Method, apparatus and system for securely providing data records
By employing blockchain technology and cryptographic verification mechanisms in smart devices and manufacturing equipment, the security protection issues of smart devices and manufacturing equipment when processing sensor data are solved, enabling reliable data transactions without mediation intermediaries, reducing transaction costs and improving the security of data transmission.
Patent Information
- Application Number
- CN201980094214.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-01-16
- Filing Date
- 2019-11-18
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2039-11-18
AI Technical Summary
Existing smart devices and manufacturing equipment lack effective security mechanisms when detecting and processing large amounts of sensor data, especially in the absence of mediating intermediaries, making it difficult to ensure the reliability of data protection against manipulation and transactions.
A distributed database system is built using blockchain technology. The data structure is protected through a cryptographic verification and consolidation mechanism. The detection module is used to obtain individual characteristics of objects, calculate cryptographic keys, and perform data verification and consolidation to ensure the integrity and security of the data.
It enables secure and reliable data transactions between smart devices and manufacturing facilities on the blockchain without the need for mediation or intermediaries, reducing transaction costs, providing flexible digital services, and improving the security and reliability of data transmission.
Smart Images

Figure CN113646764B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a method, an apparatus and a system for securely providing a data record, wherein the data record comprises, for example, sensor data. BACKGROUND
[0002] The increasing networking of smart devices, such as mobile phones, smart watches, or manufacturing devices leads to the fact that these smart devices and manufacturing devices detect more and more sensor data. These data should be utilized, inter alia, for monitoring the manufacture or transport of objects, such as workpieces, foodstuffs, etc. SUMMARY
[0003] Aspects of the invention are explained subsequently.
[0004] The technology of blockchains, or "Distributed Ledgers", is currently the subject of intense discussion, which can be implemented, inter alia, as a distributed database system. In addition to the application of decentralized payment systems, new application possibilities are being developed in the financial industry. In particular, transactions between companies can thereby be implemented without a mediating or clearing institution in a manipulationsgeschützt manner. This enables new business models without a trusted mediating institution, reduces transaction costs and can flexibly provide new digital services without having to set up a special infrastructure and trust relationship for this purpose. The transaction data records, or simply "transactions", secured by the blockchain comprise, for example, program codes which can also be referred to as so-called "Smart Contracts".
[0005] According to a first aspect, the invention relates to a device for calculating a cryptographic checksum of a data structure, having:
[0006] - a detection module (110), for example, for detecting individual features (M) of an object (O) by means of a detection device (A);
[0007] - a calculation module (120), for example, for calculating properties of the object individual from the individual features;
[0008] - a cryptographic module (130), for example, for providing a first cryptographic key from the individual features and / or the properties of the object individual;
[0009] - a protection module (140), for example, for cryptographically protecting the data structure by means of the cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of the first cryptographic key.
[0010] Unless otherwise indicated in the subsequent description, the terms "performing", "calculating", "in a computer-aided manner", "determining", "ascertaining", "generating", "configuring", "reconstructing" and the like preferably relate to actions and / or process steps of changing and / or producing data and / or transforming data into further data, wherein the data can be presentable or existent, inter alia, as physical variables, for example as electrical pulses. In particular, the expression "computer" is to be interpreted as broadly as possible so as to cover, inter alia, all electronic devices having data processing properties. A computer can thus be, for example, a Personal Computer, a server, a memory programmable control device (SPS), a Handheld-Computer-System, a Pocket-PC device, a mobile radio device and further communication devices, processors and further electronic devices for data processing which can process data in a computer-aided manner.
[0011] Within the context of the present application, "in a computer-aided manner" can be understood as, for example, the implementation of a method in which, inter alia, a processor performs at least one method step of the method. "In a computer-aided manner" can also be understood as "in a computer-implemented manner", for example.
[0012] Within the context of the present application, a processor can be understood as, for example, a machine or an electronic circuit. The processor can be, inter alia, a main processor (English: Central Processing Unit, CPU), a microprocessor or a microcontroller, for example an Application-Specific Integrated Circuit or a Digital Signal Processor, possibly in combination with a storage unit for storing program instructions, and the like. The processor can also be, for example, an IC (Integrated Circuit), in particular an FPGA (English: Field Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit), or a DSP (Digital Signal Processor) or a graphics processor GPU (Graphic Processing Unit). The processor can also be understood as a virtual processor, a virtual machine or a soft CPU. It can also be a programmable processor which is equipped with configuration steps for performing the methods according to the present application mentioned or which is configured with configuration steps such that the programmable processor implements the features according to the present application of the methods, components, modules or further aspects and / or sub-aspects of the present application.
[0013] Within the context of the present application, a "storage unit" or "storage module" or the like can be understood as a volatile memory, e.g. in the form of a working memory (English: Random-Access Memory, RAM), or a permanent memory, like a hard disk or a data carrier.
[0014] Within the context of the present application, a "module" can be understood as a processor and / or a storage unit for storing program instructions. For example, the processor is specifically set up to execute the program instructions in order for the processor to perform a function in order to implement or realize a method according to the present application or a step of a method according to the present application. The module may, for example, also be a node of a distributed database system which, for example, realizes a specific function / feature of the corresponding module. The corresponding module may, for example, also be configured as a separate or independent module. To this end, the corresponding module may, for example, comprise further elements. These elements may, for example, be one or more interfaces (e.g. a database interface, a communication interface - e.g. a network interface, a WLAN interface) and / or an evaluation unit (e.g. a processor) and / or a storage unit. By means of the interfaces, data may, for example, be exchanged (e.g. received, transmitted, sent or provided). By means of the evaluation unit, data may, for example, be compared, checked, processed, distributed or calculated in a computer-aided manner and / or in an automated manner. By means of the storage unit, data may, for example, be stored, retrieved or provided in a computer-aided manner and / or in an automated manner.
[0015] Within the context of the present application, "comprise", "have" and the like (especially with respect to data and / or information) can be understood as, for example, storing the corresponding information or the corresponding date (in a computer-aided manner) in a data structure / data record (which may, for example, in turn be stored in a storage unit).
[0016] Within the context of the present application, "distribute" (especially with respect to data and / or information) can be understood as, for example, distributing data and / or information in a computer-aided manner. For example, for this purpose, by means of a storage address or a unique identifier (English: unique identifier, UID), a second date is assigned to a first date by, for example, the first date and the storage address or the unique identifier of the second date being stored together in a data record.
[0017] Within the context of the present application, "provide" (especially with respect to data and / or information) can be understood as, for example, providing in a computer-aided manner. The provision may, for example, take place via an interface (e.g. a database interface, a network interface, an interface to a storage unit). Via these interfaces, the corresponding data and / or information may, for example, be transmitted and / or sent and / or retrieved and / or received at the time of the provision.
[0018] Within the context of the present application, "providing" can also be understood as e.g. loading or storing e.g. transactions with corresponding data. This can be e.g. on or by a storage module. "Providing" can also be understood as e.g. transmitting (or sending or transferring) corresponding data from one node of a blockchain or distributed database system (or its infrastructure) to another node.
[0019] Within the context of the present application, a "checksum" (e.g. data block checksum, data checksum, node checksum, transaction checksum, concatenation checksum, etc.) can be understood as e.g. a cryptographic checksum or cryptographic hash or hash value, which is formed or calculated with the aid of a cryptographic hash function, in particular with respect to a data record and / or data and / or one or more transactions and / or a sub-area of a data block (e.g. a block header of a block of a blockchain or a data block header of a data block of a distributed database system or only a part of a transaction of a data block) of a transaction. The checksum can be in particular a checksum / checksums or hash value / hash values of a hash tree (e.g. Merkle Baum, Patricia Baum). Furthermore, a "checksum" can also be understood as a digital signature or a cryptographic message authentication code, in particular. With the aid of a checksum, cryptographic protection / prevention of manipulation of transactions and data (records) stored therein can be achieved e.g. on different levels of a database system. If e.g. high security is required, a checksum is generated and checked e.g. on the transaction level. If less high security is required, a checksum is generated and checked e.g. on the block level (e.g. with respect to an entire data block or only with respect to a part of a data block and / or a part of a transaction).
[0020] Within the context of this invention, a “block checksum” can be understood as, for example, a checksum calculated for a portion or all of the transactions relating to a block of data. A node can then, for example, use the block checksum to check / ascertain the integrity / authenticity of the corresponding portion of a block of data. Additionally or alternatively, the block checksum can also be formed, in particular, from the transactions relating to the preceding / vorgaenger blocks of that block of data. This block checksum can also be implemented, in particular, using a hash tree (e.g., a Merkle tree [1] or a Patricia tree), wherein the block checksum is in particular the root checksum of a Merkle tree, Patricia tree, or binary hash tree. In particular, transactions are secured by means of other checksums from a Merkle tree or Patricia tree (e.g., in the case of transaction checksums), wherein these other checksums are in particular leaves in a Merkle tree or Patricia tree. The block checksum can thus secure transactions, for example, by forming a root checksum from these other checksums. The block checksum can be calculated, in particular, for the transactions of a specific block of data within a block of data. In particular, this data block checksum can be incorporated into subsequent data blocks of the defined data block, so as to concatenate the subsequent data block, for example, with its preceding data block, thereby making the integrity of the distributed database system verifiable. Thus, the data block checksum can, for example, function as a concatenation checksum, or be incorporated into a concatenation checksum. The header of a data block (e.g., a new data block or a data block for which a data block checksum has been formed) may, for example, include the data block checksum.
[0021] Within the context of this invention, "transaction checksum" can be understood as a checksum relating particularly to the transaction formation of a data block. Additionally, for example, the calculation of the block checksum for the corresponding data block can be accelerated, since the transaction checksum already calculated for this purpose can be immediately used as, for example, a leaf of a Merkle tree.
