Method for verifying the true origin of an electronic module of a modular field device for validation automation technology
By using key pairs and manufacturer signatures in field equipment of automation technology, verifying the source of electronic modules is solved, and the problem of not being able to effectively verify the true source of electronic modules in the prior art is solved, thereby reducing security risks.
Patent Information
- Application Number
- CN202110422886.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-04-22
- Filing Date
- 2021-04-20
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-04-20
AI Technical Summary
The prior art cannot effectively verify the true source of electronic modules of modular field devices in automation technology, resulting in safety risks, especially the use of electronic modules that do not meet the requirements in explosion hazard areas may have fatal effects.
Verify the manufacturer signature and key pair of electronic modules to electronic modules by assigning key pairs of public and private keys to the authorized manufacturers and storing a list of public keys for trusted manufacturers in the field device, ensuring that only electronic modules derived from authorized manufacturers can be used in the field device.
Reliable verification of the source of electronic modules is achieved, ensuring that only authorized manufacturers' electronic modules can be used in field equipment in automation technology, reducing safety risks.
Smart Images

Figure CN113536332B_ABST
Abstract
Description
Field of the Invention
[0001] The present invention relates to a method for verifying the genuine origin of an electronic module of a modular field device in automation technology. Background Art
[0002] Field devices for detecting and / or influencing physical, chemical or biological process variables are generally used in process automation as well as in manufacturing automation. Measuring devices are used to detect process variables. These measuring devices are used, for example, for pressure and temperature measurements, conductivity measurements, flow measurements, pH measurements, fill level measurements, etc., and detect the corresponding process variables of pressure, temperature, conductivity, pH value, fill level, flow rate, etc. Actuator systems are used to influence process variables. Examples of actuators are pumps or valves that can influence the flow of a fluid in a pipeline or the fill level in a tank. In addition to the aforementioned measuring devices and actuators, field devices are also understood to include remote I / O, radio adapters, or more generally, devices arranged at the field level. In connection with the present invention, all devices used near a process or a plant and supplying or processing information related to the process or the plant are referred to as field devices.
[0003] The corresponding field devices generally consist of a plurality of electronic modules, such as plug-in modules with circuit boards, sensors with digital connections, etc. If an electronic module is replaced or added, it is currently not possible to check whether the electronic module is genuine with respect to its origin, i.e., whether the electronic components originate from the original manufacturer or from a manufacturer classified as trustworthy - and also to prove this. So far, before installation, the authenticity of the origin of the electronic module has not been reliably verified. At most, if the installation is carried out by a maintenance technician in the art, a visual inspection is performed. If the visual inspection is positive, it is assumed that the electronic module can be installed in the field device.
[0004] The procedures described above pose a considerable safety risk: because, in principle, it has not been possible until now to detect electronic modules brought onto the market by unauthorized manufacturers, there is a risk that electronic modules not meeting the required safety regulations will be put into use in field devices. For example, if an electronic module does not meet the requirements for use in an explosion-hazardous area but is used in the automation technology of such an area, it can have absolutely fatal consequences. Summary of the Invention
[0005] It is an object of the present invention to provide a method by means of which it is ensured that only electronic modules originating from authorized manufacturers can be used functionally in field devices of automation technology.
[0006] The present invention is implemented by a method for verifying the genuine origin of an electronic module of a modular field device in automation technology, wherein each manufacturer of an electronic module of a field device classified as trustworthy is assigned a key pair consisting of a public key and a private key, and wherein the public keys of the manufacturers classified as trustworthy are stored in a list in the field device or in a unit communicating with the field device. In addition to the key pair identifying the electronic module consisting of a public key and a private key, each electronic module of the field device also contains the public key of the manufacturer and a manufacturer signature, by means of which the public key of the electronic module is confirmed as trustworthy. In particular, the manufacturer signature is an encryption of the public key of the electronic module using the private key of the authorized manufacturer. Alternatively, the manufacturer signature can also be generated directly or indirectly via a so-called digital signature algorithm (DSA, ECDSA, etc.).
