, comprising the following steps, see also Figure 2A Simplified flow chart in: Determine 200 a randomly or pseudo-randomly formed check template PM, which characterizes a storage area of ​​the storage device 100 or at least a first sub-area 110_1 of the storage area 110 ( Figure 1A ), based on the verification template PM, 202 is formed ( Figure 2A ) a test variable PG associated with the data D stored in at least one first sub-region 110_1. By means of a randomly or pseudo-randomly formed test template PM, the memory region (or the data stored therein) on which the test variable PG is formed can be selected unpredictably and individually for, for example, a specific memory device 100. The test variable PG advantageously characterizes the data content of the first sub-region 110_1 and enables a change, in particular a manipulation, of the data of the first sub-region to be detected, for example by comparison with a reference test variable.

[0061] In a further preferred embodiment, the check variable (whose determination will be discussed in more detail below) may represent a (unique) digital value, such as a (CRC) checksum value when the check variable is determined by means of a checksum method (e.g., CRC, cyclic redundancy check), or a hash value when the check variable is determined by means of a hash value method. However, in a further preferred embodiment, the check variable may also represent an n-tuple of corresponding individual values, n=2, 3, 4, ... or other forms of values, such as vectors and / or matrices, etc.

[0062] In a further preferred embodiment, a device 300 for performing the method according to the embodiment is provided, see Fig.12 A simplified block diagram of the .

[0063] The device 300 preferably has at least one computing device 302, to which the above-described storage device 100 can be assigned, for example, in particular for at least temporarily storing at least one computer program PRG and / or data D ( Figure 1A), in particular data to be processed by means of the device 300. More preferably, a computer program PRG can be stored in the storage device 100 for controlling the operation of the device 300, in particular for executing the method according to the embodiment. In another preferred embodiment, a plurality of computer programs ( Fig.12 ), for example, a boot loader that can control the startup process of the device or call another computer program, and the other computer program, which is, for example, an operating system and / or an application.

[0064] In another preferred embodiment, the computing device 302 has at least one of the following elements: a microprocessor, a microcontroller, a digital signal processor (DSP), a programmable logic module (such as FPGA, field programmable gate array), an ASIC (application-specific integrated circuit), a hardware circuit. In another preferred embodiment, a combination of these is also conceivable.

[0065] In another preferred embodiment, in addition to the storage device 100 described above, the device 300 ( Fig.12 ) is assigned at least one further storage device 304, which has at least one of the following elements: a volatile memory 304a, in particular a working memory (RAM), a non-volatile memory 304b, in particular a flash memory, for example a flash EEPROM. If at least one optional further storage device 304 is provided, a computer program PRG′ which is designed to control the operation of the device 300, in particular to execute a method according to an embodiment, can also be stored alternatively or additionally in the at least one further storage device 304. For example, one or more test templates PM and / or test variables PG, in particular reference test variables, can also be stored at least temporarily in the storage device 304.

[0066] In another preferred embodiment, see Figure 1A , the first sub-area 110_1 does not correspond to the entire storage area 110, but corresponds to, for example, only a part of the entire storage area 110. In other words, in another preferred embodiment, it is correspondingly provided that the verification template PM ( Figure 2A ) does not completely cover the storage area 110. In another preferred embodiment, the verification template covers, for example, 50% or less (or more), in particular 20% or less, of the storage area 110 of the storage device 100.

[0067] In a further preferred embodiment, the first sub-area 110_1 of the memory area 110 may correspond, for example, to at least one address area AB1 (in particular not the entire theoretically possible or physically existing address area) of the memory device 100, wherein the at least one address area is, for example, located between a start address SA1 and an end address EA1. In a further preferred embodiment, the first sub-area 110_1 thus represents a continuous address area AB1 of the memory device 100, wherein the first sub-area 110_1 may, for example, be described by a) the already mentioned start address SA1 and the end address EA1 and / or b) the start address SA1 and the length (not shown) of the first sub-area 110_1 and / or c) the end address EA1 and the length of the first sub-area 110_1.

[0068] In another preferred embodiment (not shown), the first sub-region 110_1 represents a non-contiguous address region of the storage device 100 , wherein correspondingly a plurality of start addresses and / or end addresses and / or length information may be used to describe the first sub-region.

[0069] As an alternative or supplement to the above information (start address, end address, length), in another preferred embodiment, an address mask, in particular a bit mask or a byte mask or a word mask or a block mask (with blocks, each block having, for example, k bytes, k=2, 3, 4, ...) can be used to define the first sub-area 110_1. In another preferred embodiment, within the scope of randomly or pseudo-randomly forming the check template PM, for example, at least one of the above information (start address, end address, length, bit mask or byte mask or word mask or block mask) can be randomly and / or pseudo-randomly selected. In another preferred embodiment, preferably a plurality of, in particular all, the information required to describe the first sub-area (start address, end address, length, bit mask or byte mask or word mask or block mask) is selected or formed randomly and / or pseudo-randomly.

[0070] For example, both the start address SA1 and the end address EA1 may be (pseudo) randomly determined for the sub-region 110_1 to form a verification template.

[0071] In another preferred embodiment, it is provided that Figure 2A The method further comprises: at least temporarily storing 204 the test variable PG. The test variable PG can thus be used later, for example as a reference test variable RPG ( Fig.12 ), for example, can be used to determine whether the data of the first sub-region 110_1 has been manipulated (ie intentionally changed) and / or unintentionally changed in the meantime (since the check variable was formed).

[0072] In another preferred embodiment, it is provided that the method further comprises: converting the currently formed check variable PG'( Figure 2A ) is compared 205 with reference test variables RPG of at least one first sub-region 110_1 (e.g. obtained by the preceding steps 202, 204). For example, the reference test variables RPG may have been determined during the production of the memory device 100 and / or the programming of the memory device 100 and / or in some other case, in particular using a method according to an embodiment (e.g. steps 200, 202) and, if necessary, at least temporarily stored for later use (see step 204), preferably in a secure memory, so that they are available for comparison 205. If the (currently formed) test variable PG' deviates from the corresponding reference test variable RPG, it can be inferred, for example, that the data of the associated one or more sub-regions 110_1, for which the reference test variable RPG has been formed, have been (unintentionally) changed or manipulated. If the currently formed test variable PG' is consistent with the corresponding reference test variable RPG, it can be inferred that there has been no (unintentional) change or manipulation of the data concerned.

[0073] In a further preferred embodiment, it is provided that when producing the storage device 100 and / or programming the storage device 100 and / or in other cases, the verification template PM is determined, in particular using a method according to an embodiment (e.g. step 200) and, if necessary, is at least temporarily stored for later use, preferably in a secure memory, so that it can be used in the future.

[0074] In a further preferred embodiment, it is provided that the determination 200 of the verification template PM ( Figure 2A ) has at least one of the following elements (see Figure 2B ): a) randomly or pseudo-randomly forming the verification template 200a, b) from an external unit 400 ( Fig.12 ) receiving 200b the verification template PM, for example by means of the data interface 306, in particular by means of a secure communication channel and / or in a secure (production) environment, c) reading 200c the verification template from the storage device 100 and / or another (i.e., different) storage device 304, d) deriving 200d the verification template from the verification template basic data.