[0022] In the context of this invention, "concatenation checksum" can be understood as a checksum that specifically refers to or refers to the previous data block hash of the distributed database system (often referred to as "previous block hash" in technical literature) [1]. For this purpose, a corresponding concatenation checksum is formed, particularly for the corresponding previous data block. As a concatenation checksum, for example, a data block checksum or a transaction checksum of the data block (i.e., an existing data block of the distributed database system) can be used to concatenate a new data block with the (existing) data block of the distributed database system. However, it is also possible, for example, that the checksum is formed with respect to the header of the previous data block or with respect to the entire previous data block and is used as the concatenation checksum. This can also be calculated, for example, for multiple or all of the previous data blocks. For example, it is also possible to form a concatenation checksum with respect to the header and the data block checksum. However, the corresponding data blocks in a distributed database system preferably include concatenated checksums calculated for the preceding data block (especially, more preferably, the directly preceding data block), or the concatenated checksum pertains to the preceding data block (especially, more preferably, the directly preceding data block). For example, it is also possible that the corresponding concatenated checksum is formed only for the portion of the corresponding data block (e.g., the preceding data block). Thus, for example, a data block can be implemented that includes an integrity-protected portion and an unprotected portion. Thus, for example, a data block can be implemented where the integrity-protected portion of the data block remains unchanged and the unprotected portion can still be changed later. "Integrity-protected" should be understood here in particular as meaning that changes to the integrity-protected data can be detected by means of the checksum.
[0023] For example, the data stored in a transaction of a data block can be provided in different ways. Instead of this data (e.g., user data, such as measurement data, or data / ownership relationships about assets), the transaction of a data block can, for example, only include checksums for this data. The corresponding checksums can be implemented in different ways here. This could be, for example, a corresponding data block checksum of a data block (with corresponding data) in another database or distributed database system, a transaction checksum of a data block (with corresponding data in a distributed database system or another database), or a data checksum formed about said data.
[0024] Additionally, the corresponding transaction may also include a reference to or description of the storage location (e.g., the address of a file server and a description of where the corresponding data should be found on that file server; or the address of another distributed database containing said data). The corresponding data may then also be provided, for example, in other transactions of other data blocks in the distributed database system (e.g., if the corresponding data and associated checksum are included in different data blocks). However, it is also conceivable, for example, that this data may be provided via another communication channel (e.g., via another database and / or a cryptographically protected communication channel).
[0025] For example, in addition to checksums, additional data records (such as references or descriptions of storage locations) can be stored in the corresponding transactions, specifically indicating storage locations where the data can be retrieved. This is particularly advantageous in keeping the data size of the blockchain or distributed database system as small as possible.
[0026] Within the context of this invention, "securely protected" or "cryptographically protected" can be understood, for example, as protection implemented particularly through cryptographic methods. This can be achieved, for instance, by utilizing a distributed database system to provide, transmit, or send corresponding data / transactions. This is preferably achieved by combining various (cryptographic) checksums in a manner that these checksums work in a particularly synergistic manner to, for example, improve the security of the transaction data or cryptographic security. In other words, within the context of this invention, "securely protected" can also be understood particularly as "cryptographically protected" and / or "protected from manipulation," where "protected from manipulation" can also be referred to as "protected for integrity."
[0027] In the context of this invention, “concatenating the data blocks / data blocks of the distributed database system” can be understood, for example, as the data blocks each including the following information (e.g., concatenating checksums): the information refers to another data block or multiple other data blocks of the distributed database system or references another data block or multiple other data blocks of the distributed database system [1][4][5].
[0028] In the context of this invention, "insertion into a distributed database system" can be understood, for example, as transmitting a transaction or a data block containing such a transaction to one or more nodes of the distributed database system. If such transactions (e.g., through the node) are successfully verified, these transactions are concatenated, in particular, as new data blocks with at least one existing data block of the distributed database system [1][4][5]. For this purpose, the corresponding transactions are stored, for example, in the new data block. In particular, this verification and / or concatenation can be performed by trusted nodes (e.g., blockchain oracles or blockchain platforms). In particular, a blockchain platform can be understood herein as Blockchain as a Service, as particularly suggested by Microsoft or IBM. In particular, trusted nodes and / or nodes can respectively register node checksums (e.g., digital signatures) in data blocks (e.g., in those data blocks verified and generated by them, which are then concatenated) in order to enable, in particular, the identifiability of the creator of the data block and / or the identifiability of the node. Here, node checksums indicate which node, for example, has concatenated the corresponding data block with at least one other data block in the distributed block system.
[0029] In the context of this invention, "transaction" or "multiple transactions" can be understood as, for example, a smart contract [4][5], a data structure, or a transaction data record, which in particular includes one or more of the transactions. In the context of this invention, "transaction" or "multiple transactions" can also be understood, for example, as transaction data of a data block in a blockchain. A transaction can in particular include, for example, program code that implements a smart contract. For example, in the context of this invention, a transaction can also be understood as a control transaction and / or a confirmation transaction. Alternatively, a transaction can be, for example, a data structure that stores data (e.g., control instructions and / or contract data and / or other data, such as video data, user data, measurement data, etc.). In the context of this invention, a "transaction" can also be, for example, a message or a communication message. Correspondingly, a message is, for example, a transaction, wherein the message includes, for example, control instructions for operating a device and / or prerequisites for executing the control instructions (e.g., pre-given requirements).
[0030] In particular, phrases such as "store transactions into data blocks" and "store transactions" should be understood as either direct or indirect storage. Direct storage, for example, can be understood as the corresponding data block or transaction (in the distributed database system) including the corresponding data. Indirect storage, for example, can be understood as the corresponding data block or transaction including checksums for the corresponding data and, where necessary, additional data records (e.g., references or descriptions of storage locations), and the corresponding data is therefore not directly stored in the data block (or transaction) (i.e., instead of checksums only for this data). In particular, when storing transactions into data blocks, these checksums can be verified, for example, as explained in the "Insertion into Distributed Database Systems" section.
[0031] In the context of this invention, “program code” (e.g., smart contracts or also chaincode) can be understood, for example, as program instructions or multiple program instructions stored in one or more transactions. The program code is particularly executable and is executed, for example, via a distributed database system. This can be achieved, for example, by means of an execution environment (e.g., a virtual machine), wherein the execution environment or the program code is preferably Turing-complete. The program code is preferably executed via the infrastructure of a distributed database system [4][5]. Here, for example, a virtual machine is implemented via the infrastructure of a distributed database system.
[0032] In the context of this invention, a “smart contract” (or also called chaincode) can be understood as, for example, executable program code [4][5] (see especially the definition of “program code”). Smart contracts are preferably stored in transactions of a distributed database system (e.g., a blockchain), for example in blocks of data within the distributed database system. For example, a smart contract can be executed in the same manner as that explained in the definition of “program code”, especially in the context of this invention.
[0033] Within the context of this invention, "smart contract process" or "smart contract" can also be understood in particular as the execution of program code or smart contracts through a distributed database system or its infrastructure during the process.
[0034] In the context of this invention, “Proof-of-Work-Nachweis” can be understood as, for example, solving computationally intensive tasks, particularly those based on the content of data blocks / determined transactions [1][4][5]. For example, such computationally intensive tasks are also referred to as kryptographisches puzzles.
[0035] In the context of this invention, “distributed database system” (which may also be referred to as a distributed database) can be understood as, for example, a decentralized distributed database, a blockchain, a distributed ledger, a distributed storage system, a system based on distributed ledger technology (DLT) (DLTS), an anti-correction database system, a cloud, a cloud-service, a blockchain in the cloud, a distributed storage system, or a peer-to-peer database. For example, different implementations of blockchain or DLTS may also be used, such as blockchains or DLTS using a directed acyclic graph (DAG), cryptographic puzzles, hash graphs, or combinations of the aforementioned implementation variations [6][7]. For example, different consensus algorithms may also be implemented. For example, this could be achieved through consensus methods such as cryptographic puzzles, gossip-about-gossip algorithms, virtual voting, or combinations thereof (e.g., a combination of gossip-about-gossip algorithms and virtual voting) [6][7]. A “distributed database system” can also be understood, for example, as a distributed database system in which at least a portion of its nodes and / or devices and / or infrastructure is implemented via the cloud. For example, the corresponding components are implemented as nodes / devices in the cloud (e.g., as virtual nodes in virtual machines). For example, this could be achieved using VM-Ware, Amazon Web Services, or Microsoft Azure. Due to the high flexibility of the described implementation variants, the sub-aspects of the mentioned implementation variants can be combined with each other, for example, by using a hash graph as a blockchain, where the blockchain itself can also be, for example, blockless.
[0036] If, for example, a directed acyclic graph (DAG) is used (e.g., IOTA or Tangle), then the transactions, blocks, or nodes of the graph are connected to each other via directed edges. This specifically means that the edges (preferably all edges) have the same direction (preferably always the same direction), similar to this, for example, in the case of time. In other words, it is particularly impossible to travel backward (i.e., in the opposite direction to the common same direction) towards or jump to a transaction, block, or node in the graph. Here, acyclicity specifically means that there are no cycles when traversing the graph.
[0037] Distributed database systems can be, for example, public distributed database systems (e.g., public blockchains) or closed (or private) distributed database systems (e.g., private blockchains).
[0038] If, for example, a public distributed database system is involved, this means that new nodes and / or devices can join or be accepted by the distributed database system without authorization, verification, registration information, or credentials. In particular, in this case, the operators of the nodes and / or devices can remain anonymous.
[0039] If the distributed database system is, for example, a closed distributed database system, then new nodes and / or devices need, for example, valid authorization and / or valid verification information and / or valid credentials and / or valid registration information in order to be able to join the distributed database system or be accepted by the distributed database system.
[0040] A distributed database system can also be, for example, a distributed communication system for data exchange. This can be, for example, a network or a peer-to-peer network. Alternatively or additionally, the present invention can also be implemented using a peer-to-peer application instead of a distributed database system.
[0041] Correspondingly, a peer-to-peer (P2P) communication protocol can be used instead of a distributed database system. Here, the message / transaction mentioned in the distributed database system is the corresponding message in the P2P communication protocol or the storage of corresponding data in the corresponding message. Storing a transaction in a distributed database system should be understood as delivering the corresponding message to the P2P communication infrastructure implementing the P2P communication protocol. Alternatively, a P2P interface or P2P application can be used, for example, instead of a distributed database system, to store and / or transmit the corresponding transaction or message.