[0007] The method comprises the following method steps:
[0008] When replacing or adding an electronic module, the field device or the unit communicating with the field device checks:
[0009] - whether the replaced or added electronic module has a key pair and a manufacturer signature,
[0010] - whether the public key of the manufacturer of the electronic module is listed in the list and whether the public key of the manufacturer is classified as trustworthy; additional forms of identity associated with the public key of the relevant manufacturer can also be stored in the list. This can be advantageous if the form of identity is chosen in such a way that it requires less storage space than the public key of the manufacturer and can therefore be transmitted faster.
[0011] - whether the manufacturer signature matches the manufacturer and the electronic module, i.e., whether the electronic module actually originates from a trustworthy manufacturer, and
[0012] - whether the electronic module has the correct private key.
[0013] If the check ends with a positive result, the replaced or added electronic module is allowed to communicate or interact with the field device or another electronic module related to the function of the field device.
[0014] Electronic modules, in particular plug-in modules with a circuit board or sensors with digital connections. These sensors are preferably intelligent sensors connected to a central converter via a pluggable cable, such as Memosens sensors. The sensors are, for example, pH sensors, turbidity sensors, conductivity sensors, etc. Suitable converters are sold and distributed by the applicant, for example, under the designations CM42, CM44 or Liquiline. The method according to the invention is very suitable for ensuring that only sensors from authorized manufacturers are connected to the converter / transmitter. Depending on the use case, in particular pH sensors must be calibrated at longer or shorter time intervals. Calibration is usually performed in a laboratory using a PC application (e.g., the applicant's Memobase Plus); the determined calibration data is stored in the associated sensor. Here too, the method according to the invention can also advantageously be used to distinguish sensors from authorized manufacturers and fake sensors.
[0015] In summary, it can be said that according to the invention, an inspection is carried out to determine a) whether the manufacturer of the electronic module is trustworthy and b) whether the module was actually manufactured by a trustworthy manufacturer. Or, in other words: an electronic module from a manufacturer is accepted if it can verify that it was actually also manufactured by a manufacturer identified as trustworthy. In connection with the invention, a manufacturer signature means, for example, the encryption of the public key of the electronic module using the private key of the manufacturer. As already mentioned above, other signature methods can also be used, such as DSA, ECDSA, etc. Creation can also be done using additional intermediate steps, such as using a hash (SHA256). With the help of the signature, the manufacturer confirms the origin of the public key of the electronic module, in particular from its production.
[0016] If it is desired to ensure that the electronic module is only used with field devices from authorized manufacturers, a list of the manufacturers of the field devices classified as trustworthy can be stored in the electronic module. It can only provide its (full) functionality if the electronic module can ensure that it is used with a trustworthy field device.
[0017] To check whether the manufacturer signature matches the manufacturer and the replaced or added electronic module, the manufacturer signature, the manufacturer's public key, and the public key of the electronic module are read out and checked. If the manufacturer signature of the replaced or added electronic module can be decrypted using the manufacturer's public key, it is ensured that the public key of the electronic module originates from a trusted manufacturer. Preferably, via a challenge / response method, a corresponding check is performed to determine whether the replaced or added electronic module with which the field device or unit communicates and the public key of the electronic module actually belong together. In this case, an arbitrary message is sent from the field device or alternatively from a unit communicating with the field device as a challenge to the replaced or added electronic module created by requesting encryption or signature creation using the private key. The replaced or added electronic module encrypts or signs the message using its private key and returns the signed message as a response to the field device or unit. The field device or unit decrypts the signed message using the public key of the replaced or added electronic module and receives the message in the case of a positive verification. Alternatively, the message can also be hashed first and then encrypted using the private key of the electronic module. This is particularly advantageous if longer messages or messages of unknown / variable length are communicated. By hashing, the message etc. can be made of a defined length.
[0018] According to a further development of the method according to the invention, the following method steps are proposed:
[0019] If the check indicates that the replaced or added electronic module does not have a manufacturer signature or does not have a key pair, a check is made as to whether a manufacturer signature and / or a key pair can be generated or provided for the electronic module. In the case where a manufacturer signature and / or a key pair can be provided or generated, the manufacturer signature and / or the key pair are transmitted to the replaced or added electronic module. Note the following: The private keys of an authorized manufacturer are of course kept secret by the manufacturer; thus, they are not available in the field device. If the electronic module does not have a key pair, a key pair can be generated and assigned to the electronic module in the presence of a corresponding generator. If the manufacturer signature is missing, as an alternative, the field device can do what the manufacturer itself usually does: It acts as the manufacturer with the public key Q of the field device and vouches for the public key of the electronic module by creating a signature q(Pk) using the private key q of the field device. In this case, it is of course necessary to list the public key Q of the field device as a quasi-manufacturer in the list of manufacturers classified as trusted.