[0075] In another preferred embodiment, for example, a pseudo-random generator or a random generator may be used to form the verification template, and the pseudo-random generator or the random generator is assigned to the device 300 ( Fig.12 ), the device has, for example, a microcontroller or is configured as a microcontroller. In another preferred embodiment, for example, a noise signal RS of the device 300 can be used as a random variable for randomly forming the verification template, and the noise signal RS can be determined, for example, at the analog input 308 of the device 300.

[0076] In another preferred embodiment, the external unit 400 (see Fig.12 ) receives a randomly or pseudo-randomly formed verification template PM, the external unit being, for example, a computing device of a manufacturing device for the device 300. In this case, in a further preferred embodiment, the verification template PM is transmitted to the device 300 via a secure communication channel and a data interface 306. The verification template PM received in this way can also be stored, for example, in a further storage device 304. In a further preferred embodiment, the verification template PM can be determined or formed by means of an external unit 400 using a (pseudo) random generator (for example based on a noise signal).

[0077] In another preferred embodiment, as already mentioned above, a verification template PM or at least one verification template can be stored in the storage device 100 and / or in the at least one other (optional) storage device 304, and in another embodiment, multiple verification templates are also possible, so that the device 300 constructed to perform the method according to the embodiment can read the verification template PM concerned from the corresponding storage device 100, 304 when necessary.

[0078] In a further preferred embodiment, the further storage device 304 is a storage device which is integrated in the device 300 and which in particular cannot be accessed by external units. Fig.12 ) is assigned to the device 300, but is arranged outside the device 300 if necessary, for example in such a way that the data interface 306' (address bus and / or data bus and / or serial communication bus etc.) is accessible from the outside. In these embodiments, it is particularly advantageous if at least one check template PM or a plurality of check templates or all check templates that can be used for the device 300 are arranged in the integrated storage device 304, so that the manipulation of the check template PM is more difficult. In this way, the calculation unit 302 can effectively access the check template PM stored, for example, in the volatile memory 304a of the integrated storage device 304, in particular for applying the method according to the embodiment to at least one storage area of ​​the storage device 100.

[0079] In another preferred embodiment, instead of the complete verification template PM, for example, randomly or pseudo-randomly formed verification template basic data PMB ( Fig.12), which does not yet represent a complete verification template and can be transmitted to the device 300 according to the embodiment and / or stored in at least one of the storage devices 100, 304 (preferably again in the integrated storage device 304). In a further preferred embodiment, at least one verification template PM can be formed by the device 300 based on the verification template base data PMB, in particular also dynamically (during the runtime of the device 300). Here, for example, one or more counter values ​​or other operating variables of the computing device 302 can be used by the computing device 302 to change the verification template base data PMB in a desired manner to obtain an unpredictable verification template. In a further preferred embodiment, the formation of the verification template based on the verification template base data PMB can, for example, advantageously save computing time resources of the computing device 302 compared to the complete (new) formation of the complete verification template PM.

[0080] In a further preferred embodiment, a hardware security module 307 or a cryptographic module or the like having a separate, protected memory for storing at least one verification template PMa is assigned to the device 300. Particularly preferably, only a computing device 302 configured to execute the method according to the embodiment can access the verification template PMa stored in the hardware security module 307.

[0081] In another preferred embodiment, it is provided that the hardware security module 307 or the cryptographic module at least partially or completely executes the method according to the embodiment, such as steps 200, 202, etc. In another preferred embodiment, it is provided that the hardware security module 307 or the cryptographic module manages (in particular stores and / or forms) the check template PMa, and / or determines the check variable PG, and / or compares the check variable PG with the reference check variable RPG. In another preferred embodiment, it is provided that the hardware security module 307 or the cryptographic module is constructed to output the comparison result of the values ​​PG, RPG to another unit, such as the computing device 302.

[0082] In another preferred embodiment (see Figure 3 The simplified flowchart of Fig.12 ) comprises the following steps: providing 210 ( Figure 3 ) a random or pseudo-random, preferably binary, digital sequence ZF, see Figure 4A , according to at least one first part ZF1 of the digital sequence ZF ( Figure 4A ) confirm 212 ( Figure 3 ) at least one first sub-region 110_1 ( Figure 1A ), where in particular the first part ZF1 of the numerical sequence ZF ( Figure 4A ) forms a start address SA1 of the first sub-region 110_1 in the storage region 110 ( Figure 1A). In the present case, the random number sequence ZF is generated by the device 300 ( Fig.12 ) is formed by a random generator RNG, and the first part of the digital sequence ZF1 is Figure 4A In the example, the three bits "111" are represented by the reference symbol ZF1. Figure 4B Table T1 shows in the first column S1 by way of example the identifiers of the start addresses SA1, SA2, SA3, ... of various sub-areas according to further preferred embodiments. For example, in these embodiments, the identifiers according to Figure 1B The verification templates of a total of three sub-areas 110_1, 110_2, and 110_3 of the storage area 110a, and the corresponding starting addresses SA1, SA2, and SA3 of these sub-areas are all represented in the first column S1 of the table T1.

[0083] Figure 4B The second column S2 of the table T1 contains in rows Z1, Z2, Z3, ... Figure 4A For example, in the table cell corresponding to the first row Z1 and the second column S2 ("Z1; S2"), the digital value 0111b (binary) or 0x7 (hexadecimal) assigned to the first part ZF1 of the random sequence ZF is assigned, which indicates that the first sub-area 110_1 associated with the first row Z1 and the storage area 110a ( Figure 1B ), the reference address being, for example, the start address SA of the storage area 110a or, if necessary, the end address of a preceding sub-area. In the present case, therefore, the first sub-area 110_1 is at a distance of, by way of example, 0111b (binary) bytes, i.e., seven bytes in decimal, from the start address SA2 of the storage area 110_2. For the start address SA2 of the second sub-area 110_2, the address interval or offset (in the present case relative to the end address EA1 of the first sub-area 110_1) is 0x1, i.e., 1 byte, as derived from row Z2 and column S2 of table T1. It should be noted that according to Figure 1B The illustrations are not drawn to scale.

[0084] In a further preferred embodiment, the length of all sub-areas 110_1, 110_2, 110_3 represented by the check template is constant, for example fixedly predetermined or configurable (parameterized). Therefore, by adding the constant length to the corresponding start address SA1, SA2, SA3, the corresponding end address EA1, EA2, EA3 of the sub-area 110_1, 110_2, 110_3 concerned can be determined particularly efficiently.

[0085] In a further preferred embodiment, the start address SA1 of the first sub-area 110_1 under consideration can also be determined as a function of the assigned portion ZF1 of the random sequence ZF in such a way that the value of the portion of the random sequence ZF1 is multiplied by a constant or configurable first factor F1. For example, in a further preferred embodiment, the first factor F1 can be 32, i.e., F1=32. In this case, based on an exemplary predetermined value of the first portion ZF1 of the random sequence ZF, the start address SA1 of the first sub-area 110_1 is determined by multiplying the value of the first portion ZF1 by the first factor F1, i.e., in the present case, SA1=7 (corresponding to 111b)*F1=7*32=224 (bytes). Therefore, in the present embodiment, the first sub-area 110_1 starts at a start address SA1=224 (i.e., for example, SA+224). Accordingly, the start address SA2 of the second sub-region 110_2 can be determined as follows: SA2=001b*32=32, wherein the second start address SA2 indicates, for example, the distance between the start of the second sub-region 110_2 and the end address EA1 of the previous first sub-region 110_1. Figure 4B Table T1 , column S2 , row Z3 (also using factor F1 ) yields the value 000b in the present case. This means that the start address SA3 of the third sub-area 110_3 directly follows the end address EA2 of the preceding second sub-area 110_2 .