[0042] In the context of this invention, a “data block” that may also be referred to as a “ring” or “block” depending on the context and implementation can be understood, for example, as a data block in a distributed database system (e.g., a blockchain or peer-to-peer database), which is particularly implemented as a data structure and preferably includes one or more transactions in a transaction. In one implementation, for example, the database (or database system) may be a DLT-based system (DLTS) or a blockchain, and the data block may be a block of the blockchain or DLTS. A data block may include, for example, a description of the size of the data block (data size in bytes), a data block header, a transaction counter, and one or more transactions [1]. The data block header may include, for example, a version, a concatenation checksum, a data block checksum, a timestamp, proof-of-work evidence, and a one-time nonce (one-time value, random value, or counter used for proof-of-work evidence) [1][4][5]. A data block may also simply be a defined storage area or address area of total data stored in a distributed database system. Thus, for example, blockless distributed database systems can be implemented, such as IoT Chain (ITC), IOTA, and Byteball. In this case, the functionality of blockchain blocks and transactions are combined to ensure, for example, that the transactions themselves guarantee (i.e., are stored in a secure manner) a sequence or chain of transactions (in the distributed database system). For this purpose, for example, transaction checksums can be concatenated together, preferably using individual checksums or transaction checksums of one or more transactions as the concatenation checksum, which is stored together with the corresponding new transaction when the new transaction is stored in the distributed database system. In this implementation, a data block may also include one or more transactions, where in the simplest case, one data block corresponds to one transaction.
[0043] In the context of this invention, "one-time random number" can be understood as, for example, a one-time random number for a password (an abbreviation for "used only once" [2] or "number used once" [3]). In particular, a one-time random number refers to individual numbers or letter combinations that are preferably used only once in the relevant context (e.g., transaction, data transfer).
[0044] Within the context of this invention, "the preceding data block of a (determined) data block in a distributed database system" can be understood as, for example, the data block that directly precedes the (determined) data block in the distributed database system. Alternatively, "the preceding data block of a (determined) data block in a distributed database system" can also be understood as all data blocks in the distributed database system that precede the determined data block. Thus, concatenation checksums or transaction checksums can be formed, particularly via only the data blocks (or their transactions) that directly precede the determined data block, or via all the data blocks (or their transactions) that precede the first data block.
[0045] In the context of this invention, "blockchain node," "node," "node of a distributed database system," etc., can be understood as, for example, a device (e.g., a field device, a mobile phone), a computer, a smartphone, a client, or a user, which performs operations for (using) a distributed database system (e.g., a blockchain), [1][4][5]. Such a node can, for example, execute transactions of a distributed database system or its data blocks, or insert or concatenate new data blocks with new transactions into a distributed database system by means of new data blocks. In particular, this verification and / or concatenation can be performed by a trusted node or only by a trusted node. A trusted node is, for example, a node that has additional security measures (e.g., firewalls, access restrictions on the node, etc.) to prevent manipulation of the node. Alternatively or additionally, when concatenating a new data block with a distributed database system, the trusted node can, for example, store a node checksum (e.g., a digital signature or certificate) in the new data block. In this way, in particular, proof can be provided that the corresponding data block was inserted by a determined node, or that its origin is explained. The devices (e.g., corresponding equipment) are, for example, devices in technical systems and / or industrial plants and / or automated networks and / or manufacturing facilities, and these devices are particularly nodes in distributed database systems. Here, these devices can be, for example, field devices or devices in the Internet of Things (IoT), which are also, in particular, nodes in distributed database systems. A node may also include, for example, at least one processor to perform, for example, its computer-implemented functions.
[0046] Within the context of this invention, "blockchain oracle" can be understood as, for example, a node, device, or computer having a security module, which is governed by, for example, software protection mechanisms (e.g., cryptographic methods), mechanical protection devices (e.g., a sealable housing), electrical protection devices (e.g., tamper-proof or protection systems that include deleting data from the security module without allowing the blockchain oracle to be used / disposed of) or a combination of the aforementioned possibilities. Here, the security module may include, for example, cryptographic keys or secrets (e.g., strings) necessary for calculating checksums (e.g., transaction checksums or node checksums).
[0047] Within the context of this invention, "computer" or "device" can be understood as, for example, a computer (system), client, smartphone, device, or server, which are located outside the blockchain and are not part of the infrastructure of the distributed database system or form a separate, independent infrastructure. Devices are, for example, manufacturing equipment and / or electromechanical equipment and / or electronic equipment and / or devices for automation networks (e.g., for industrial technology installations, manufacturing installations, energy or resource distribution devices), which in particular cannot communicate directly with the distributed database system. Correspondingly, nodes can be, for example, devices, computers, virtual devices, or virtualized computers.
[0048] Within the context of this invention, "separate and / or direct communication channels" can be understood, for example, as data transmission (e.g., sending, receiving, transmitting, providing, or conveying) via a communication channel. For example, transactions / messages can be sent more quickly via this channel, and confirmation of the data exchange is stored in the distributed database system. This allows, for example, the transmission of important and / or time-critical transactions or messages (e.g., control instructions or control transactions) to the corresponding target (e.g., a device) at a higher speed, and, for example, avoids the slower data transmission in the distributed database system (e.g., when replicating data blocks / transactions). For example, for the purposes of this invention and the aspects, embodiments, implementations, and variations thereof mentioned herein, separate and / or direct communication channels can be constructed for data transmission between devices (and / or nodes). For example, in the case of a direct communication channel, transactions / messages are exchanged directly between the sender (e.g., (first)) and the receiver / target (e.g., a device to execute, process, or evaluate control instructions) without the participation of other nodes and / or devices in the distributed database system. In the case of a separate communication channel, nodes and / or devices in the distributed database system can, for example, participate in the data exchange. If a separate and / or direct communication channel is successfully established between the sender and receiver (and thus, in particular, a communication connection is established), data can be exchanged between the sender and receiver, for example, in the form of transactions or messages. If, for example, the communication channel is closed / terminated (and thus, in particular, the communication connection is terminated), the result of the data transmission, for example, in the form of a transaction (e.g., as a transmission confirmation transaction or confirmation transaction), is stored, for example, in a distributed database system (e.g., in a data block of the distributed database system). The result of the data transmission may be, for example, confirmation of the transmission or receipt of the corresponding transaction / message, and / or analysis results, and / or the last transmitted transaction / message transmitted via the separate and / or direct communication channel before the communication channel was closed. For example, the storage of transactions and results can be performed by the sender and / or receiver. Analysis results may be, for example, confirmation of the receipt of a message / transaction, and / or the message / transaction and, for example, its control instructions can be processed by the target / receiver (e.g., by the target's confirmation of executability). For example, this can be stored in a transaction (e.g., in an executability confirmation transaction). Alternatively or additionally, the executability confirmation transaction is stored in the distributed database system. An executability confirmation transaction here includes, for example, a clear identifier of a device capable of executing control instructions, and / or, for example, control instructions that specify the latest time to execute the message / transaction.Alternatively or additionally, the executability confirmation transaction may include data about execution, such as how well the control instructions are performed or to what extent the control instructions are performed (e.g., how quickly the control instructions are performed, when the control instructions are performed safely, how accurately or precisely the control instructions are performed—e.g., when performing manufacturing control instructions, in order to record, for example, the machining of the workpiece).
[0049] Alternatively or additionally, the executability confirmation transaction may include, for example, device-specific data of the corresponding device (e.g., target / receiver) (e.g., device type; current device status, such as ready to operate, requiring maintenance, corresponding device error status; device serial number; device location; checksum / hash of the control command to be executed, calculated, for example, by means of the aforementioned invention; tools used; materials used, or combinations of the aforementioned data), which is relevant to the execution of the control command, wherein, for example, the device-specific data is determined by the corresponding device at the moment the device confirms executability. Here, for example, the confirmation of executability and the determination of the device-specific data occur (approximately) at the same time (e.g., within a time window of a few seconds or minutes). For example, the data of the executability confirmation transaction may have already been exchanged between the sender and receiver before the executability confirmation transaction is stored, for example, in a distributed database system. For example, the executability confirmation transaction may also be cryptographically protected (e.g., the executability confirmation transaction may be encrypted or protected by a transaction checksum). For example, the last message exchanged via the communication channel may also be stored in the transmission confirmation transaction (e.g., if the communication channel is interrupted), and the transmission confirmation transaction may then be stored, for example, in a distributed database system. For example, the last exchanged message can be used to continue data exchange or data transmission when the communication channel is rebuilt. Transmission confirmation transactions can also be cryptographically protected, for example. Transmission confirmation transactions can include, for example, control commands and / or control transactions and / or the last exchanged message between the sender and receiver. The continuation of data exchange or data transmission can also be used for other data transmissions, and is not particularly limited to the transmission or exchange of a single message.
[0050] Separate and / or direct communication channels are advantageous to improve transmission speed and / or transmission latency. For example, a hybrid approach is also possible, where corresponding communication channels are used for time-critical control instructions (e.g., those with high or high priority). For example, it can be determined, based on execution requirements (e.g., time-critical control instructions are priority control instructions for real-time applications), whether a corresponding control instruction is involved, which should be transmitted via a corresponding separate and / or direct communication channel. Alternatively or additionally, the determining module can determine, for example, the corresponding instruction for data transmission of the message when determining the message control data record.
[0051] In the context of this invention, "object" can be understood as, for example, a physical object, a physical article, a workpiece (e.g., a motor part or engine part or an electronic component or a circuit board having an electronic component), an intermediate product in the process of manufacturing, a raw material (e.g., diamonds, petroleum), a food (e.g., milk or bananas), or equipment (e.g., electrical equipment, electromechanical equipment, electronic equipment, or mechatronics equipment).
[0052] Within the context of this invention, "individual characteristics" (or simply "characteristics") can be understood as (e.g., in data form) features that can be detected from or via an object by a sensor and can, for example, correspond to a physical quantity (e.g., the wavelength of light). Here, individual characteristics are, for example, properties of an individual object; that is, for example, these features or data correspond to unique combinations of sequences of ones and zeros in binary encoded data form (digital fingerprints or a unique identifier), which can, for example, be fixedly assigned to a corresponding object or the object itself. Individual characteristics can, for example, be surface features of the object (e.g., scratches, surface roughness). Alternatively or additionally, individual characteristics can, for example, be spectral data about the object (e.g., measured spectra, hyperspectral images). For example, the object can be a gemstone, crude oil, or food, wherein the spectrum of the object or a predetermined location of the object (e.g., a predetermined facet and / or position) is detected, for example, by means of a detection device in the form of a spectrometer. In this regard, individual characteristics can, for example, be spectral individual characteristics. Individual characteristics can also, for example, be features that cannot, for example, be removed from the object without damaging or altering it. For example, the corresponding characteristic can be referred to as an inherent individual characteristic of the object.