[0020] Furthermore, the following method step is provided: In the case where the electronic module does not have a manufacturer signature and / or does not have a suitable key pair, or a manufacturer signature and / or a suitable key pair cannot be generated for the electronic module, communication from the field device to the electronic module is excluded.
[0021] Preferred embodiments provide the following method steps: If the check indicates that the replaced or added electronic module has a manufacturer signature and a suitable key pair, but the public key of the manufacturer is not stored in the list, then if an authorized person - such as a maintenance technician - confirms the credibility of the manufacturer of the electronic module, the public key of the manufacturer is assigned to the list.
[0022] In addition, the following is proposed: If a manufacturer signature q(Pk) and a suitable key pair (Pk, pk) can be generated for the electronic module, the data is assigned to the electronic module or stored in the electronic module.
[0023] In connection with the present invention, during the production process, each electronic module is provided with a suitable key pair by an authorized manufacturer, the original manufacturer, or a third party authorized by the original manufacturer; in addition, the public keys of the authorized manufacturers are stored in a list of manufacturers classified as trusted. The generation of the key pairs and manufacturer signatures of the electronic modules generally takes place in the production of the manufacturer. Only in this way can the private key of the manufacturer be kept confidential. Otherwise, the signature - that is, the encryption using the private key of the manufacturer - will lose its validity or meaning.
[0024] However, during in-situ maintenance access, in certain cases, additional manufacturers can be added to the list of manufacturers classified as trusted. For example, this can occur in such a way that an authorized person logs into the field device and actively writes the public key of the additional manufacturer into the list, or adopts it from one of the plug-in electronic modules. In addition, it is possible for the additional manufacturer to contact a manufacturer already recorded in the list, especially the original manufacturer, and request that this manufacturer, for example, create an add-supplier ticket, which the additional manufacturer can then add to all of its electronic modules. Such a ticket must contain the public key of the additional manufacturer signed by an authorized manufacturer, and the authorized manufacturer hereby guarantees the public key of the additional manufacturer.
[0025] In addition, it is stipulated that when an electronic module is replaced, if the authorized manufacturer does not provide any other electronic modules for the field device, the public key of that manufacturer is deleted from the list.
[0026] This check is preferably performed during the ongoing operation of the field device. This check can also be performed after the field device is restarted, or cyclically according to any predetermined time interval.
[0027] As mentioned previously, derivatives such as hash values, or some other independent and unique identifier, can also be used instead of the public keys of the authorized manufacturers.
[0028] Additional intermediate steps can also be used to calculate the manufacturer signature: for example, before encryption using the private key of the manufacturer, the hash value of the public key of the electronic module is determined. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The present invention will be explained in more detail with reference to the following drawings. Shown below are:
[0030] Figure 1 : A schematic representation of a field device having a plurality of modules and a list of module manufacturers classified as trusted,
[0031] Figure 2 : A schematic diagram of a field device having a plurality of modules, in which modules of unknown manufacturers have been added,
[0032] Figure 3 : A schematic diagram of a field device having a plurality of modules, in which the field device itself enables itself to act as a manufacturer, and
[0033] Figure 4 is a flowchart visualizing the method according to the present invention and its embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0034] Figure 1 A schematic representation of a field device FG is shown, which has a plurality of modules Mk (where k = 1, 2, 3) and a list PTL having public keys H, V1 of module manufacturers classified as trusted. Two of the electronic modules M1, M2 are manufactured by the original manufacturer; one module M3 is from an authorized manufacturer classified as trusted (supplier 1). Since both the original manufacturer and the (one or more) module manufacturers classified as trusted are authorized manufacturers, for simplicity, in the patent claims and Figure 4 description, the abbreviation Vm is used for the public key of the authorized module manufacturer, and the abbreviation vm is used for the corresponding private key, where m = 1, 2, ……, I.