[0086] In a further preferred embodiment, the first factor F1 can also be selected pseudo-randomly or randomly, but a lower limit and / or an upper limit are advantageously predefined for the first factor F1, in particular depending on the size of the entire storage area 110a and / or on the number of subareas on which the relevant check template is based. Alternatively, in a further preferred embodiment, lower limits and upper limits can also be predefined for parts ZF1, 2, 3 of the random sequence ZF. For example, if a part of the digital sequence (e.g. ZF1) falls below or exceeds a lower limit or an upper limit, this part of the digital sequence (e.g. ZF1) is not used to form the check template, but the following digital part (e.g. ZF2) is used instead, and so on.

[0087] In a further preferred embodiment, a predefinable number of sub-regions can be predefined for the formation of the check template PM, thereby advantageously providing a further degree of freedom for controlling the formation of the check template PM.

[0088] In another preferred embodiment, alternatively or additionally, the number sequence ZF ( Figure 4A ), in particular forming, for example, the end address EA1 of the first sub-area 110_1 and / or the length of the first sub-area 110_1 based on a part of the digital sequence that differs from the mentioned first part ZF1.

[0089] In another preferred embodiment, see Figure 5A The random sequence ZF' is based on Figure 5B Table T2, for example, can determine the start address SA1 of the first sub-region 110_1 according to the first part ZF1 of the digital sequence ZF', and determine the length of the first sub-region 110_1 according to the second part ZF2 of the digital sequence ZF' which is different from the first part ZF1 of the digital sequence ZF' ( Figure 1B ). If in another preferred embodiment, another sub-region 110_2, 110_3, ... is provided to form the verification template, the another sub-region can be determined in a similar manner in another preferred embodiment.

[0090] In accordance with Figure 5B In the table T2 of FIG. 1 , the first row Z1 is assigned, by way of example, to the first storage area of ​​the check template, the second row Z2 to the second storage area, etc. The random value generated by the first part ZF1 of the digital sequence ZF' is entered in column S2, row Z1 and, in a further preferred embodiment, characterizes the size or length of the first sub-area 110_1. The further random value generated by the second part ZF2 of the digital sequence ZF' is entered in column S3, row Z1 and, in a further preferred embodiment, characterizes the address interval (offset) between the first sub-area 110_1 and the subsequent second sub-area 110_2, i.e., for example, the difference between the start address SA2 of the second sub-area and the end address EA1 of the first sub-area. The third random value generated by the third part ZF3 of the digital sequence ZF' is entered in column S2, row Z2 and characterizes the length of the second sub-area 110_2. A fourth random value generated from the fourth part ZF4 of the digital sequence ZF′ is entered in column S3 , row Z2 and characterizes the address interval (offset) between the second subregion 110_2 and the subsequent third subregion, and so on.

[0091] In a further preferred embodiment, the start address can be determined from the first part ZF1 of the digital sequence ZF′ and the end address of, for example, the first sub-region and / or at least one further sub-region can be determined from the second part ZF2 of the digital sequence ZF′.

[0092] In a further preferred embodiment, determining the start address and / or end address and / or length of at least one sub-area based on the relevant part of the digital sequence can also include multiplying the digital value represented by the relevant part of the digital sequence by a corresponding predefined factor (e.g., similar to the first factor described above, wherein in a further preferred embodiment, the corresponding predefined factor can also be selected differently for different parts of the digital sequence). The use of the corresponding factor advantageously makes it possible to determine a larger storage area or storage address and / or a larger offset between the corresponding storage areas from a shorter part ZF1, ZF2, ... of the digital sequence ZF, ZF' (if, for example, the factor is multiplied by a part of the random sequence that encodes the offset). In a further preferred embodiment, the starting address and / or end address and / or length of the at least one sub-area can also be (pseudo) randomly determined or constantly or variably (e.g., based on the device 300 ( Fig.12 ) at least one operating parameter) select the corresponding factor.

[0093] In another preferred embodiment, for example, the start address SA1 of the first sub-region 110_1 may also be interpreted as the first sub-region 110_1 and the storage region 110a ( Figure 1B )'s starting address SA's address interval (offset).

[0094] In a further preferred embodiment, it is provided that the check template also represents at least one second sub-region 110_2 ( Figure 1B ), preferably a plurality of further sub-areas, wherein preferably the second sub-area 110_2, in particular at least one further sub-area, does not directly adjoin the first sub-area 110_1. This means that the start address SA2 of the second or further sub-area in the address space of the memory device does not directly follow the end address EA1 of the first sub-area 110_1 or of another further (previous) sub-area, thereby contributing to the formation of the check variable PG ( Figure 2A ) are distributed in the storage area 110a ( Figure 1B ). This advantageously makes it possible to check a larger area of ​​the storage device 100 ( Figure 1A), without having to take into account for this the amount of data corresponding to the entire storage area 110, 110a of the storage device 100. Instead, it is sufficient to take into account a storage area characterized by at least one first sub-area 110_1 or, if necessary, further optional sub-areas 110_2, 110_3. This consideration is based on the fact that, due to the random or pseudo-random formation of the check template PM, it is extremely difficult or impossible to manipulate in a targeted manner the storage area or parts of the storage area that are not covered by one or more sub-areas 110_1, 110_2, ... according to the embodiment in the sense of forming a check variable, in particular in the case of such further preferred embodiments, in which the check template PM is newly formed repeatedly, in particular periodically. Therefore, in further preferred embodiments, it is sufficient that at least one first sub-area 110_1 or the optional further sub-areas 110_2, 110_3 do not cover the entire storage area 110, 110a of the storage device 100. Furthermore, this speeds up the checking of memory areas 110 , 110 a compared to variants in which all data of the entire memory area are taken into account to form the check variable, since in a particularly preferred embodiment less data than all data of the entire memory area are processed to form the check variable.

[0095] In another preferred embodiment, it is provided that the method further comprises (see according to Figure 3 Flow chart of): a) According to the digital sequence ZF, ZF' ( Figure 4A , 5A) is different from the first part ZF1 of the digital sequence ZF, ZF', and the second sub-area 110_2 is determined 214a, wherein in particular the second part ZF2 of the digital sequence ZF, ZF' forms the start address SA2 of the second sub-area 110_2 in the storage area 110, 110a. Figure 4A , 4B , 5A, 5B describe other preferred embodiments related to this.

[0096] In another preferred embodiment, it is provided that the method further comprises (see according to Figure 3 ): Determine 214b further sub-areas 110_3, ... according to the corresponding corresponding further parts ZF3, ZF4 of the digital sequence ZF', the corresponding corresponding further parts are in particular different from the first part ZF1 of the digital sequence ZF' and / or the second part ZF2 of the digital sequence ZF', wherein in particular the start address SA3 of the corresponding further sub-area 110_3 in the storage area 110a is formed according to the corresponding further part ZF3 of the digital sequence ZF'. In a further preferred embodiment, the aspects described above with respect to the determination of the first sub-area 110_1 can also be applied in a corresponding manner to the second sub-area and / or to at least one further storage area.

