Apparatus and method for performing integrity checks on sensor data streams
By adopting a combination of hash tree memory and encryption key memory in the sensor data stream, the problem of independent integrity checking of sensor data streams in low-performance systems is solved, and the integrity and authenticity verification of sensor data streams with low resource consumption is achieved.
Patent Information
- Application Number
- CN202080024476.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-04-03
- Filing Date
- 2020-03-18
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2040-03-18
AI Technical Summary
The prior art requires intervention in the existing architecture and high resource consumption when conducting integrity checks on sensor data flows, which are difficult to implement in low-performance embedded systems, and cannot handle integrity checks of the sensor data flow parts independently of the existing architecture.
The control device connected to the hash tree memory is used to calculate and store the hash value of the sensor data stream part, reduce storage consumption through the structure of the hash tree, and electronically sign the root hash value with the encryption key memory, and conduct integrity checking in combination with the decentralized check memory.
Independent integrity check of sensor data flow under low resource consumption, can be transmitted between multiple architectural nodes, and real-time data integrity and authenticity verification in low-performance systems, reducing memory access time and possibility of modification forgery.
Smart Images

Figure CN113632418B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a device and a method for integrity checking of sensor data streams, having an acquisition unit with sensor data input. Background Art
[0002] In order to perform integrity checking on sensor data, that is, to check the correct content, unchanged state, and temporal correctness of sensor data, encryption or transmission through a secure environment (US 20130243189A1) is usually used to prevent possible tampering of sensor data during transmission. However, the disadvantage of this is that such encryption methods are not only resource-intensive but also cannot further process existing sensor data in plain text in existing architectures, which makes it difficult to apply especially in the field of monitoring and controlling vehicle components or industrial machines.
[0003] In order to ensure the security of the encryption parameters used and to accelerate the processing process, it has been proposed (WO2016049077 A1) to use a Trusted Platform Module (TPM).
[0004] However, the disadvantage of all known devices and methods is that to ensure security by encrypting the sensor data stream, the existing transmission architecture must be intervened, and the encryption functions used are very expensive especially for security reasons, and the required processing rate cannot be achieved in low-performance embedded systems, where low-performance embedded systems can achieve comprehensive distribution to receive many different sensor data streams at different clock frequencies.
[0005] In addition, especially in the case of sensor data streams, it should not only be possible to perform integrity checking on individual sensor data stream parts in the form of data packets, but also to perform integrity checking of sensor data stream parts relative to the sensor data stream, so that it can be checked whether the sensor data stream part actually appears at the specified position in the sensor data stream; no sensor data stream parts are added or omitted before or after; and the data of the sensor data stream part itself has not been changed. Summary of the Invention
[0006] Therefore, the technical problem to be solved by the present invention is to design a device and a method of the type described at the beginning, such that each sensor data stream part of the sensor data stream can be independently integrity-checked without further processing in the existing architecture, especially in the case of transmission between multiple architecture nodes with low resource consumption.
[0007] The present invention solves the above technical problems in the following manner: The acquisition unit includes a control device connected to the sensor data input and the hash tree memory, which is used to calculate and store hash values based on each sensor data stream part and the lower-level hash values of the hash tree; and the control device has a root hash output for outputting the finally calculated root hash value. As a result of these measures, hash values can be calculated for each sensor data stream part of the sensor data stream and stored in the memory area at the bottom layer of the hash tree memory with a predetermined structure (for example, in the form of a simple binary tree). When all the hash values directly set at the lower level of the parent storage area are available, the upper-level hash value can be calculated based on these hash values and stored in the parent storage area, and then the lower-level hash values are no longer needed, so they can be deleted to reduce storage consumption. Therefore, during operation, it is not necessary to save all the hash values of the hash tree in the hash tree memory, but only those hash values required for calculating the upper-level hash values in the hash tree need to be saved respectively. If the root hash value of the hash tree with a predetermined structure has been calculated in this way, the root hash value can be output through the root hash output and then deleted from the hash tree memory. In this way, even when the performance of the control device is low, the clock frequency or data rate of the sensor data stream to be acquired can be achieved by adjusting especially the depth of the hash tree. For example, in a binary hash tree with a depth of 1 to 10 layers, a sensor data stream with simple numerical values can be acquired at a clock frequency of 1 Hz, while when the depth is 10 to 27 layers, it can be acquired at a clock frequency of up to 50000 Hz. Finally, according to the present invention, for the case where consecutive root hash values are formed by sensor data stream parts that are temporally continuous and non-overlapping, the entire hash tree memory is not used at any time, so that the size of the memory can be reduced accordingly, which also reduces the access time to such a memory. If a larger storage area is considered, a further advantage is that when the calculation of the hash values of the previous sensor data stream part has not been completed, the calculation of the subsequent sensor data stream part can already start, but the deeper layers of the hash tree memory are no longer occupied.