[0053] Individual characteristics can also be, for example, individual characteristics of a noise signal detected by a detection device (e.g., an oscilloscope). If the object is, for example, an electronic component, then, for example, the noise signal or signal of the object individual (e.g., a signal generator that produces a specific, unchangeable signal, which can be configured once) can be detected via the object's interface. In the case of this noise signal, the amplitude of the noise signal can be detected and / or considered for a defined resistance and / or attenuation. For example, a pre-given test signal can also be provided by the object, and in this case, signal distortion of individual characteristics can be considered if necessary. Alternatively or additionally, the detection device can send a test signal, for example, transmitted / transmitted through a pre-given circuit of the object. For example, the object or its corresponding circuitry generates a response, for example, including the test signal, which is transmitted to the detection device. Then, for example, the individual effect of the circuitry on the test signal is detected as an individual characteristic by the detection device. For example, such an individual effect can be distortion of the test signal. Correspondingly, individual characteristics can be, for example, individual electronic characteristics. Individual characteristics can also be, for example, acoustic characteristics of the object (e.g., motor noise, operating noise). To enable detection devices to detect individual characteristics as easily as possible, object data records are used to pre-define the manner and location (e.g., configuration) on the object. This object data record can be provided, for example, through a database (e.g., a distributed database system), or it can be retrieved from the object by means of a data storage device attached to the object for the detection module or detection device. The object may also include a data storage device. Here, the object data record may include, for example, information such as: what type of measurement should be performed (e.g., optical, spectral, acoustic, electrical, photoacoustic, multispectral photoacoustic), what type of sensor should be used (e.g., microphone, ultrasonic sensor, infrasound sensor, spectral measurement system, photoacoustic measurement system), at what location, at what time period, and using what measurement parameters (e.g., attenuation; signal filters, such as high-pass, low-pass, band-pass, frequency, wavelength) to detect individual characteristics.
[0054] Alternatively, for example, for objects of the same type (e.g., workpieces of the same type), corresponding information necessary for detecting individual features is fixedly pre-defined. For example, in the case of workpiece-shaped objects, the underside of the object is detected, or, for example, markers are placed on the object so that the object can find the corresponding position on the object and the individual feature can be detected. This fixedly pre-defined information may, for example, be stored in a database system (e.g., a distributed database system) for corresponding objects of the same type or fixedly pre-configured in the corresponding device.
[0055] Within the context of this invention, "characteristics of an individual object" (or simply "characteristics") can be understood, for example, as processed individual features (e.g., through data processing), such individual features are processed in particular to make the individual characteristics reproducible for the same individual characteristics. In particular, tolerance values can be considered in this case to compensate, for example, for measurement tolerances or measurement inaccuracies of the detection device. The characteristics of an individual object can be, for example, a digital fingerprint of the object. A digital fingerprint is calculated, for example, by means of a digital fingerprint algorithm (e.g., the Rabin fingerprint algorithm). If the individual characteristic is, for example, a signal or noise signal, the signal-to-noise ratio, the phase, frequency, wavelength information, and frequency amplitude can be used. The individual characteristic can also be evaluated, for example, with respect to wavelength and amplitude in the spectrum. In the case of hyperspectral images, for example, the intensity of the wavelength at one or more image locations or on the object (or in the corresponding detected image) can be evaluated with respect to the corresponding wavelength of the image.
[0056] Before calculating the corresponding characteristics of a given individual feature, the individual feature may be preprocessed to compensate for measurement inaccuracies. For example, the measured values of the individual feature may lie within a possible value range (e.g., 1 to 100). This value range may be divided into pre-defined intervals, such as five intervals (1-20, 21-40, 41-60, 61-80, 81-100). Then, interval-specific values are assigned to each interval (e.g., 1-20: A, 21-40: B, 41-60: C, 61-80: D, 81-100: E). If, for example, the measured values of the individual feature are evaluated or preprocessed, it is then examined which interval a specific measured value falls into, and the interval-specific value is used to calculate the digital fingerprint. For example, for values 1 and 100, "AE" would be the result. Alternatively, other methods may be used, such as the average method or the moving average method. The corresponding potentially preprocessed individual features are then used, for example, as input parameters to an algorithm for calculating the digital fingerprint. Alternatively or additionally, the aforementioned variations of preprocessing / processing may, for example, be applied to data (individual characteristics and / or characteristics of an object individual) used to determine, provide, or compute a first cryptographic key. Alternatively, for example, the interpreted preprocessing / processing may be applied to the corresponding data (e.g., individual characteristics and / or characteristics of an object individual) before it is also used for another purpose. For example, a cryptographic checksum can be computed based on this thus processed data in such a way that the data is used as a secret, for example, when computing the cryptographic checksum (e.g., this can be used by a device or verification device).
[0057] Within the context of this invention, "message" can be understood, for example, as a message in a communication protocol and / or a transaction in a database system (e.g., a distributed database system). For example, a message may correspond to a data structure, or a message may include a data structure. For example, a corresponding message may also include a corresponding cryptographic checksum.
[0058] Within the context of this invention, "data structure" can be understood, for example, as a message or transaction. Alternatively, a message or transaction may include a corresponding data structure. For example, the data structure, message, or transaction may, if necessary, include a corresponding cryptographic checksum for the data structure.
[0059] In the context of this invention, a “cryptographic key”, such as a first cryptographic key and / or a second cryptographic key and / or a third cryptographic key, can be understood as the private key of a symmetric cryptographic key pair or the public key of an asymmetric cryptographic key pair.
[0060] In the context of this invention, "target" can be understood, for example, as a device or receiver to which a message is to be transmitted by means of a communication protocol.
[0061] Within the context of this invention, "message priority" can be understood, for example, as the manner and / or order in which corresponding messages are processed and / or forwarded by nodes / devices. Here, high priority means, for example, that the corresponding message should be processed as quickly and / or efficiently as possible compared to messages with lower priority. In other words, messages with higher priority are preferred over messages with lower priority.
[0062] For example, the data structure used by the present invention may also include other data, such as control instructions, so as to control further transport or further processing of the object if, for example, it is determined by the present invention that the object is real or corresponds to an object for which a corresponding data structure (e.g., with a checksum) has been stored, for example, in a distributed database system.
[0063] Particularly likely with this invention is the realization of a decentralized (blockchain-based) infrastructure that manages and controls the handling of actual or physical items (e.g., objects) via digital infrastructure (e.g., production, transportation, and verification of their authenticity). Digital twins are often generated, for example, for physical objects, to control further processing of the object (e.g., a workpiece) and / or record its transportation and working steps. For example, data about the digital twin can be stored in a data structure. If, for example, such an object is delivered, there is a need or necessity to verify whether the object is indeed the object assigned to the digital twin. To solve this task, individual characteristics of the object are detected, for example, by a detection device. If the object is, for example, a workpiece manufactured by means of machining, then the individual characteristics can be, for example, the surface structure of the object. In this case, the individual characteristics can be detected, for example, at a pre-given location on the object by a detection device (e.g., a surface inspection device such as a 3D surface scanner or surface camera), where, for example, the individual characteristics in this case are individual surface features of the object. It is also conceivable, for example, that digital fingerprints are incorporated into the object as individual characteristics. The fingerprint or digital feature cannot be determined by the naked eye and / or without knowledge of its type and location, or can only be determined with considerable technical effort. Correspondingly, information for detecting individual characteristics may be located in a protected memory of the device, preventing unauthorized access. The included fingerprint may, for example, be surface roughness generated during the manufacture of the object. Alternatively or additionally, the fingerprint can be achieved by applying color or particles, wherein, for example, color or particles are applied to generate an individual spectrum for the object. For this purpose, different colors / particles may be distributed on the surface of the object, such as generating a geometric spectrum so that a pre-given spectrum can be measured, for example, at a specific location on the object. The spectrum or color / particles are selected, for example, such that they are not within the spectrum visible to the human eye. This may, for example, be a spectrum exceeding 800 nm (e.g., wavelengths > 800 nm, such as wavelengths in the range between 800 nm and 1000 nm).
[0064] Individual characteristics can also be features different from surface features. For example, an individual characteristic can be spectral data about an object. For example, the object can be a gemstone, crude oil, or food, where the object's spectrum or a pre-defined location (e.g., a pre-defined facet and / or position) is detected, for example, by means of a detection device in the form of a spectrometer. In this regard, an individual characteristic can be, for example, a spectral individual characteristic. An individual characteristic can also be, for example, an individual characteristic of a noise signal detected by a detection device (e.g., an oscilloscope). If the object is, for example, an electronic component, then, for example, the noise signal or signal of the object individual can be detected via the object's interface (e.g., a signal generator that produces a specific, unchangeable signal, which can be configured once). In the case of a noise signal, for example, the amplitude of the noise signal can be detected and / or considered for a defined resistance and / or attenuation. For example, a pre-defined test signal can also be provided by the object, and in this case, signal distortion of the individual characteristics can be considered if necessary. Alternatively or additionally, for example, the detection device can send a test signal, which is transmitted / transmitted, for example, through a pre-defined circuit of the object. For example, the object or its corresponding circuit generates a response, which includes, for example, the test signal, and this response is transmitted to the detection device. Then, for example, the individual effect of the circuit on the test signal is detected as an individual characteristic by a detection device. This individual effect can be, for example, distortion of the test signal. Correspondingly, the individual characteristic can be, for example, an individual electronic characteristic.
[0065] Depending on the object and / or the corresponding configuration / specification, individual characteristics can be, for example, individual surface characteristics and / or individual spectral characteristics and / or individual electronic characteristics. Individual characteristics can also be, for example, acoustic characteristics, photoacoustic characteristics, or multispectral photoacoustic characteristics. Corresponding individual characteristics can be reproducibly detected for the object.
[0066] Individual characteristics can also be a combination of the examples of individual characteristics mentioned above.
[0067] When using individual features, the characteristics of the individual object can then be calculated, for example. In this case, tolerance values for the individual features can be considered, for example, to generate reproducible characteristics of the individual object. The characteristics of the individual object are advantageous in order to, for example, compensate for measurement inaccuracies when detecting individual features.