[0097] In another preferred embodiment - as mentioned above Figure 1B As already mentioned, it is provided that at least two, preferably all, sub-areas 110_1, 110_2, 110_3 have the same length L1. In a further preferred embodiment, in this case, for example, the start address or the end address of the sub-area concerned can be determined pseudo-randomly or randomly. In a further preferred embodiment, it is also conceivable to (pseudo)randomly determine a constant length L1 and then use it to define the different sub-areas.

[0098] In a further preferred embodiment, it is provided that at least some of the sub-areas have different lengths. In a further preferred embodiment, in this case, the length of the sub-area concerned (and, if necessary, the start address and / or the end address) can be determined pseudo-randomly or randomly, for example.

[0099] In a further preferred embodiment, it is provided that the length L1 ( Figure 1B ).

[0100] Reference below Fig. 6A , 6B , 6C describe another preferred embodiment. Fig. 6A A random sequence ZF is shown which is divided, in the present case, by way of example, into four different parts ZF1', . . . , ZF4', wherein each of these parts has, by way of example, a length of 4 bits. Figure 6B The multiplier arrangement of FIG. 1 converts or scales the corresponding binary values ​​of the different parts ZF1', ..., ZF4' into different output value ranges by means of the first factor F1 and the second factor F2. For example, the value of the first part ZF1' assigned to the random sequence ZF is multiplied by the first factor F1 by means of the first multiplier m1, wherein the output value ZF1" is obtained as the product, which in the present case is also based on Figure 6C In another preferred embodiment, the output value ZF1 ″ is used to set the size or length L1 of the first sub-region 110_1. In a similar manner, by means of the second multiplier m2 ( Figure 6B ) determines a further output value ZF3'' which is entered in column S2, row Z2 and is used, by way of example, to set the size or length of the second sub-region. The output values ​​ZF2", ZF4" determined in column S3, rows Z1, Z2 can be determined by means of further multipliers m3, m4 from further parts ZF2', ZF4' of the random sequence ZF and the second factor F2, such as from Figure 6Band defines, for example, an address interval or offset from a sub-region corresponding to a corresponding row Z1, Z2 to the end of the respective preceding sub-region or the start address SA of the storage region 110a ( Figure 1B ).

[0101] In other preferred embodiments, the second factor F2 may also be constant, for example configurable, or may also be (pseudo) randomly generated.

[0102] Fig. 7A A simplified block diagram of a memory area 110b of a memory device according to a further preferred embodiment is schematically shown. The memory area 110b of the memory device, which is defined by a start address SA and an end address EA, is subdivided in the present case into a plurality of different sub-areas 110_1, 110_2, 110_3a, 110_3b, 110_3c, 110_3d (collectively referred to as a plurality of further sub-areas), 110_4a_, 110_4c, 110_4d, 110_4e (collectively referred to as a plurality of further sub-areas). In this case, the sub-areas 110_1, 110_2, 110_3a, 110_3b, 110_3c, 110_3d form a verification template PM according to an embodiment ( Fig.12 ), which is formed, for example, (pseudo) randomly according to the embodiments described above by way of example. Each of the sub-areas 110_1, 110_2, 110_3a, 110_3b, 110_3c, 110_3d can be characterized here by way of example by a corresponding start address and a corresponding end address, which are not shown for reasons of clarity. The other sub-areas 110_4a, 110_4b, 110_4c, 110_4d, 110_4e are not components of the check template PM and are therefore not used as a basis for forming the check variable PG in further preferred embodiments (see Figure 2A Step 202). Fig. 7A In the configuration shown by way of example in FIG. 1 , all sub-regions that together form the verification template exemplarily have the same length. Fig. 7A It can be seen that the check template represented or formed by the sub-regions 110_1, 110_2, 110_3a, 110_3b, 110_3c, 110_3d covers the entire storage area 110b substantially uniformly, so that the entire storage area 110b can be reliably checked using the check variable PG determined according to the check template PM according to the embodiment. Since the check template PM contains random elements, an attacker cannot know and cannot predict the check template PM or its parts, that is, in particular the number and / or position and / or size of the individual sub-regions, so that it is extremely difficult or impossible to form the check variable PG on this basis, and therefore, if necessary, a manipulation aimed at simulating the check variable while changing the data of the storage area 110b is extremely difficult or impossible.

[0103] Figure 7B Schematically shows a simplified block diagram of a storage area 110c of a storage device 100 according to another preferred embodiment. Figure 7B As can be seen in FIG. 1 , the sub-areas 110_1 , 110_2 , 110_3a , 110_3b , 110_3c , 110_3d associated with the verification template PM have different lengths. In another preferred embodiment, these lengths can be determined randomly, in particular according to a random sequence ZF, ZF′. Figure 7B Reference numerals 110_4a and 110_4b are used to symbolically represent some sub-regions that are not covered by the verification template PM in the current situation.

[0104] Reference above Fig. 7A , 7B The storage area and its sub-areas shown (not to scale or highly schematic) and the division of the sub-areas in response to the association with forming the verification template are purely exemplary. In other preferred embodiments, other numbers of corresponding local areas and / or other arrangements of corresponding sub-areas in the storage areas 110b, 110c may also be adopted.

[0105] In a further preferred embodiment, provision is made for the formation 202 of the test variable PG ( Figure 2A ) has at least one of the following elements (see also Fig. 8A 2 ): a) applying 220 a hash function, in particular a cryptographic hash function, in particular to data D stored in at least one first sub-region 110_1 ( Figure 1A ), b) forming 222 a checksum based on the data D stored in the at least one first sub-area 110_1, c) forming 224 a signature, in particular based on a first secret (or private) key and the data stored in the at least one first sub-area 110_1 (and / or a hash value of the data stored in the first sub-area 110_1, from steps 220 and 224)), d) forming 226 a message authentication code (MAC), in particular a CMAC (cipher-based MAC), in particular based on a second secret (or symmetric) key and the data D stored in the at least one first sub-area 110_1.

[0106] In a further preferred embodiment, applying 220 a hash function may include, for example, applying a hash function of the SHA-2 type, such as SHA-224 and / or SHA-256 and / or SHA-384 and / or SHA-512 and / or other, preferably cryptographic (i.e., collision-resistant) hash functions. This provides a particularly high level of resistance to manipulation.

[0107] In a further preferred embodiment, the formation 222 of the checksum can in particular include the formation of a CRC checksum and / or a hash function or the like, wherein the hash function in particular does not have to be collision-resistant. As a result, the check variable PG can be formed particularly efficiently, and in a further preferred embodiment, at least in some implementations of the device 300 or other devices configured to perform the method according to an embodiment, the check variable PG requires fewer computing resources than using a cryptographic hash function.