[0008] In order to be able to check not only the integrity but also the authenticity of the sensor data stream, it is proposed to connect the control device to an encryption key memory that is uniquely associated with the control device in order to electronically sign the root hash value. By means of the signature of the output root hash value thus achieved, it can subsequently be checked, for example via a public key infrastructure, whether the root hash value has been output by a specific control device and thus also by a specific acquisition unit. Due to the low performance requirements, the acquisition unit can be arranged spatially and structurally close to the sensor that generates the sensor data stream, thus making it very difficult to forge the authenticity. In addition, since only the root hash value, rather than each part of the sensor data stream, needs to be signed for authenticity checking, a correspondingly time-consuming signature procedure can be used despite the relatively low performance requirements of the acquisition unit, which also makes it unlikely that real-time data can be forged. The key memory can be, for example, a secure or trusted runtime environment, such as a Trusted Platform Module (TPM), to which the signed root hash value is transferred and from which the signature can be invoked, while the private part of the encryption key used for this purpose does not leave the key memory.
[0009] For the tamper-proof storage of the root hash value and for the simple transmission and interrogation of the same root hash value for integrity checks, the root hash output of the control device can be connected to a consensus-based, decentralized, and addressable check memory. Thus, the root hash value itself is not transmitted in the sensor data stream, which is in principle tamperable, but only its address is transmitted as a reference to the storage area in the check memory, which, due to its decentralized, consensus-based design, cannot be tampered with by a single attacker or can only be tampered with at great expense. To facilitate the synchronization of the hash tree calculation between the acquisition unit and the interrogation unit described below, it is proposed to output the address of the root hash value in the check memory together with a reference to the part of the sensor data stream that is used to calculate the root hash value. For this purpose, the control device can have a sensor data output for outputting the part of the sensor data stream and for outputting the address of the root hash value in the check memory together with a reference to the part of the sensor data stream used to calculate the root hash value. If, in a particularly advantageous embodiment, the address of the root hash value is inserted between the parts of the sensor data stream that respectively mark the end or the start of the hash tree, the additional reference to the part of the sensor data stream used to calculate the root hash value can be dispensed with. If, in addition to the reference to the part of the sensor data stream used to calculate the root hash value, information about the structure of the hash tree, in particular information about its depth and the method used for hash formation, is output together with the part of the sensor data stream, particularly simple transmission and check conditions result, since the structure of the hash tree, like the method used for hash formation, can be adapted to the current parameters of the sensor data stream, such as the data transmission rate, and no additional transmission is required for transmitting these calculation parameters.
[0010] In order to be able to check the integrity of the sensor data stream part independently of the acquisition unit, according to the present invention, an interrogation unit can be provided, which includes a sensor data input for the sensor data stream part and a control device connected to the sensor data input and the hash tree memory, for calculating and storing a hash value based on each sensor data stream part and based on the lower-level hash values of the hash tree, wherein the control device is connected to a consensus-based, decentralized and addressable check memory for interrogating the root hash value. Here, the control device and the hash tree memory can be constructed in the same way as those in the acquisition unit, so that in principle there is no need to transmit calculation parameters from the acquisition unit to the interrogation unit, that is, information about the calculation of the hash value and information about the structure of the hash tree. For example, if a different hash tree structure or a method for calculating the hash value is to be used to match the clock frequency of the sensor data stream, a central management unit can be provided, in which these calculation parameters can be stored for each sensor data stream or each acquisition unit and can be called by the interrogation unit. However, as described above, these calculation parameters can also be directly integrated into the data stream together with the address of the root hash value in the check memory.