[0035] In addition to its own key pair (Q, q), the list PTL having public keys H, V1 of module manufacturers classified as trusted is stored in the field device FG. In addition to its own key pair (Pk, pk), each electronic module Mk contains the public keys H, V1 of the corresponding module manufacturer and the public keys h(P1), h(P2), v1(P3) of the electronic module Mk encrypted with the corresponding private key h, v1 of the module manufacturer. The public keys h(P1), h(P2), v1(P3) of the electronic module Mk encrypted with the corresponding private key h, vm of the module manufacturer are also referred to as manufacturer signatures. In Figures 1 to 3 , the encryption itself is marked with the letter E.
[0036] The key pair (Q, q) of the field device FG can be used to enable the field device FG to be configured as a genuine field device FG of the original manufacturer or an authorized manufacturer relative to other field devices. However, in order to identify whether the electronic module Mk originates from an authorized manufacturer and can thus be incorporated into the communication necessary for the operation of the field device, the key pair (Q, q) is only relevant in the case where the manufacturer's signature q(Pk) of the electronic module Mk is to be generated. This is particularly necessary because the electronic module Mk itself has no information about which manufacturers are trustworthy or untrustworthy. However, an authorized manufacturer can - as mentioned above - directly install the corresponding additional vendor ticket on the electronic module Mk.
[0037] Figure 2 is a schematic representation of a field device FG with a plurality of modules Mk, to which a module M4 of an as yet unknown manufacturer has been added. The manufacturer has a public key V2, which, when the M4 electronic module is installed, has not yet been entered in the list PTL of manufacturers classified as trustworthy. However, the public key V2 of the manufacturer is signed by one of the manufacturers classified as trustworthy in the list, in this case by the private key h of the original manufacturer. If, for example, an authorized person logs into the field device FG and adds the public key V2 of the new manufacturer to the list PTL, the public key of manufacturer V2 is recorded in the list PTL of manufacturers classified as trustworthy.
[0038] In addition, the electronic module M4 has a key pair (P4, p4) assigned to the electronic module M4 and a manufacturer's signature v2(P4).
[0039] Figure 3 A schematic representation of a field device FG with a plurality of modules Mk is shown. In this case, the following can be seen: The field device FG itself enables itself to act as a manufacturer. The field device FG signs the added module M4 - thus, it encrypts the public key P4 of the electronic module M4 with its private key q - and transmits the manufacturer's signature q(P4) to the electronic module M4, so that the electronic module M4 can subsequently be identified relative to the field device FG. In addition, the field device FG must add its public key Q to the list PTL of manufacturers classified as trustworthy. With this procedure, the field device FG subsequently accepts all the electronically signed modules Mk.
[0040] An alternative in this regard is that the field device FG has, in addition to a list PTL of manufacturers classified as trusted, a list MTL of electronic modules classified as trusted. In this case, the manufacturer's signature q(P4) of the electronic module M4 can be omitted. In a patent application of the applicant filed simultaneously with the present patent application, a method for ensuring that only electronic modules Mk classified as trusted are used in the field device FG is described in detail in other respects.
[0041] Figure 4 A flowchart showing the method according to the invention and its embodiments is shown. During the production or ongoing operation of the field device FG, an electronic module MK is replaced or a new module M4 is inserted at point 20 ( Figure 2 ). Since only the replaced or added electronic modules Mk, M4 are included in the communication required for the operation of the field device FG if it is ensured that the electronic module Mk originates from an authorized manufacturer V1 and is authentic in this sense, the origin of the electronic module Mk must be verifiable.
[0042] At program point 30, in a first step, it is checked whether the replaced or added electronic module Mk has the following data elements:
[0043] a) The public key Vm of the manufacturer - this is requested by the field device FG in order to determine the identity of the manufacturer and verify whether the manufacturer is classified as trusted,
[0044] b) The key pair Pk, pk assigned to the electronic module Mk - which encrypts its identity and consists of the public key Pk and the private key pk,
[0045] c) The manufacturer's signature vm(Pk) - that is, the public key Pk of the electronic module Mk encrypted with the private key vm of the manufacturer.