[0108] In a further preferred embodiment, it is also possible to select dynamically, i.e. during the runtime of the device 300, which of the above methods is used to form the check variable PG. This makes it possible to flexibly utilize the available degrees of freedom to form the check variable PG, for example to adapt predefined boundary conditions (such as computing time resources and / or memory of the device 300) or security requirements. In a further preferred embodiment, it is also possible to sometimes use the first method to form the check variable PG, such as a cryptographic hash function, such as SHA-256, and sometimes use a CRC checksum that is relatively easy to evaluate to form the check variable PG. According to a further preferred embodiment, it is advantageous that corresponding reference check variables RPG ( Figure 2A ).

[0109] In a further preferred embodiment, it is provided that the formation of the test variable PG comprises the following steps (see Figure 8B Simplified flow chart of: according to the data D stored in at least one first sub-region 110_1 ( Figure 1A ), preferably according to the data stored in the plurality of sub-areas 110_1, 110_2 ( Figure 1B ) forms 228 a primary test variable PG1, and at least forms 229 ( Figure 8B ) Secondary check variable PG2.

[0110] In a further preferred embodiment, forming 228 the primary check variable PG1 comprises, for example, forming a checksum, in particular a CRC checksum and / or evaluating a preferably non-cryptographic hash function, for example an MD5 (Message Digest 5) hash function. As a result, the primary check variable PG1 can be determined efficiently with low resource expenditure, and, in order to increase the resistance to manipulation, a secondary check variable PG2 can be formed, for example, using a cryptographic hash function (for example SHA-256), wherein the formation is preferably carried out based on the primary check variable PG1. In a further preferred embodiment, the secondary check variable PG2 can also be formed based on the primary check variable PG1 and at least one sub-region 110_1 of the storage area 110 associated with the check template PM. As a result, in a further preferred embodiment, it is possible to form the check variable, namely the secondary check variable PG2, at least partially in two stages, which formation, in addition to the primary check variable PG1, optionally also directly takes into account the data of the sub-region 110_1 associated with the check template PM. In a further preferred embodiment, the generation of the primary test variable PG1 can also be interpreted as a "data compression" and / or "data reduction" of the input data for forming the primary test variable PG1, because in a further preferred embodiment, the primary test variable PG1 itself is much smaller than the input data taken into account for determining the primary test variable. The amount of data on which the formation of the secondary test variable is based can thereby be advantageously reduced.

[0111] In a further preferred embodiment, provision is made for the formation 202 of the test variable PG ( Figure 2A ) includes the following steps (see Fig. 9 Simplified flow chart of ): Select 230 the storage area 110 of the storage device 100 ( Figure 1A), a second number of sub-areas of the storage area 110 of the storage device 100 is selected 232, the second number being different in particular from the first number, a primary test variable or primary test variable PG1 is formed 234a for the first number of sub-areas of the storage area 110, and a secondary test variable or secondary test variable PG2 is formed 236a for the second number of sub-areas of the storage area, wherein the secondary test variable PG2 is optionally additionally formed 236 for at least a portion of the primary test variable PG1. This advantageously allows different test variables to be formed for different sub-areas (e.g. also by means of different methods), thereby advantageously making it possible, for example, to control the computational effort and / or the resistance to manipulation flexibly, in particular also dynamically (i.e. during the operating time of the device 300). For example, in a further preferred embodiment, it can be provided that the first number of sub-areas is associated with a first test variable PG1 which can be determined in a less computationally demanding manner, and the second number of sub-areas is associated with a second test variable PG2 which requires a greater computational effort (e.g. SHA-256). By selecting the first number and the second number or the ratio of the first number to the second number, the computational complexity and / or the resistance to manipulation of the entire method can be advantageously controlled and, for example, in a further preferred embodiment, the current operating state of the device 300 or the utilization of the computing device 302 can be adapted. Particularly preferably, the data for forming the first test variable PG1 and for forming the second test variable PG2 are associated, for example, with a test template PM.

[0112] Fig.10 A simplified flow chart of a method according to a further preferred embodiment is schematically shown. In the present case, five storage areas 110a, 110b, 110c, 110d, 110e are considered in total, for example, which respectively form the storage device 100 ( Figure 1A , 12 ). Each of the five storage areas 110a, 110b, 110c, 110d, 110e is assigned its own reference check variable RPGa, RPGb, RPGc, RPGd, RPGe, which is determined, for example, during the manufacture of the storage device 100 according to the above-described embodiment and stored, for example, in the hardware security module 307 (see also Fig.12 ). In a further preferred embodiment, the associated check templates for determining the respective reference check variables RPGa, RPGb, RPGc, RPGd, RPGe can also be stored in the hardware security module 307. In a further preferred embodiment, the check templates can also be (particularly completely) formed or stored in the hardware security module 307, for example, and the hardware security module 307 can also be configured to determine (one or more) check variables.

[0113] In the present case, the first memory area 110a contains, by way of example, a boot loader, i.e., a program that controls the startup process of the computing device 302 or the device 300 and, for example, specifies which further computer programs are to be executed after the startup process. The second memory area 110b represents computer programs and / or data of an operating system of the device 300 or its computing device 302, and the further memory areas 110c, 110d, 110e represent, for example, application programs of the device 300.

[0114] At the beginning of the boot process, first in step s1, the (current) check variable of the storage area 110a where the boot loader is located is determined, and then the check variable is compared with the reference check variable RPGa. If they are consistent, it can be concluded that the boot loader is intact, and then the boot loader is started in step s2. Then in step s3, the boot loader forms the current check variable for the next storage area 110b containing the operating system, and compares the currently formed check variable with the corresponding reference check variable RPGb. If the currently formed check variable is consistent with the reference check variable RPGb for the storage area 110b, it is concluded that the computer program and / or data of the operating system are intact, that is, they have not been manipulated, and the corresponding computer program of the operating system is executed in step s4. Subsequently, with the help of steps s5, s6, s7, s8, sn, sn+1, a similar process is carried out for the other storage areas 110c, 110d, 110e respectively using the correspondingly assigned reference check variables RPGc, RPGd, RPGe.

[0115] Reference above Fig.10 In the described embodiment, the storage area 110a containing the boot loader has preferably been completely checked or has been checked using a check template covering the entire storage area 110a. In a further preferred embodiment, the storage area 110a containing the boot loader can also be checked with the aid of a check template that does not cover the entire storage area 110a, as is the case in the present case for the further storage areas 110b, 110c, 110d, 110e.

[0116] Fig.11A , 11B , 11C each schematically (and not to scale) show a simplified flow chart of a method according to another preferred embodiment.