[0068] The first cryptographic key can be calculated, for example, based on individual characteristics and / or the properties of an object, by using these characteristics as input parameters for deriving the cryptographic key (e.g., the first cryptographic key). Alternatively or additionally, the individual characteristics and / or the properties of the object can be compared with a pre-given reference value, and the first cryptographic key is released by the cryptographic module after sufficient agreement with the pre-given reference value. In this case, the first cryptographic key is preferably protected from access by the cryptographic module (e.g., through the key storage of the cryptographic module or through cryptographic encryption) until the individual characteristics and / or the properties of the object that conform to the pre-given reference value are detected by a detection device or calculated by a calculation module. For example, the corresponding reference value is also protected from access.
[0069] The first cryptographic key can then be used to digitally sign the data structure, or in a variant implementation, the first cryptographic key can be used to verify the digital signature of the data structure.
[0070] For example, it's also possible that an entity (e.g., a processing device / node that creates the data structure for the object and stores it in a distributed database system, or an operator of the processing device / node) additionally uses other cryptographic checksums to protect the data structure. These other checksums are, for example, transaction checksums, and are used, for example, to ascertain whether the object is actually assigned to the data structure. These other checksums are, for example, generated using a cryptographic key that can be assigned to the entity in such a way that, for example, a public key is provided by the entity to enable verification of the other checksums.
[0071] The present invention is advantageous in that, for example, the data structure can only be digitally signed if the corresponding object physically exists. To prevent, for example, the first cryptographic key from being extracted from the device used for digital signing by an unauthorized person (e.g., if the object exists and a digital signature is performed), the device may include corresponding security measures. This could be, for example, a stable housing that prevents access to the device's components and memory. Alternatively or additionally, the device may be protected, for example, by means of a protective film (e.g., a drill-proof protective film), which, if necessary, erases sensitive data, such as the first cryptographic key or reference values, in the event of manipulation of the device (e.g., in the event of breaking / drilling open the housing).
[0072] For example, a data structure can be a message, or a message can include a data structure, wherein the message is, for example, stored through a distributed database system, such as a blockchain, and the data structure is a transaction of the distributed database system, and the cryptographic checksum is, for example, a transaction checksum. For example, attaching a cryptographic checksum to the data structure allows verification of the data structure's integrity and / or origin and / or authenticity, and the attribution of the data structure to objects.
[0073] In a first embodiment of the device, the characteristics of an individual object are calculated taking into account a pre-given tolerance value for individual characteristics.
[0074] The device is advantageous in that it compensates for measurement inaccuracies, for example, when calculating characteristics, so as to reproducibly calculate the characteristics of an individual object when necessary for a specific object. For example, a tolerance value can be selected such that, in the case of the spectral characteristics of an individual object, such as food, if the object or food is no longer sufficiently fresh, a first key is not provided (or a valid first key cannot be provided). If the object is, for example, a banana, the tolerance value for the spectrum of the banana's surface can be selected such that when a large area of the banana turns brown (e.g., there is a significant reduction in the green and / or yellow components in the spectrum, such that, for example, the corresponding reference value is not exceeded), a first key is not provided or generated for these bananas (or a valid first key cannot be provided). Correspondingly, at the point of transport or at the intermediary, bananas or the supply of bananas containing these bananas can no longer be confirmed / stored as "fresh" in the supply chain by means of a message with a data structure or such a data structure in a distributed database system. In the same way, other objects in the form of perishable goods can be monitored in a distributed database system, for example, by means of a message / data structure. Then, a corresponding tolerance value is selected so that if perishable goods deteriorate too much (e.g., food expires or spoils), the first cryptographic key is not provided if necessary. Alternatively, for example, if the tolerance value is exceeded, an alternative cryptographic key can be provided, based on which points in the record of the object's transport were exceeded. In other words, by means of the tolerance value, for example, a threshold can be specified, in which case, in particular, a corresponding valid first cryptographic key is not provided or a valid cryptographic checksum is not created. In particular, in this case, the tolerance value may correspond to a threshold.
[0075] In other embodiments of the device, the first cryptographic key may be calculated, for example, based on the characteristics and / or individual features and / or strings of the object. Alternatively, a cryptographic checksum may be calculated instead of the first cryptographic key.
[0076] The device is advantageous in that it can more securely generate a first cryptographic key, for example, in combination with a string (which may also be referred to as a character chain). For example, characteristics of an individual object can be used in combination with the string to provide the first cryptographic key (e.g., to compute the first cryptographic key using a key derivation function). The string can be secret and can only be read and / or accessed within the device and / or cryptographic module, making it preferably unavailable outside the device. Alternatively or additionally, the string can be selected such that it is pre-given, for example, by another cryptographic key or another cryptographic key. In this case, for example, the other cryptographic key can be pre-given by an operator or a machine that processes or manipulates the object. This can be, for example, a public key or a private key, where the choice of key depends, for example, on the trust relationship between the parties involved in processing / managing the object. The string can also be selected according to function so that a cryptographic key is generated according to function (e.g., see subsequent embodiments). For example, a cryptographic key can be generated in such a way that it can be used to decrypt the first cryptographic key upon provision.
[0077] In other embodiments of the device, a second cryptographic key is calculated, for example, based on characteristics and / or individual features and / or strings, and the second cryptographic key is used to decrypt the first cryptographic key.
[0078] This is advantageous, for example, in order to secure the provision of the first cryptographic key. The first cryptographic key is, for example, first encrypted and only decrypted by the second cryptographic key, and thus makes it particularly usable.
[0079] In other embodiments of the device, for example, the characteristics and / or individual features are compared with corresponding reference values and the first cryptographic key is released via the cryptographic module when the reference value matches the characteristics and / or individual features with sufficient precision.
[0080] In other embodiments of the device, the data structure includes object data records, which specify at which geometric points and / or interfaces the detection device can detect individual features.
[0081] The device is advantageous in that it can, for example, define a specific selected area or interface of an object, via which individual characteristics can be detected by a detection device. If, for example, the object is an electronic component, then the interface may be, for example, the object's interface.
[0082] In other embodiments of the device, the object data record includes, for example, encrypted individual characteristics and / or object individual properties, wherein, for example, the encrypted individual characteristics and / or object individual properties can be decrypted by means of a first cryptographic key or a third cryptographic key.
[0083] The device is advantageous in that it allows for the verification of characteristics by the recipient (e.g., in the sense of goods supply) to determine, for example, how much individual characteristics and / or the properties of an individual object have changed during object handling. This is relevant, for example, when the object is transported over a long transport route or when multiple production steps are performed during object production. In these and other cases, a data structure is created for the object and stored, for example, in a distributed database system (as explained above). For example, this data structure may additionally include information about the manufacturing steps, manufacturing conditions (temperature during manufacturing), tools used, and materials used. During transport, the data structure may, for example, include information about transport conditions (cold chain temperature, location information, etc.). This additional information may, for example, be referred to as other object-related data. For example, in the case of transport, the object may be a transport container including corresponding sensors and / or the device. The transport container may, for example, be a transport container for milk, gemstones, or other food / materials. The transport container may, for example, include the device according to the invention and corresponding detection equipment.
[0084] In other embodiments of the device, the object data record includes, for example, other object-related data, such as measurements of the object, measurements about the object, manufacturing specifications of the object, and the location of the object. This other object data is detected, for example, by sensors of the device for the object or by sensors of the object. These sensors are, for example, GPS modules and / or temperature sensors and / or optical sensors and / or acoustic sensors and / or photoacoustic sensors, which detect, for example, corresponding characteristics of the object.
[0085] For example, sensor values can be detected during the manufacture of an object or during its transport, and stored, for example, in a distributed database system (preferably by means of a data structure combined with a cryptographic checksum).
[0086] In other embodiments of the device, the first cryptographic key and / or the second cryptographic key and / or the third cryptographic key are calculated with regard to a secret character chain, and / or the first cryptographic key and / or the second cryptographic key and / or the third cryptographic key are either the private key of an asymmetric key pair or a symmetric key.
[0087] In other embodiments of the device, the data structure is a transaction of a distributed database system and the cryptographic checksum is a transaction checksum, wherein the distributed database system is, for example, a blockchain, wherein the device is, for example, constructed as a node or oracle of the distributed database system, and wherein the cryptographic checksum is, for example, a digital signature.
[0088] According to another aspect, the present invention relates to a verification device for verifying cryptographic checksums of data structures, the verification device comprising:
[0089] - A receiving module for receiving data structures, which are protected by means of cryptographic checksums;
[0090] - Detection module (110) for detecting individual characteristics (M) of an object (O) by means of detection device (A);
[0091] - A calculation module (120) for calculating the characteristics (I) of an individual object based on its individual characteristics;
[0092] - A cryptographic module (130) for providing cryptographic keys based on individual characteristics and / or object-specific properties;
[0093] - A verification module for verifying a password checksum using a cryptographic key, wherein control data is provided, for example, based on the result of the verification.
[0094] The same implementation method of this device can be applied to testing equipment, for example.
[0095] For example, to verify a data structure, another data structure protected by a cryptographic checksum can be read from a distributed database system. This other data structure is protected, for example, using a cryptographic key generated based on individual characteristics and / or the properties of the object, and thus, in particular, produces the same cryptographic key. If, for example, the data structure content of the data structure is the same as the data structure content of the other data structure, then the corresponding cryptographic checksum of the data structures is preferably consistent. For this verification, for example, the corresponding data structure content of the other data structure can be read to provide the corresponding data structure content.