[0011] In a particularly preferred embodiment of the invention, not only can data stream portions be interrogated and integrity-checked in a temporally staggered manner, but also the integrity of multiple data stream portions from which a complete hash tree cannot be formed and thus the root hash value cannot be calculated can be checked. This can be achieved by connecting the acquisition unit to a data memory for recording data stream portions of the sensor data stream, which data memory includes a control device connected to a hash tree memory for calculating and storing hash values based on the individual sensor data stream portions and based on the lower-level hash values of the hash tree. Thus, the interrogation unit can interrogate not only the data stream portions directly output in real time by the acquisition unit, but also any data stream portions from this data memory. If a complete hash tree cannot be formed from the interrogated data stream portions, the control device of the data memory (which can be constructed similar to the control device of the acquisition unit and thus also similar to the control device of the interrogation unit) calculates the intermediate hash values in the hash tree that are respectively closest to the root hash value (the interrogation unit cannot calculate these intermediate hash values based on the interrogated data stream portions), and transmits these intermediate hash values together with the interrogated data stream portions to the interrogation unit. Then, the control device of the interrogation unit can store these intermediate hash values in the hash tree memory and, in this way, determine the root hash value based on the transmitted sensor data stream portions. Here, if a data stream portion transmitted to the interrogation unit has been tampered with, the data memory will transmit incorrect intermediate hash values to the interrogation unit, where the integrity check described above will also fail. This has the advantage that tampering before or after the interrogated data stream portions can be detected, which also calls into question the integrity of the interrogated data stream portions.
[0012] The invention also relates to a method for operating a device of the type described above, in which hash values are calculated for individual sensor data stream portions of the sensor data stream and stored in the memory area of the lowest level of a hash tree memory having a predetermined structure, where, when all the hash values directly subordinate to a parent memory area are available, the upper-level intermediate hash values are calculated therefrom and stored in the parent memory area, after which the lower-level hash values are deleted. The method is repeated until the root hash value of the hash tree is calculated, and the root hash value can be output for checking. For integrity-checking the sensor data stream, the entire method is repeated, and the formed check root hash value is compared with the initially output root hash value. If the check root hash value and the initially output root hash value are identical, the integrity check is successful; if the check root hash value and the initially output root hash value are not identical, the integrity check fails.
[0013] In order that sensor data that appears and remains unchanged over a long period of time does not result in a predictable root hash value, it is proposed that the individual sensor data stream portions have time stamps, which are taken into account when calculating the hash values.
[0014] As described above, each newly calculated root hash value of the hash tree may have an electronic signature identifying the acquisition unit, and in addition to performing an integrity check on the sensor data stream portion, the source of the sensor data stream portion may also be checked.
[0015] Finally, as explained in detail above, if each newly calculated root hash value of the hash tree is stored in a consensus-based, decentralized inspection memory, and the address of the root hash value in the inspection memory is output together with the calculation parameters including a reference to the sensor data stream portion used to calculate the root hash value, inspection of the sensor data stream portion is facilitated.
[0016] For the integrity check, the address of the root hash value and the calculation parameters can be extracted from the sensor data stream together; the root hash value stored at the address can be called; and the root hash value can be checked for comparison based on the sensor data stream portion of the sensor data stream and the calculation parameters. Alternatively, the calculation parameters can also be queried by the management unit.
[0017] If the determined check root hash value is consistent with the called root hash value, the integrity check succeeds. If the check root hash value is inconsistent with the called root hash value, or the root hash value is not found at the specified address, the integrity check fails. In the case of a root hash value with an electronic signature, it can also be checked whether the signature is consistent with a preset, for example, stored in the management unit. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The subject matter of the invention is illustrated by way of example in the accompanying drawings, in which:
[0019] Figure 1 shows a schematic diagram of a collection unit according to the present invention,
[0020] Figure 2 shows the memory structure of a hash tree memory of such an acquisition unit, which is also schematically shown, and
[0021] Figure 3 The schematic diagram also shows on a larger scale a device according to the invention having Figure 1 The device of the collection unit. DETAILED DESCRIPTION
[0022] The device according to the invention for integrity checking of a sensor data stream comprises a collection unit 1, by means of which sensor data of a sensor 2 can be collected. For example, the sensor 2 can be arranged on a machine 3 and measure its temperature or similar parameters. The collection unit 1 itself includes not only a control device 4 but also a hash tree memory 5.
[0023] Refer to the following Figure 2Explain the memory structure within the hash tree memory 5 in more detail. In this embodiment, the hash tree is constructed in the form of a simple binary hash tree 6. This binary hash tree 6 has separate storage areas 7, 8, 9, 10 respectively, in which the hash values of the sensor data stream parts 11, 12, 13, 14 of the sensor data stream 15 can be stored. The storage areas 7 and 8 are associated with the parent storage area 16 at the upper level of the intermediate hash, and the storage areas 9 and 10 are associated with the parent storage area 17 at the upper level of the intermediate hash. The storage areas 16 and 17 are in turn associated with the parent storage area 18 at the upper level, and the root hash value of the binary hash tree 6 can be stored in this parent storage area 18.