[0117] exist Fig.11AIn the configuration shown in , a check template is provided, which characterizes a first number of multiple non-contiguous sub-areas 110_1, 110_2, ..., 110_9 of the entire storage area 110f. The check template also characterizes a second number of further sub-areas, which for the sake of clarity are collectively provided with the reference numeral 111. For example, there are currently four separate further sub-areas 111 between the sub-areas 110_1, 110_2, there are currently three separate further sub-areas 111 between the sub-areas 110_2, 110_3, and so on. The storage area 110f Fig.11A Areas not represented in are not detected by the verification template. In the present case, eight function blocks PG1_1, PG1_2, ..., PG1_8 are provided, each of which forms a part of the primary verification variable PG1 according to the data content of the storage area assigned to it. For example, the function block PG1_1 forms the first part of the primary verification variable PG1 according to four separate additional sub-areas 111 between the storage areas 110_1 and 110_2, the function block PG1_2 forms the second part of the primary verification variable PG1 according to three separate additional sub-areas 111 between the storage areas 110_2 and 110_3, and so on. Therefore, the primary verification variable PG1 can represent an 8-tuple of output values ​​formed by the function blocks PG1_1, ..., PG1_8, respectively. In another preferred embodiment, it is provided that the secondary verification variable PG2 is formed according to the data content of the primary verification variable PG1 and the first number of sub-areas 110_1, 110_2, ..., 110_9, which in the present case can be realized, for example, by means of the function block PG2_1. The secondary verification variable PG2 can, for example, be used as a reference verification variable RPG ( Figure 2A ) is stored for later use or used as current secondary test variable PG2, for example for comparison with a previously stored reference test variable RPG.

[0118] In a further preferred embodiment, the function blocks PG1_1, ..., PG1_8 can be designed, for example, to form a CRC checksum on their input data, for example a CRC checksum with 32 bits, which enables a particularly efficient determination of the primary check variable as an 8-tuple of the CRC checksum obtained therein. In a further preferred embodiment, the function block PG2_1 is designed to apply a cryptographic hash function (for example SHA-256) to the input data ED supplied to the function block, which results in a secondary check variable PG2. In a further preferred embodiment, the input data ED can be formed, for example, as a concatenation (linking) of the output values ​​of the function blocks PG1_1, ..., PG1_8 and the data of the first number of sub-areas 110_1, 110_2, ..., 110_9.

[0119] exist Fig. 11B In the configuration shown, something like Fig.11AA check template is set up that characterizes a first number of multiple non-contiguous sub-regions 110_1, 110_2, ..., 110_9 of the entire storage area 110g. The check template further characterizes a second number of additional sub-regions, similar to Fig.11A For the sake of clarity, these further sub-areas are collectively provided with the reference numeral 111. Fig.11A As in the case of the embodiment of the present invention, the storage area 110g is Fig. 11B The areas not represented in are not covered by the verification template. Fig.11A The configuration is different. Fig. 11B In the configuration of , a single function block PG1_1' is provided, to which the data of the further sub-areas 111 can be supplied as first input data ED1, for example again as a concatenation of the data of the individual sub-areas, see element K. The function block PG1_1' forms a first test variable PG1 from the first input data ED1, for example again using a CRC checksum or a less complex, in particular non-cryptographic or non-collision-free hash function. The first test variable PG1 is then combined with the data content of the first number of sub-areas 110_1, 110_2, ..., 110_9, for example concatenated, which results in second input data ED2, which are converted into second test variables PG2 by a further function block PG2_1, for example using a further, preferably cryptographic hash function (for example SHA-256).

[0120] exist Fig. 11C In the configuration shown, something like Fig.11A and 11B A check template is set to represent a first number of multiple non-contiguous sub-regions 110_1, 110_2, ..., 110_9 of the entire storage area 110h. Fig.11A , 11B , the verification template also features a second number of further sub-regions, which for the sake of clarity are collectively provided with the reference numeral 111. Fig.11A , 11B The same as the embodiment of the present invention, the storage area 110h is Fig. 11C The areas not represented in are not covered by the verification template. Fig.11A , 11B The configuration is different. Fig. 11B In a configuration of , each of the further sub-areas 111 is assigned its own functional block for forming a primary check variable, for example by forming a CRC checksum, wherein Fig. 11CFor the sake of clarity, only three function blocks PG1_1, PG1_2 and PG1_21 are shown in the figure. The output values ​​of the function blocks PG1_1, PG1_2, ..., PG1_21 are combined, preferably with the data contents of the first number of sub-areas 110_1, 110_2, ..., 110_9, wherein the combination may preferably include a cascade, and the function block PG2_1 applies a preferably cryptographic hash function, such as SHA-512, to the input data ED supplied to it.

[0121] As an alternative or in addition to the checksum or hash function mentioned above by way of example, in further preferred embodiments a message authentication code (eg MAC, CMAC) and / or a signature may also be used to determine at least one of the check variables PG, PG1, PG2.

[0122] Another preferred embodiment relates to the method according to the embodiment in the computing device 302 ( Fig.12 ), the computing device being constructed to access the storage device 100 before and / or after and / or during at least one of the following operating phases of the computer: a) starting the computing device 302 from a switched-off state (“boot”), b) (re) starting the computing device 302 from a power-saving state, in particular from a suspend-to-RAM state, c) starting the computing device from a reset state (reset), in particular from a soft reset, d) normal operation.

[0123] Thus, for example, before starting ("booting") or launching from a suspend to RAM state, or during normal operation, it is also possible to advantageously check whether the storage content of storage device 100 has the prescribed content, which can also be referred to as "runtime manipulation detection", i.e., recognition of manipulation during runtime.

[0124] A further preferred embodiment relates to a device 300 for processing data stored in a storage device ( Fig.12 ), wherein the device 300 is configured to perform a method according to an embodiment.

[0125] Another preferred embodiment relates to a method for forming a verification template PM ( Fig.12 ), wherein the verification template represents at least one first sub-region 110_1 ( Figure 1A), wherein the verification template PM is formed randomly or pseudo-randomly. In a further preferred embodiment, it is provided that the method for forming the verification template PM is performed by the above-mentioned device 300 according to the embodiment. However, in a further preferred embodiment, the method for forming the verification template PM can (also) be performed by other units, which then provide the formed verification template PM to, for example, the device 300 according to the embodiment, preferably via a secure channel, for example in a protected manufacturing environment, in which the device 300 according to the embodiment is manufactured.

[0126] In another preferred embodiment, the method according to the embodiment may be executed by, for example, the computing device 302. Alternatively or additionally, the method according to the embodiment may be at least partially executed by an optional hardware security module 307, which in another preferred embodiment may be integrated into the device 300, in particular, may also be arranged on the same semiconductor substrate as the computing device 302 and / or the further storage device 304.

[0127] In a further preferred embodiment, the hardware security module 307 may have or provide a programming interface (API), so that a computer program executed by the computing device 302 for executing the method according to the embodiment can call corresponding functions of the hardware security module 307 by means of the programming interface, so as to execute at least some steps of the method according to the embodiment by means of the hardware security module 307, such as the evaluation of the hash function. In a further preferred embodiment, this is particularly advantageous if the determination or formation of the check variable PG is based on a MAC or CMAC or a signature, or in general in cases where at least one secret key or a shared secret or the like should be used. In a further preferred embodiment, the computer program configured to execute the method according to the embodiment can also be stored, for example, in a read-only memory, such as a ROM and / or an OTP (one-time programmable memory).

[0128] In another preferred embodiment, it is provided that at least two different storage areas 110a, 110b, 110c, 110d, 110e ( Fig.10 ) Different verification templates PM are set respectively. This provides further freedom. For example, a relatively thorough verification using a corresponding detailed or comprehensive verification template PM can be set for the storage area 110a with the boot loader, while a less comprehensive verification template is set for the other storage areas 110c, 110d, and the less comprehensive verification template, for example, covers a smaller area of ​​the storage area involved.