[0046] If the availability of the aforementioned data elements is confirmed at program point 30, then at program point 40 it is checked whether the public key Vm of the manufacturer of the electronic module Mk is listed in the list PTL of manufacturers classified as trusted assigned to the field device FG. In the case of a positive output of the verification, the electronic module Mk appears to be from a trusted manufacturer. This assumption will be proven below.
[0047] The measures required for verification are stated at program point 50: The field device FG requests the public key Pk of the electronic module Mk and the manufacturer's signature vm(Pk).
[0048] At program point 60, a check is made as to whether the signature vm(Pk) matches the authorized manufacturer of module Mk. This check is affirmative if the public key Pk of the electronic module Mk, which is signed by the manufacturer using its private key vm, can be decrypted using the public key Vm of the manufacturer. It can then be assumed that the signature vm(Pk) has been written to the module Mk by the manufacturer who owns the private key vm of the authorized manufacturer. Therefore, the public key Pk of the electronic module Mk must be signed by this authorized manufacturer, provided that the private key vm has not been compromised.
[0049] At program point 70, a check is then made as to whether the electronic module MK also has the associated private key pk. This third step can ensure that the replaced or added electronic module Mk and the public key Pk of the electronic module Mk actually belong together. This final check is then performed by a challenge / response method, with or without a hash.
[0050] As a challenge, the replaced or added module Mk encrypts the message m sent by the field device FG using its own private key pk and sends the signed message pk(m) as a response to the field device FG. The field device FG decrypts the signature pk(m) using the existing public key pk of the electronic module Mk and expects the result to be the unencrypted message m. If so, it can clearly be concluded that the electronic module Mk must have the private key pk. Therefore, the public key pk must also belong to the private key Pk of the electronic module Mk.
[0051] The electronic module Mk is considered trustworthy only if an affirmative result is obtained in each of the foregoing checks - its origin from a manufacturer classified as trustworthy is proven - and is included in the communication required for the operation of the field device FG (program point 80); the program terminates at point 90.
[0052] If the check at program point 30 indicates that the replaced or added electronic module Mk does not have the following data elements: the public key vm of the manufacturer, the key pair Pk, pk assigned to the electronic module Mk, and the manufacturer's signature Vm(Pk) - i.e., the public key Pk of the electronic module Mk encrypted using the private key Vm of the manufacturer - then a check is made at program point 100 as to whether these data elements can be generated or added. If the check at program point 100 indicates that the data elements cannot be generated or added, an error message "Incomplete data" is output at program point 110; subsequently, the check is terminated. If the data elements can be generated or added at program point 120, the check continues at program point 40.
[0053] If the check at program point 40 indicates that the public key Vm of the module manufacturer has not been entered into the list PTL of manufacturers classified as trusted, the authorized user / maintenance technician can still confirm the trustworthiness of the module Mk at program point 130. Alternatively, a supplier ticket may also be present in the field device FG or in the electronic module Mk. If such verification is carried out, the public key Vm of the manufacturer is recorded in the list of manufacturers classified as trusted (program point 140). If the trustworthiness is not verified at program point 130, an error message "Manufacturer not trusted" is generated at program point 150 and the check ends.
[0054] If the check at one of program points 60, 70 indicates that the signature vm(Pk) does not match the manufacturer or the electronic module Mk, or the electronic module Mk does not possess the associated private key pk, an error message: "Module not genuine" is output (program point 160). Then the communication required for the operation of the field device is excluded.
Claims
1. A method for verifying the genuine origin of an electronic module of a modular field device in an automation technology, wherein, The field device consists of multiple electronic modules. Each manufacturer of the electronic modules classified as trusted field devices is assigned a key pair consisting of a public key and a private key, and the public key of the manufacturer classified as trusted is stored in a list in the field device or in a unit communicating with the field device. Each electronic module of the field device further contains the public key of the manufacturer and a manufacturer signature, in addition to its own appropriate key pair consisting of the public key and private key of the electronic module, where the manufacturer signature confirms the public key of the electronic module as trusted. The method has the following method steps: When replacing or adding an electronic module in the field device, the field device or a unit communicating with the field device checks whether the replaced or added electronic module has a key pair consisting of the public key and private key of the electronic module and a manufacturer signature, whether the public key of the manufacturer of the electronic module is listed in the list having the public keys of the manufacturers classified as trusted, whether the manufacturer signature matches the manufacturer and the electronic module, i.e., whether the electronic module actually originates from a trusted manufacturer, and whether the electronic module has the correct private key of the electronic module, and this check is performed by a challenge / response method. Only when a positive result is obtained in each of the above checks is the replaced or added electronic module allowed to communicate or interact with the field device or another electronic module related to the function of the field device.