[0024] As a result of these measures, hash values can be calculated for the respective sensor data stream parts 11, 12, 13, 14 of the sensor data stream and stored in the memory areas 7, 8, 9, 10 at the bottom layer of the hash tree memory 5 having a predetermined structure (such as in the form of a simple binary tree 6). When all the hash values directly set at the lower level of the parent storage areas 16, 17 are available, the upper-level hash values can be calculated based on these hash values and stored in the parent storage areas 16, 17. After that, the lower-level hash values are no longer needed, so the memory areas 7, 8, 9, 19 can be deleted to reduce storage consumption. Here, the hash values of the parent storage areas 16 and 17 can be calculated in parallel or sequentially, and the latter measure can make the deletion of the storage areas 7 and 8 independent of the deletion of the memory areas 9 and 10. Finally, when the intermediate hash values in the parent storage areas 16 and 17 are both available, the upper-level root hash value is also calculated and stored in the parent storage area 18. Then, the parent storage areas 16 and 17 can be deleted again. Therefore, from Figure 2 it can be seen that in principle, all the sensor data stream parts 11, 12, 13, 14 of the sensor data stream 15 are required to calculate the complete hash tree. However, for example, if in addition to the existence of the sensor data stream parts 11, 12, there is also the intermediate hash value of the parent memory area 17, or if in addition to the existence of the sensor data stream parts 13, 14, there is also the intermediate hash value of the parent memory area 16, the hash tree can also be calculated.
[0025] In order to output the most recently calculated root hash value respectively, the control device 4 of the acquisition unit 1 has a root hash output 19, which can be connected to the symbolically shown, consensus-based, decentralized and addressable check memory 20 for secure storage of the root hash value, as Figure 1 and Figure 3 shown.
[0026] In addition to the root hash output 19, the control device 4 may also have a sensor data output 21 for outputting the sensor data stream parts 11, 12, 13, 14 and for outputting the address of the root hash value in the check memory 20 together with a reference to the sensor data stream parts used for calculating the root hash value.
[0027] In a particularly preferred embodiment of the invention, the acquisition unit 1 includes an encryption key memory 22 uniquely associated with the control device 4 for electronically signing the root hash value.
[0028] In addition to the acquisition unit 1, an interrogation unit 23 may be provided. The interrogation unit includes sensor data inputs 24 for the sensor data stream parts 11, 12, 13, 14 and a control device (not shown in detail) connected to the sensor data inputs 24 and to a hash tree memory (also not shown in detail) for calculating and storing hash values based on the respective sensor data stream parts and on the lower-level hash values of the hash tree. Thus, the structure of the interrogation unit 23 may correspond to the structure of the acquisition unit 1. In addition, the control device of the interrogation unit 23 is connected to a consensus-based, decentralized and addressable check memory 20 for interrogating the root hash value.
[0029] In order to not only interrogate the sensor data stream parts 11, 12, 13, 14 at staggered times and perform integrity checks, but also to check the integrity of multiple sensor data stream parts 13, 14 (from which a complete hash tree cannot be formed and thus the root hash value cannot be calculated), according to the invention, the acquisition unit 1 is connected to a data memory 25 for recording the sensor data stream parts 11, 12, 13, 14. The data memory 25 also includes a control device (not shown) connected to the hash tree memory for calculating and storing hash values based on the respective sensor data stream parts 11, 12, 13, 14 and on the lower-level hash values of the hash tree. Thus, in addition to the storage areas for the sensor data stream parts 11, 12, 13, 14, the data memory 25 may also be constructed similarly to the acquisition unit 1.
[0030] The transmission of the sensor data stream parts 11, 12, 13, 14 from the acquisition unit 1 to the interrogation unit 23 may in principle be carried out via any, even an insecure, architecture 26 (for example via the Internet). Here, the calculation parameters for determining the hash values and the calculation parameters for the structure of the hash tree to be used may be fixedly pre-given in advance, integrated into the sensor data stream or pre-given or interrogated via a management unit 27 provided therefor.