[0129] In a further preferred embodiment, it is provided that, depending on the computer programs and / or data stored in the different memory areas, a corresponding verification template is selected for the memory area in question.

[0130] In a further preferred embodiment, the determination 200, in particular the formation 200a of at least one calibration template can advantageously be carried out dynamically, i.e. during the operation of the device 300, and in a further preferred embodiment can also be carried out repeatedly, in particular periodically. In a further preferred embodiment, the determination 200, in particular the formation 200a of at least one calibration template can be carried out in one or more of the following situations: after the manufacture of the device 300 is completed, after the start-up process or booting of the device 300 is completed, during deceleration, in particular before the device 300 is deactivated. The above embodiments also apply in a corresponding manner to the determination of at least one calibration variable according to the calibration template involved.

[0131] In a further preferred embodiment, it is provided that the determined or generated check template is used only once. Thereafter, if necessary, at least one further check template can be determined, in particular formed. In a further preferred embodiment, the check variable PG or the assigned reference check variable can be used only once in a corresponding manner.

[0132] In a further preferred embodiment, it is provided that the reference check variable RPG is written to a one-time programmable memory (OTP), from which the device 300 can then read the reference check variable if necessary. This can be particularly advantageous if the device 300 does not have an optional hardware security module 307 .

[0133] In a further preferred embodiment, it can be provided that the storage area 110 or at least one first sub-area 110_1 is copied from the storage device 100 to the working memory ( Fig.12 ), to perform the method according to the embodiment using the copied data, for example to form a check variable according to the copied data. In another preferred embodiment, the method according to the embodiment can also be directly applied to the data located in the storage device 100, in particular when the storage device 100 has a storage unit based on non-volatile flash memory (NOR-flash) technology.

[0134] In a further preferred embodiment, the device 300 can be configured as a control device, in particular for a motor vehicle, for example for an internal combustion engine of a motor vehicle. However, in a further preferred embodiment, the application of the principles of the embodiments is not limited to the field of motor vehicles or the field of control devices.

[0135] In further preferred embodiments, the method according to the embodiments may also be combined with other methods for checking the storage device 100. For example, the storage device 100 may be checked at least temporarily according to the above-described embodiments, for example by determining a check template, forming a reference check variable and, if necessary, later forming a current check variable using the same check template, comparing the current check variable with the reference check variable, and sometimes other check methods may also be used to check the storage device 100, for example those in which the check template is not formed on a (pseudo) random basis.

[0136] A significant advantage of the principle according to the embodiment is the fact that the check template is not deterministic, so that an attacker cannot predict which areas of the storage device 100 will be checked with the help of the check template according to the embodiment. Another particular advantage is that the individual devices 300 can determine and / or form and / or use individual check templates PM and / or check template basic data PMB, respectively, so that, for example, the check templates and / or check template basic data involved are only known within the device 300, which further increases the difficulty of manipulation. Another advantage of the principle according to the embodiment is the possibility of flexibly predetermining the storage area to be checked, which can be achieved, for example, by determining the dimensions of the check template PM. In addition, the "check density", i.e. the proportion of the storage area covered by the check template PM in the entire storage area of ​​the storage device 100, can be advantageously set dynamically. In addition, in a further preferred embodiment, the waiting time between the continuous repetition or repeated execution of the method according to the embodiment is flexibly settable, which enables the time-based check density to be precisely set. In a further preferred embodiment, it is also possible to check, for example, different sub-areas 110_1, 110_2 of the storage device with different frequencies or using check templates of different sizes.

[0137] Fig.13 Schematically shows a simplified block diagram according to another preferred embodiment. Storage device 100 ( Figure 1A ) is shown in three different operating states Z_1, Z_2, Z_3. The first operating state Z_1 is characterized by checking the first (pseudo-)randomly formed check template in Fig.13 The sub-regions represented as rectangles, which are not shown in detail, are shaded, for example, by comparing first calibration variables obtained with the aid of the first calibration template with corresponding reference calibration variables, which may have been previously formed. The remaining unchecked regions are shaded.

[0138] The second operating state Z_2 is characterized by checking the Fig.13The third operating state Z_3 is characterized in that the second (pseudo) randomly generated check template is used to check the second check variable obtained with the aid of the second check template with a corresponding, possibly previously generated reference check variable. Fig.13 , for example by comparing a third check variable obtained with the aid of a third check template with a corresponding, if necessary previously formed, reference check variable. Between the first operating state Z_1 and the second operating state Z_2 (see phase P1), the device or device 300 accessing the storage device 100 can, for example, be inactive, for example by being deactivated or adopting a suspend-to-RAM state or another energy-saving state. Between the second operating state Z_2 and the third operating state Z_3 (see phase P2), the device 300 accessing the storage device 100 can, for example, be inactive again, for example by being deactivated or adopting a suspend-to-RAM state or another energy-saving state.

[0139] After the end of phase P1, the device 300 is reactivated and then checked with the aid of a second verification template, which, due to its non-deterministic characteristics, leads to at least partial checking of storage areas that were not previously checked with the aid of the first verification template. Similar characteristics apply to further examinations after the end of phase P2. In this way, in a further preferred embodiment, it is advantageously possible to continuously check almost the entire storage area 110 of the storage device 100. At the same time, the demand for resources, in particular the demand for computing time, can be flexibly controlled, in particular so that also larger storage areas can be checked efficiently without affecting the operation of the device.

[0140] In a further preferred embodiment, a second check template for checking during the second operating state Z_2 can be determined, for example, by the device 300, which is then deactivated or switched off at the end of the first operating state Z_1. After forming the second check template, the second check template is securely stored, preferably within the device 300, and a check variable is determined with the aid of the second check template, which can be used as a reference check variable for checking during the second operating state Z_2 and is likewise stored in the device 300. The device 300 then enters an inactive phase P1, which it leaves again to assume the second operating state Z_2. Then, in particular before assuming normal operation during the second operating state Z_2 (execution of an application, etc.), a second check can be performed, for example, with the aid of a boot loader, using the previously formed second check template and the corresponding reference check variable. The second check can include, for example, forming a current check variable using the second check template and comparing the current check variable obtained in this way with a reference check variable. If it is determined that the current check variable is consistent with the reference check variable, it can be concluded that the storage device has not been manipulated and that the data is therefore authentic and complete. Otherwise, for example, a fault response can be initiated. A similar process can be performed for the state transition from the second operating state Z_2 to the third operating state Z_3. Since the check template changes continuously in a non-deterministic manner in the various operating states, an attacker cannot see the check template and therefore also cannot see the basis for the formation of the check variable in advance, so that unidentified manipulation of the data stored in the storage device is almost impossible.

[0141] In another preferred embodiment, the method according to the embodiment can be at least partially executed by a computing device or a computing device 302 and / or a possibly existing hardware security module 307. For example, in another preferred embodiment, at least some of the following steps can be executed by the computing device 302 and / or a possibly existing hardware security module 307: storing the first or second secret key and / or a hash value of the first or second secret key, processing the first or second secret key, forming and / or storing a verification template PM or verification template basic data, forming and / or storing a reference verification variable based on the verification template or the verification template basic data, forming and / or storing a current verification variable based on the verification template or the verification template basic data, comparing the current verification variable with the reference verification variable or verifying the current verification variable.