[0096] Particularly likely with this invention is the realization of a decentralized (blockchain-based) infrastructure that manages and controls the handling of actual or physical items (e.g., objects) via digital infrastructure (e.g., production, transportation, and verification of their authenticity). Digital twins are often generated, for example, for physical objects, to control further processing of the object (e.g., a workpiece) and / or record its transportation and working steps. For example, data about the digital twin is stored in a data structure. If, for example, such an object is delivered, there is a need or necessity to verify whether the object is indeed the object assigned to the digital twin. To solve this task, individual characteristics of the object are detected, for example, by a detection device. If the object is, for example, a workpiece manufactured by machining, then the individual characteristics may be, for example, the surface structure of the object. In this case, the individual characteristics may be detected, for example, at a pre-given location on the object by a detection device (e.g., a surface inspection device such as a 3D surface scanner or surface camera), where, for example, the individual characteristics are, in this case, individual surface features of the object. It is also conceivable, for example, that a digital fingerprint is contained within the object as an individual characteristic. This fingerprint or digital feature may not be ascertainable by the naked eye and / or without knowledge of its type and location, or may only be ascertainable with considerable technical effort. Correspondingly, information used to detect individual characteristics can be located in a protected memory of the inspection device, preventing unauthorized access. The included fingerprint can be, for example, surface roughness generated during the manufacture of the object. Alternatively or additionally, the fingerprint can be achieved by applying color or particles, wherein, for example, the color or particles are applied to generate an individual spectrum for the object. For this purpose, different colors / particles can be distributed on the surface of the object, generating, for example, a geometric spectrum so that a pre-given spectrum can be measured, for example, at a specific location on the object. The spectrum or color / particles are selected, for example, such that they are not within the spectrum visible to the human eye. This could, for example, be a spectrum exceeding 800 nm. For example, it is possible that the individual characteristics included in the object in the form of a fingerprint provide a public key or data for calculating a public key. The public key is, for example, a first cryptographic key. It is also conceivable, for example, that if the object is, for example, an electronic component or the object includes electronic components, electronic circuits are wired together to generate a configurable fingerprint or individual characteristic for the object.
[0097] Individual characteristics can also be features different from surface features. For example, an individual characteristic can be spectral data about an object. For example, the object can be a gemstone, crude oil, or food, where the spectrum of the object or a predetermined location of the object (e.g., a predetermined facet and / or position) is detected, for example, by means of a detection device in the form of a spectrometer. In this regard, an individual characteristic can be, for example, a spectral individual characteristic. An individual characteristic can also be, for example, an individual characteristic of a noise signal detected by a detection device (e.g., an oscilloscope). If the object is, for example, an electronic component, then, for example, the noise signal of the object can be detected via the object's interface. In the case of this noise signal, for example, the amplitude of the noise signal can be detected and / or considered for a defined resistance and / or attenuation. For example, a predetermined test signal can also be provided by the object, and in this case, signal distortion of the individual characteristic can be considered if necessary. Alternatively or additionally, for example, the detection device can send a test signal, which is transmitted / sent, for example, through a predetermined circuit of the object. For example, the object or a corresponding circuit of the object generates a response, which includes, for example, the test signal, and the response is transmitted to the detection device. Then, for example, the individual effect of the circuit on the test signal is detected by the detection device as an individual characteristic. Such individual effects can be, for example, distortion of the test signal. Correspondingly, individual characteristics can be, for example, individual electronic characteristics.
[0098] Depending on the object and / or the corresponding configuration / specification, individual characteristics may be, for example, individual surface characteristics and / or individual spectral characteristics and / or individual electronic characteristics. Individual characteristics may also be, for example, acoustic characteristics, photoacoustic characteristics, or multispectral photoacoustic characteristics. Corresponding individual characteristics may be reproducibly detectable for the object.
[0099] When using individual features, the characteristics of the individual object can then be calculated, for example. In this case, tolerance values for the individual features can be considered, for example, to generate reproducible characteristics of the individual object. The characteristics of the individual object are advantageous in order to, for example, compensate for measurement inaccuracies when detecting individual features.
[0100] The first cryptographic key can be calculated, for example, based on individual characteristics and / or the properties of an object, by using these characteristics as input parameters for deriving the cryptographic key (e.g., the first cryptographic key). Alternatively or additionally, the individual characteristics and / or the properties of the object can be compared with a pre-given reference value, and the first cryptographic key is released by the cryptographic module after sufficient agreement with the pre-given reference value. In this case, the first cryptographic key is preferably protected from access by the cryptographic module (e.g., through the key storage of the cryptographic module or through cryptographic encryption) until the individual characteristics and / or the properties of the object that conform to the pre-given reference value are detected by a detection device or calculated by a calculation module. For example, the corresponding reference value is also protected from access.
[0101] Using a first cryptographic key, a cryptographic checksum (e.g., a digital signature) can be transformed into a data structure, and this key, or the generation / providance of the key, is bound to an object, thereby implicitly confirming that the object involves a data structure protected by a checksum. For this purpose, a cryptographic checksum is calculated for the data structure, for example, using a cryptographic key (e.g., a first cryptographic key of a previously described device or verification device with a corresponding embodiment). According to this embodiment, for example, a public key is transmitted to the verification device, and then the key is stored in the verification device in an access-protected manner. For example, the public key is associated with a private key, and the cryptographic checksum is calculated using the private key. In this variant, the public key can be released, for example, by comparison with a reference value or by providing an object-binding method by applying a fingerprint to the object. For example, it is also conceivable that, in order to generate and verify the cryptographic checksum of the data structure, a cryptographic key generated by means of a symmetric cryptographic method is involved.
[0102] For example, it's also possible that an entity (e.g., a processing device / node that creates the data structure for the object and stores it in a distributed database system, or an operator of the processing device / node) additionally uses other cryptographic checksums to protect the data structure. These other checksums are, for example, transaction checksums, and are used, for example, to ascertain whether the object is actually assigned to the data structure. These other checksums are, for example, generated using a cryptographic key that can be assigned to the entity in such a way that, for example, a public key is provided by the entity to enable verification of the other checksums.
[0103] The present invention is advantageous in that, for example, if the corresponding object physically exists, it can verify the digital signature of the data structure. In particular, this enables a stronger assignment of the object to the data structure associated with the corresponding object. To prevent, for example, unauthorized persons from extracting the first cryptographic key from the verification device used for digital signatures, the verification device may include corresponding security measures. This could, for example, be a stable housing that prevents access to the components and memory of the verification device. Alternatively or additionally, the verification device may be protected, for example, by means of a protective film (e.g., an anti-drilling protective film), which, if necessary, deletes sensitive data, such as the first cryptographic key or reference values, in the event of manipulation of the verification device (e.g., breaking / drilling open the housing). By means of the verification result of a cryptographic checksum or a check of the control data, it can then, for example, be confirmed that: the data structure is associated with the corresponding object or the data of the data structure relates to the object (die Daten derDatenstruktur, die das Objekt betreffen).
[0104] For example, the data structure can be a message or a message can include a data structure, wherein the message is, for example, stored through a distributed database system, such as a blockchain, and the data structure is a transaction of the distributed database system, and the cryptographic checksum is, for example, a transaction checksum. For example, attaching a cryptographic checksum to the data structure allows verification of the data structure's integrity and / or origin and / or authenticity, and the data structure's relevance to the object.
[0105] In a first embodiment of the inspection equipment, the characteristics of the individual object are calculated taking into account a pre-given tolerance value for individual characteristics.
[0106] The inspection device is advantageous in that it compensates for measurement inaccuracies, for example, when calculating characteristics, so as to reproducibly calculate the characteristics of individual objects when necessary for a specific object. For example, a tolerance value can be selected such that, in the case of the spectral characteristics of an object, such as food, if the object or food is no longer sufficiently fresh, a first key is not provided (or a valid first key cannot be provided). If the object is, for example, bananas, the tolerance value for the spectral characteristics of the banana surface can be selected such that, when a large area of the banana has turned brown, a first key is not provided or generated (or a valid first key cannot be provided). Correspondingly, at the point of transport or at the intermediary, bananas or the supply of bananas containing these bananas can no longer be confirmed as "fresh" in the supply chain by means of a message with a data structure or in a distributed database system using that data structure, because a valid key can no longer be generated or provided for the checksum verification. In the same way, other objects in the form of perishable goods can be monitored in a distributed database system, for example, by means of a message / data structure. Then, a corresponding tolerance value is selected such that if perishable goods deteriorate too much (e.g., the food has expired or rotted), the first cryptographic key is not provided if necessary. In other words, a threshold can be specified by means of the tolerance value, and when the threshold is exceeded, a corresponding valid first cryptographic key is not provided or a valid cryptographic checksum is not created. In particular, in this case, the tolerance value can correspond to the threshold.
[0107] In other embodiments of this verification device, a first cryptographic key may be calculated, for example, based on the characteristics and / or individual features and / or strings of the object. Alternatively, instead of a first cryptographic key, a cryptographic checksum may be calculated.
[0108] The verification device is advantageous in that it can more securely generate the first cryptographic key, for example, in combination with a string (which may also be called a character chain). For example, the characteristics of an individual object are used in combination with the string to provide the first cryptographic key (e.g., to compute the first cryptographic key by means of a key derivation function). The string can be secret and can only be read and / or accessed within the verification device and / or cryptographic module, making it preferably unavailable outside the device. Alternatively or additionally, the string can be selected such that it is pre-given, for example, by another cryptographic key or another cryptographic key. In this case, for example, the other cryptographic key can be pre-given by the operator or the machine handling or processing the object. This can be, for example, a public key or a private key, where the choice of key depends, for example, on the trust relationship between the parties involved in processing / managing the object. The string can also be selected based on function, for example, to generate the cryptographic key according to function (see, for example, a subsequent implementation). For example, the cryptographic key can be generated in such a way that it can be used to decrypt the first cryptographic key upon provision.
[0109] In other embodiments of the testing device, a second cryptographic key is calculated, for example, based on characteristics and / or individual features and / or strings, and the second cryptographic key decrypts the first cryptographic key, for example.
[0110] In other embodiments of the testing device, for example, the characteristics and / or individual features are compared with corresponding reference values and the first cryptographic key is released via a cryptographic module when the reference value matches the characteristics and / or individual features with sufficient precision.
[0111] In other embodiments of the inspection device, the data structure includes object data records, which specify at which geometric points and / or interfaces the inspection device can detect individual features.
[0112] The inspection equipment is advantageous in that it can, for example, define a specific selected area or interface of the object, via which individual characteristics can be detected by the inspection equipment. In the case of an interface, if the object is, for example, an electronic component, then the interface can be, for example, the object's interface.
[0113] In other embodiments of the inspection device, the object data record includes, for example, encrypted individual characteristics and / or object individual properties, wherein, for example, the encrypted individual characteristics and / or object individual properties can be decrypted by means of a first cryptographic key or a third cryptographic key.