[0031] Especially from Figure 3It can be seen that the device according to the invention and the method according to the invention can thus be implemented by collecting the sensor data stream measured by the sensor 2 through the acquisition unit 1 in the first security domain 28 and interrogating it through the insecure architecture 26 by the interrogation unit 23 in the second security domain 29. Although the sensor data can be obtained and further processed in plain text, any modification of the sensor data results in a failure of the integrity check on the side of the interrogation unit 23. In addition, not only can the sensor data stream from the sensor 2 be interrogated in real time, but also the sensor data stream portions 11, 12 of any record from the data memory 25 can be interrogated using the integrity check.
Claims
1. A method for performing an integrity check on a sensor data stream (15), characterized in that, Calculate hash values for respective sensor data stream parts (11, 12, 13, 14) of the sensor data stream (15), store the hash values as lower-level hash values in the memory areas (7, 8, 9, 10) at the bottom layer of a hash tree memory (5) having a predetermined structure, calculate upper-level hash values based on the lower-level hash values and store them in the parent memory areas (16, 17), after which delete the lower-level hash values in the memory areas (7, 8, 9, 10) at the bottom layer, and use the upper-level hash values to calculate even more upper-level hash values, wherein the parent memory areas (16, 17) are the upper-level memory areas for the memory areas (7, 8, 9, 10) at the bottom layer in the hash tree memory (5).
2. The method according to claim 1, characterized in that, Respective sensor data stream parts (11, 12, 13, 14) have time stamps, and the time stamps are taken into account when calculating the hash values.
3. The method according to claim 1, wherein Each newly calculated root hash value of the hash tree has an electronic signature for identifying the acquisition unit (1).
4. The method according to any one of claims 1 to 3, characterized in that, Store each newly calculated root hash value of the hash tree in a consensus-based, decentralized verification memory (20), and output the address of the root hash value in the verification memory (20) together with the calculation parameters including references to the sensor data stream parts (11, 12, 13, 14) used to calculate the root hash value.
5. The method according to claim 4, wherein Extract the address of the root hash value and the calculation parameters from the sensor data stream (15), call the root hash value stored at the address, and determine a verification root hash value based on the sensor data stream parts (11, 12, 13, 14) of the sensor data stream (15) and the calculation parameters for comparison.
6. An apparatus for performing the method according to any one of the preceding claims, the apparatus having an acquisition unit (1) with a sensor data input, characterized in that, The acquisition unit (1) includes a control device (4) connected to the sensor data input and the hash tree memory (5), for calculating and storing hash values based on the respective sensor data stream parts (11, 12, 13, 14) and calculating and storing upper-level hash values based on the lower-level hash values of the hash tree; and the control device (4) has a root hash output (19) for outputting the most recently calculated root hash value.
7. The device according to claim 6, characterized in that, The control device (4) is connected to an encryption key memory (22) uniquely associated with the control device (4) for electronically signing the root hash value.
8. The device according to claim 6, characterized in that, The root hash output (19) of the control device (4) is connected to a consensus-based, decentralized and addressable verification memory (20), and the control device (4) has a sensor data output (21) for outputting the sensor data stream parts (11, 12, 13, 14) and the address of the root hash value in the verification memory (20).
9. The device according to claim 8, characterized in that, The interrogation unit (23) includes a sensor data input (24) for the sensor data stream parts (11, 12, 13, 14) and a control device connected to the sensor data input (24) and the hash tree memory, for calculating and storing hash values based on the individual sensor data stream parts (11, 12, 13, 14) and calculating and storing higher-level hash values based on the lower-level hash values of the hash tree, and the control device is connected to a consensus-based, decentralized and addressable check memory (20) for interrogating the root hash value.
10. The device according to any one of claims 6 to 9, characterized in that, The acquisition unit (1) is connected to a data memory (25) for recording the sensor data stream parts (11, 12, 13, 14), and the data memory includes a control device connected to the hash tree memory, for calculating and storing hash values based on the individual sensor data stream parts (11, 12, 13, 14) and calculating and storing higher-level hash values based on the lower-level hash values of the hash tree.
Citation Information
Patent Citations
Method and apparatus for providing information authentication from external sensors to secure environments
US20130243189A1
Securing sensor data
WO2016049077A1
Data integrity authentication information generation method and device as well as data integrity authentication method and device
CN102413313A
Hash tree-based data dynamic operation verifiability method
CN103218574A
Data stream integrity
WO2019020194A1