[0142] In another preferred embodiment, the verification template PM or the verification template basic data PMB and / or the reference verification variable RPG are not necessarily stored in, for example, the internal memory of the computing device 302. Alternatively or additionally, in other preferred embodiments, the verification template PM or the verification template basic data PMB can be stored in an external storage unit, for example, in encrypted form, and / or the key used for encryption or the hash value of the key can be stored in the internal memory or the internal memory, if necessary. In addition, in another preferred embodiment, the key can be preferably implemented specifically for the device / control device (generalized: device).

[0143] In a further preferred embodiment, the reference check variable RPG can be stored in an internal or external memory unit, in particular in unencrypted form, in particular if the reference check variable RPG represents an asymmetric signature and / or the reference check variable represents a MAC.

[0144] In a further preferred embodiment, the reference check variable RPG can be stored in an external storage unit, in particular in encrypted form, in particular if the reference check variable RPG represents a cryptographic hash (value), wherein in particular the same or similar standards as used for encrypting the check template PM can be used for the key used for encryption (see the above description).

Claims

1. A method for processing data stored in a storage device (100) of a control device of a motor vehicle, The following steps are involved: At least one first sub-area (110_1) of a storage area (110) of the storage device (100) is determined by means of a randomly or pseudo-randomly formed check template (PM), in which at least one of a start address, an end address, a length, a bit mask and a byte mask is selected randomly and / or pseudo-randomly, a check variable (PG) is formed according to data (D) stored in the at least one first sub-area (110_1), the check variable (PG) is compared with a stored reference check variable (PRG) for the at least one first sub-area (110_1), wherein if the check variable (PG) deviates from the reference check variable (PRG), it is concluded that the data of the associated first sub-area (110_1) from which the reference check variable (PRG) is formed has been changed or manipulated, The formation of the check variable (PG) comprises the following steps: selecting a first number of sub-areas of a storage area (110) of the storage device (100), selecting a second number of sub-areas of the storage area (110) of the storage device (100), the second number being different from the first number, forming a primary check variable (PG1) for the first number of sub-areas of the storage area (110), and forming a secondary check variable (PG2) for the second number of sub-areas of the storage area (110).

2. The method according to claim 1, further comprising: include: a) at least temporarily storing (204) the check variable (PG).

3. The method according to claim 1, wherein the formation of the verification template (PM) The following steps are involved: A random or pseudo-random digital sequence (ZF) is provided, and the at least one first sub-region (110_1) is determined according to at least one first part (ZF1) of the digital sequence (ZF). The method of claim 3 , wherein the digital sequence is binary. 5 . The method according to claim 3 , wherein a start address of a first sub-area ( 110_1 ) in the memory area ( 110 ) is formed from a first part ( ZF1 ) of the digital sequence (ZF).

6. The method according to claim 3, wherein the verification template (PM) represents at least one second sub-region (110_2) in addition to the first sub-region (110_1).

7. The method according to claim 6, wherein the second sub-region (110_2) does not directly adjoin the first sub-region (110_1) and / or has a non-vanishing distance from the first sub-region (110_1).

8. The method according to claim 3, wherein the verification template (PM) represents, in addition to the first sub-region (110_1), a plurality of further sub-regions (110_3a, 110_3b, 110_3c).

9. The method according to claim 6, further comprising: include: The second sub-region (110_2) is determined based on a second part (ZF2) of the digital sequence (ZF) that is different from the first part (ZF1) of the digital sequence (ZF).

10. The method according to claim 9, wherein a start address of the second sub-area (110_2) in the memory area (110) is formed as a function of a second part (ZF2) of the digital sequence (ZF).

11. The method according to claim 8, further comprising: include: The further sub-regions (110_3a, 110_3b, 110_3c) are determined based on respective corresponding further parts of the digital sequence (ZF), which are respectively different from the first part (ZF1) of the digital sequence (ZF) and / or the second part (ZF2) of the digital sequence (ZF).

12. The method as claimed in claim 11, wherein a start address of a respective further sub-area in the memory area (110) is formed from a corresponding further part of the numerical sequence (ZF).

13. The method according to any one of claims 6 to 12, wherein a) all sub-regions have the same length, or b) at least some of the sub-regions have different lengths.

14. The method according to claim 3, wherein the length of at least one sub-region is determined from at least one part of the digital sequence (ZF).

15. The method according to any one of claims 1 to 12, wherein the verification template (PM) does not completely cover the storage area (110).

16. A method according to any one of claims 1 to 12, wherein the formation of the check variable (PG) has at least one of the following elements: a) applying a hash function to the data (D) stored in the at least one first sub-area (110_1), b) forming a checksum based on the data (D) stored in the at least one first sub-area (110_1), c) forming a signature based on a first secret key and the data (D) stored in the at least one first sub-area (110_1), d) forming a message authentication code based on a second secret key and the data (D) stored in the at least one first sub-area (110_1).

17. The method according to claim 1, wherein the formation of the check variable (PG) comprises the following steps: forming a primary check variable (PG1) based on the data (D) stored in the at least one first sub-area (110_1), and forming (229) a secondary check variable (PG2) based on at least the primary check variable (PG1).

18. The method as claimed in claim 1, wherein the secondary test variable (PG2) is additionally formed for at least a portion of the primary test variable (PG1).

19. A method according to claim 1, wherein the method can be used before and / or after and / or during at least one of the following operating stages of a computing device (302), wherein the computing device is constructed to access the storage device (100): a) starting the computing device (302) from a shutdown state, b) starting the computing device (302) from a power-saving state, c) starting the computing device (302) from a reset state reset, d) normal operation.

20. The method of claim 19, wherein the power saving state is a Suspend to RAM state.

21. A device (300) for processing data stored in a memory device (100) of a control device of a motor vehicle, wherein the device (300) is configured to perform the following steps: determining at least one first sub-area (110_1) of a memory area (110) of the memory device (100) by means of a randomly or pseudo-randomly formed check template (PM), in which at least one of a start address, an end address, a length, a bit mask and a byte mask is selected randomly and / or pseudo-randomly, forming a check variable (PG) based on the data (D) stored in the at least one first sub-area (110_1), comparing the check variable (PG) with a stored reference check variable (PRG) for the at least one first sub-area (110_1), wherein if the check variable (PG) deviates from the reference check variable (PRG), it is inferred that the data of the associated first sub-area (110_1) from which the reference check variable (PRG) is formed has been changed or manipulated, wherein the formation of the check variable (PG) The following steps are involved: A first number of sub-areas of a storage area (110) of the storage device (100) is selected, a second number of sub-areas of the storage area (110) of the storage device (100) is selected, the second number being different from the first number, a primary check variable (PG1) is formed for the first number of sub-areas of the storage area (110), and a secondary check variable (PG2) is formed for the second number of sub-areas of the storage area (110).

22. The device (300) according to claim 21, wherein the device (300) is configured to perform the method according to any one of claims 2 to 18.

Citation Information

Patent Citations

  • Verification device, electronic apparatus, program, and verification system

    JP2017169147A

  • Method for monitoring components of the drive train of a motor vehicle and for diagnosing errors in the same

    US20050187679A1

  • Method for storing data blocks from client devices to a cloud storage system

    WO2018024658A1