[0114] The inspection equipment is advantageous in that it allows, for example, the recipient (e.g., in the sense of goods supply) to inspect characteristics, such as determining how much individual characteristics and / or object-specific properties have changed during object handling. This is relevant, for example, when the object is transported over a long transport route or when multiple production steps are performed during object production. In these and other cases, a data structure is created for the object and stored, for example, in a distributed database system (as explained above). For example, this data structure may additionally include information about the manufacturing steps, manufacturing conditions (temperature during manufacturing), tools used, and materials used. During transport, the data structure may, for example, include information about transport conditions (cold chain temperature, location information, etc.). This additional information may, for example, be referred to as other object-related data. For example, in the case of transport, the object may be a transport container including corresponding sensors and / or the inspection equipment. The transport container may, for example, be a transport container for milk, gemstones, or other food / materials. The transport container may, for example, include the equipment according to the invention and / or the inspection equipment according to the invention and / or corresponding detection equipment.
[0115] In other embodiments of the inspection equipment, the object data record includes, for example, other object-related data such as object measurements, measurements about the object, manufacturing specifications of the object, and the location of the object. This other object data is detected, for example, by sensors of the inspection equipment for the object or by sensors of the object. These sensors are, for example, GPS modules and / or temperature sensors and / or optical sensors and / or acoustic sensors and / or photoacoustic sensors, which detect, for example, the corresponding characteristics of the object.
[0116] In other embodiments of the verification device, the first cryptographic key and / or the second cryptographic key and / or the third cryptographic key are calculated with reference to a secret character chain, and / or the first cryptographic key and / or the second cryptographic key and / or the third cryptographic key are either the private key of an asymmetric key pair or a symmetric key.
[0117] In other embodiments of the verification device, the data structure is a transaction of a distributed database system and the cryptographic checksum is a transaction checksum, wherein the distributed database system is, for example, a blockchain, wherein the verification device is, for example, constructed as a node or oracle of the distributed database system, and wherein the cryptographic checksum is, for example, a digital signature.
[0118] According to another aspect, the present invention relates to a write control module having:
[0119] - A communication interface used for transmitting messages, such as transmitting messages to a distributed database system;
[0120] - Inspection module, in which
[0121] - Verify the data write configuration of the module. This configuration specifies the conditions under which messages will be written to the distributed database system.
[0122] - The verification module checks whether the conditions for writing messages to the distributed database system are met;
[0123] - Transmission control module, in which
[0124] - The transmission control module controls the transmission of messages to the distributed database system via the communication interface based on the inspection results of the inspection module.
[0125] Particularly relevant to this invention is the implementation of a decentralized (blockchain-based) infrastructure in which, for example, the conditions under which messages are written to a distributed database system can be defined and controlled. This, for example, avoids writing to distributed database systems that are, for example, in an error state or a restricted operating state. For this purpose, a data write configuration can be evaluated, for example, pre-defined, that messages or transactions from other nodes also exist in the distributed database system so that the messages or transactions are relatively current. This can be pre-defined, for example, by means of a time window in the data write configuration, preferably pre-defined as the maximum allowed age of messages or transactions from other nodes. For this verification, messages or transactions from other nodes are, for example, equipped with a timestamp and a checksum (e.g., a transaction checksum in the form of a digital signature) or include such a checksum. With the help of the checksum, it can be determined, if necessary, by means of a public key, whether the corresponding message / transaction actually originates from the corresponding pre-defined node.
[0126] In other implementations of the write control module, the data write configuration is pre-defined: one or more pre-defined nodes have written messages to the distributed database system, wherein, for example, the conditions of the data write configuration are pre-defined: the messages of the nodes already exist in the distributed database system.
[0127] In other implementations of the write control module, the checksum of messages from one or more nodes is checked when verifying the conditions of the data write configuration, wherein, for example, the messages used for verification are stored in a distributed database system, and wherein, for example, the conditions that the messages used for verification should meet are specified by the data write configuration.
[0128] In other implementations of the write control module, the write control module selects one or more messages of the distributed database system that utilize checksum protection, wherein, for example, corresponding data about the corresponding message is stored by the sending device.
[0129] It is advantageous to write the control module as follows, so as to ascertain, for example, by means of a selected message, whether the distributed database system has been manipulated or whether the target address has been changed through manipulation in the routing table. This can also identify changes to the blockchain, for example, via a fork. For this purpose, the data includes, for example, the transaction containing the message, the block number of the message, and the checksum of the block and / or the transaction containing the message, where, for example, the message can also be a transaction.
[0130] In other implementations of the write control module, when verifying the conditions of the data write configuration, the write control module verifies the selected message or a portion of the selected message based on the stored messages.
[0131] In other implementations of the write control module, the data write configuration conditions include one, more, or a combination of the following parameters:
[0132] - The time window to be followed for the checksum and / or the selected message.
[0133] - Nodes are pre-defined using corresponding node information.
[0134] - The message of the corresponding node must include the pre-defined content.
[0135] - The checksum of the message to be verified must meet the pre-defined cryptographic conditions.
[0136] According to another aspect, the present invention relates to a transmission apparatus for transmitting control messages, comprising:
[0137] - Message data detection module, in which
[0138] - The message data detection module reads priority data records with priority from the message.
[0139] - The message data detection module reads the target of the message.
[0140] - Assign transmission parameters for message delivery to the priority level;
[0141] - Determine the module, where
[0142] - The determination module generates message control data records based on the target and priority to control the transmission of the messages.
[0143] - Message control data records are assigned to the message.
[0144] - Transmission module, in which
[0145] - The transmission module sends messages to the nodes of the distributed database system based on the message control data record.
[0146] - Nodes control data records in advance via messages.
[0147] In particular, the present invention can be used to implement a decentralized (blockchain-based) infrastructure, in which messages or transactions of high priority are accelerated within the decentralized infrastructure to their destinations. This is necessary, for example, so that messages or transactions that should be processed quickly by a specific or pre-defined node (also called the target) in industrial applications are also transmitted quickly to that node. If, for example, a message for the emergency shutdown of a manufacturing facility or an alarm from a sensor (e.g., a smoke detector or thermal sensor in a manufacturing machine) is transmitted via the decentralized infrastructure to the node controlling the emergency shutdown, it is necessary to transmit the corresponding message to the node to be processed as quickly as possible via the decentralized infrastructure. To achieve this, for example, when replicating or transmitting messages, messages of high priority can be preferred via the decentralized infrastructure or distributed database system. For this purpose, for example, routing for the decentralized infrastructure can be pre-defined or separate communication channels can be constructed to, for example, guarantee the pre-defined rapid transmission to the target. To achieve this, for example, the interface for data input to a distributed database system (e.g., a blockchain oracle) can be equipped with a transmission device according to the invention. Through these interfaces, such as those selected above, alarm sensors can be connected communicatively so that the device can be shut down as described above if necessary.
[0148] In other embodiments of the transmission device, the message control data record includes routing via multiple nodes of a distributed database system, wherein, for example, in order to determine the routing, the message transmission time between nodes is transmitted to the transmission device through the nodes, and in particular, the corresponding transmission time is taken into account when determining the message control data record, wherein, for example, the routing is determined based on the result of a (priority) check.
[0149] In other embodiments of the transmission device, the message control data record includes configuration data, wherein, for example, the configuration data is determined based on the results of an inspection, wherein, for example, the transmission module is configured such that, in order to transmit messages, a separate and / or direct communication channel to the target is established.
[0150] The transmission device is advantageous in that it enables rapid transmission of corresponding messages to the target, for example, without utilizing the replication mechanism of a distributed database system, and records message reception solely through acknowledgment transactions and / or message transmission through corresponding send transactions. This is advantageous so that messages are transmitted to the target as quickly as possible, while still securely recording transmission and reception via a distributed database system using acknowledgment and / or send transactions. For this purpose, a send transaction includes, for example, the send date and / or send time and / or the target (e.g., the target address), acknowledgment of the connection establishment to the target, and / or acknowledgment of transmission to the target, wherein the acknowledgment of transmission is confirmed by the target, for example, through a checksum, such as a digital signature, by means of a corresponding acknowledgment message given to the transmission device (which may also be stored in the send transaction if necessary). Similarly, acknowledgment transactions can be constructed, for example. The confirmation transaction may include, for example, the date and / or time of receipt and / or the sending address (e.g., the address of the transmitting device), confirmation of the connection established with the transmitter, and / or confirmation of the transmission from the transmitter, wherein the confirmation of the transmission (e.g., by the transmitter through a checksum, such as a digital signature) is confirmed by means of a corresponding confirmation message given to the transmitting device (which may also be stored in the transmission transaction if necessary). For example, the message itself may be protected by means of a transaction checksum. For example, the content of the message may also be stored in the confirmation transaction.
[0151] In other embodiments of the transmission device, after the message is received by the target, the confirmation transaction is stored in a distributed database system.
[0152] The transmission device is advantageous in that it can, for example, record how quickly data transmission of a message proceeds to its destination. In this case, for example, the corresponding transmission time between the nodes of a distributed database system can be recorded. With the aid of confirmed transactions, the transmission device can then calculate which route through the infrastructure of the distributed database system is suitable for that priority.
[0153] In other embodiments of the transmission device, the message control data record additionally includes a pre-configured data record that at least partially pre-defines the transmission path of the message to the target.
[0154] The transmission device is advantageous in that it allows for, for example, at least partially pre-defined routing. Other parameters, which should be considered in the transmission between nodes or in the routing, can also be taken into account. Thus, for example, these parameters can be pre-defined to prohibit nodes in a specific / pre-defined region (e.g., a pre-defined country, such as the Democratic People's Republic of Korea, the Principality of Andorra, Eritrea, or Iran) from being used for transmission and, for example, from being used in the routing. Alternatively, it can be pre-defined that only nodes located in a specific region (e.g., the EU, USA, Kazakhstan) are allowed to be used for the route. For example, it can be pre-defined (Vorgaben) that only corresponding nodes with specific hardware equipment are allowed for the route (e.g., redundant components, broadband network connectivity, cryptographic security mechanisms, protection against unauthorized access). This, in particular, allows for the time-consuming solution of proof-of-work (cryptographic puzzles) until the verification of the confirmed transaction is completed, without verifying the corresponding message and therefore, for example, for transmission to the destination. This is especially advantageous for high-priority messages that need to be transmitted quickly. Data exchange relies on confirmation of transactions and / or confirmation of sent transactions, which is not strictly time-sensitive, and these transactions can also be verified periodically.