2. The method according to claim 1, comprising the following method steps: In order to check whether the manufacturer signature matches the manufacturer and the replaced or added electronic module, the manufacturer signature, the public key of the manufacturer, and the public key of the electronic module are read out and checked.
3. The method according to claim 1 or 2, comprising the following method steps: If the manufacturer signature of the replaced or added electronic module can be decrypted using the public key of the manufacturer, it is ensured that the public key of the electronic module originates from a trusted manufacturer.
4. The method according to claim 3, comprising the following method steps: An inspection is performed via a challenge / response method to check whether the replaced or added electronic module with which the field device or the unit communicates and the public key of the electronic module actually belong together.
5. The method according to claim 4, comprising the following method steps: From the field device or a unit communicating with the field device, an arbitrary message is sent as a challenge to the replaced or added electronic module created or encrypted by requesting a signature, The replaced or added electronic module encrypts or signs the message using its private key and returns the signed message as a response to the field device or the unit, The field device or the unit decrypts the signed message using the public key of the replaced or added electronic module and receives the message in the case of a positive verification.
6. The method according to claim 1 or 2, comprising the following method steps: If the inspection indicates that the replaced or added electronic module does not have a manufacturer signature or does not have a key pair, an inspection is performed on whether a manufacturer signature and / or a key pair can be generated or provided for the electronic module, wherein,In the case where the manufacturer signature and / or the key pair are provided or generated by another electronic module, the manufacturer signature and / or the key pair are transmitted to the replaced or added electronic module.
7. The method according to claim 6, comprising the following method steps: In the case where the electronic module does not have a manufacturer signature and / or a suitable key pair, or a manufacturer signature and / or a suitable key pair cannot be generated for the electronic module, the electronic module remains excluded from the communication.
8. The method according to claim 1 or 2, comprising the following method steps: If the check indicates that the replaced or added electronic module has the manufacturer signature and the appropriate key pair, but the public key of the manufacturer is not stored in the list, then if an authorized person confirms the credibility of the electronic module manufacturer, the public key of the manufacturer is assigned to the list.
9. The method according to claim 1 or 2, comprising the following method steps: If a manufacturer signature and a suitable key pair can be generated for the electronic module, the manufacturer signature and the suitable key pair are assigned to the electronic module or stored in the electronic module.
10. The method according to claim 1 or 2, comprising the following method steps: - During the production process or during a maintenance visit, each of the electronic modules is provided with a suitable key pair by an authorized manufacturer, the original manufacturer, or a third party authorized by the original manufacturer, and the public key of the authorized manufacturer is stored in the list.
11. The method according to claim 1 or 2, comprising the following method steps: When replacing an electronic module, the public key of the authorized manufacturer is deleted from the list.
12. The method according to claim 1 or 2, comprising the following method steps: The check is performed during the ongoing operation of the field device.
13. The method according to claim 1 or 2, comprising the following method steps: Instead of the public key of the authorized manufacturer, a derivative or some other independent and unique identifier is used.
14. The method according to claim 13, comprising the following method steps: Instead of the public key of the authorized manufacturer, a hash value is used.
15. The method according to claim 1 or 2, comprising the following method steps: - Using an additional intermediate step to calculate the manufacturer signature: determining a hash value before encrypting with the private key of the manufacturer.
16. The method according to claim 1 or 2, Among them, An insertion module having a circuit board or a sensor having a digital connection is used as the electronic module.
Citation Information
Patent Citations
Identity authentication method and device for communication equipment as well as equipment
CN109361669A
Certificate issuing method, device and system for intelligent equipment
CN110138562A
Systems and methods for binding a hardware component and a platform
US20050289343A1
Secure provisioning of devices for manufacturing and maintenance
US20160294829A1