[0155] In other embodiments of the transmission device, the transmission device includes, for example, a write control module, wherein priority data records with priority are pre-defined by the write control module and the message includes, for example, a data structure (e.g., with sensor data), wherein, for example, the checksum is a transaction checksum and / or, for example, the distributed database system is a blockchain and / or the message is a verified or unverified transaction of a distributed database system.
[0156] According to other aspects, the present invention relates to a system having:
[0157] - A generation module for generating messages for objects, wherein the messages include, for example, priority data records and data structures with priorities;
[0158] - A device for calculating cryptographic checksums for data structures, the device having:
[0159] - Detection module (110) for detecting individual characteristics (M) of object (O) with the aid of detection device (A);
[0160] - Calculation module (120) is used to calculate the characteristics (I) of an individual object based on its individual characteristics;
[0161] - Cryptographic module (130) for providing cryptographic keys based on individual characteristics and / or the properties of the object individual;
[0162] - Protection module (140) for cryptographically protecting a data structure with the aid of a cryptographic checksum, wherein the protection module uses a cryptographic key to calculate the cryptographic checksum;
[0163] - Write control module, with:
[0164] - A communication interface used for transmitting messages, such as transmitting messages to a distributed database system;
[0165] - Inspection module, in which
[0166] - Verify the data write configuration of the module. This configuration specifies the conditions under which messages will be written to the distributed database system.
[0167] - The verification module checks whether the conditions for writing messages to the distributed database system are met;
[0168] - Transmission control module, in which
[0169] - The transmission control module controls the transmission of messages to the distributed database system via the communication interface based on the inspection results from the verification module.
[0170] - A transmission device for controlling the transmission of messages across multiple nodes, having:
[0171] - Message data detection module, in which
[0172] - The message data detection module reads priority data records with priority from the message.
[0173] - The message data detection module reads the target of the message.
[0174] - Priority is assigned with transmission parameters used for message delivery;
[0175] - Determine the module, where
[0176] - The determination module generates message control data records based on the target and priority to control the transmission of the messages.
[0177] - Message control data records are assigned to the message.
[0178] - Transmission module, in which
[0179] - The transmission module transmits the message to the nodes of the distributed database system according to the message control data record.
[0180] - The node controls the data recording in advance via messages.
[0181] - For example, a communication interface uses a transmission device to transmit messages.
[0182] According to other aspects, the present invention relates to a method for calculating a cryptographic checksum in a computer-aided manner, the method comprising the following steps:
[0183] - Use detection equipment (A) to detect the individual characteristics (M) of the object (O);
[0184] - Calculate the characteristics of an individual based on its individual features;
[0185] - Provide a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0186] - The data structure is cryptographically protected by a checksum, which is calculated using a first cryptographic key.
[0187] In other embodiments of the method, the method includes other method steps to implement functional features or other features of the device or its implementation.
[0188] According to other aspects, the present invention relates to a method for verifying a password checksum in a computer-aided manner, the method comprising the following steps:
[0189] - Receive a data structure, which is protected by a cryptographic checksum;
[0190] - Use detection equipment (A) to detect the individual characteristics (M) of the object (O);
[0191] - Calculate the characteristics of an individual based on its individual features;
[0192] - Provide a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0193] - Use the first cryptographic key to verify the cryptographic checksum.
[0194] In other embodiments of the method, the method includes other method steps to implement functional features or other features of the testing equipment or its embodiments.
[0195] According to other aspects, the present invention relates to a method for controlling data transmission in a computer-aided manner, the method comprising the following steps:
[0196] - Transmitting messages, such as transmitting messages to a distributed database system;
[0197] - Verify data write configuration, where
[0198] - Data write configuration instructions specify the conditions under which messages will be written to the distributed database system.
[0199] - Verify whether the conditions for writing messages to a distributed database system are met;
[0200] - Messages are transmitted to the distributed database system via a communication interface, where...
[0201] - Control the transmission based on the verification results of the data write configuration.
[0202] In other embodiments of the method, the method includes other method steps to implement functional features or other features of the write control module or its implementation.
[0203] According to other aspects, the present invention relates to a method for controlling the transmission of messages via multiple nodes in a computer-aided manner, the method comprising the following steps:
[0204] - Read messages from priority data records that have message priorities, where
[0205] - The target of reading the message,
[0206] - Priority is assigned with transmission parameters used for message delivery;
[0207] - Message control data records are determined based on priority and objective to control message transmission, wherein...
[0208] - Message control data records are assigned to messages.
[0209] - Messages are transmitted to nodes in the distributed database system based on message control data records, where...
[0210] - The node, for example, controls data records in advance via messages.
[0211] In other embodiments of the method, the method includes other method steps to implement functional features or other features of the transmission device or its embodiments.
[0212] Furthermore, protection is sought for a computer program product having program instructions for performing the methods according to the invention, wherein one of the methods according to the invention, all of the methods according to the invention, or a combination of the methods according to the invention can be performed by means of the computer program product.
[0213] Additionally, a variant of a computer program product is claimed, the computer program product having program instructions for configuring a creation device, such as a 3D printer, a computer system, or a manufacturing machine suitable for creating a processor and / or device, wherein the creation device is configured using the program instructions to create the aforementioned device and / or write control module and / or inspection device and / or transfer device according to the invention.
[0214] In addition, protection is sought for a providing device for storing and / or providing computer program products. This providing device is, for example, a data carrier that stores and / or provides computer program products. Alternatively or additionally, the providing device is, for example, a network service, a computer system, a server system, especially a distributed computer system, a cloud-based computer system, and / or a virtual computer system, which preferably stores and / or provides computer program products in the form of a data stream.
[0215] The provision is made, for example, as a download in the form of program data blocks and / or instruction data blocks of a complete computer program product, preferably as a file, especially as a download file, or as a data stream, especially as a download data stream. However, the provision can also be made, for example, as a partial download consisting of multiple parts and especially via a peer-to-peer network, or as a data stream. For example, when using a provision device in the form of a data carrier, such a computer program product is read into the system and program instructions are executed, causing the method according to the invention to be executed on a computer, or a creation device is configured to create the device and / or write control module and / or verification device and / or transmission device according to the invention. Attached Figure Description
[0216] The features, characteristics, and advantages of the present invention described above, and how these features, characteristics, and advantages are realized, will become clearer and more apparent from the following description of embodiments, which are explained in more detail with reference to the figures. Schematic diagrams are provided below:
[0217] Figure 1 The first embodiment of the present invention is shown;
[0218] Figure 2 Other embodiments of the invention are shown;
[0219] Figure 3 Other embodiments of the invention are shown;
[0220] Figure 4 Other embodiments of the invention are shown;
[0221] Figure 5 Other embodiments of the invention are shown;
[0222] Figure 6 Other embodiments of the invention are shown; and
[0223] Figure 7 Other embodiments of the invention are shown.
[0224] In these figures, unless otherwise stated, elements with the same function are equipped with the same reference numerals. Detailed Implementation
[0225] Unless otherwise stated or stated, subsequent embodiments have at least one processor and / or storage unit for implementing or performing the method.
[0226] Given knowledge of the method claims, all possibilities for implementing or carrying out the product commonly found in the prior art are naturally known to those skilled in the art, making independent disclosure unnecessary, especially in the specification. In particular, common implementation variations known to those skilled in the art can be implemented solely by hardware (components) or solely by software (components). Alternatively and / or additionally, those skilled in the art, within the scope of their expertise, may choose, to the greatest extent possible, any combination of hardware (components) and software (components) according to the invention to implement variations according to the invention.
[0227] If a portion of the function according to the invention is preferably caused by special hardware (e.g., a processor in the form of an ASIC or FPGA) and / or another portion by (processor-assisted and / or memory-assisted) software, then combinations of hardware (components) and software (components) according to the invention are particularly likely to occur.
[0228] In particular, given the large number of different implementation possibilities, it is neither possible nor, for the purpose of understanding the invention, to name all of these implementation possibilities. In this regard, all the following embodiments are merely intended to exemplify several ways in which such an implementation might appear, particularly according to the teachings of the invention.
[0229] Therefore, the features of the various embodiments are not limited to the corresponding embodiments, but are generally relevant to the invention. Correspondingly, a feature of one embodiment can preferably also be used as a feature of another embodiment, especially if this is not explicitly mentioned in the corresponding embodiments.
[0230] Figures 1 to 7 Embodiments of different aspects of the present invention are shown respectively.
[0231] Here, Figure 1A system is shown that is used to store, for example, sensor data in a distributed database system.
[0232] Here, the system may include, for example, the following features:
[0233] - A generation module for generating messages for objects, wherein the messages include, for example, priority data records and data structures with priorities;
[0234] - A device for calculating cryptographic checksums for data structures, the device having:
[0235] - Detection module, used to detect individual characteristics with the aid of detection equipment;
[0236] - Calculation module, used to calculate the characteristics of an individual object based on its individual features;
[0237] - A cryptographic module for providing cryptographic keys based on individual characteristics and / or the properties of an individual object;
[0238] - A protection module for cryptographically protecting data structures using a cryptographic checksum, wherein the protection module calculates the cryptographic checksum using a cryptographic key;
[0239] - Write control module, with:
[0240] - A communication interface used for transmitting messages, such as transmitting messages to a distributed database system;
[0241] - Inspection module, in which
[0242] - This verification module loads the data write configuration, which specifies the conditions under which messages will be written to the distributed database system.
[0243] - This verification module checks whether the conditions for writing messages to a distributed database system are met;
[0244] - Transmission control module, in which
[0245] - The transmission control module controls the transmission of messages to the distributed database system via the communication interface based on the inspection results from the verification module.
[0246] - A transmission device for controlling the transmission of messages across multiple nodes, having:
[0247] - Message data detection module, in which
[0248] - The message data detection module reads priority data records with priority from the message.
[0249] - The message data detection module reads the target of the message.
[0250] - Priority is assigned with transmission parameters used for message delivery;
[0251] - Determine the module, where
[0252] - The module determines the message control data records used for controlling message transmission based on the target and priority.
[0253] - Message control data records are assigned to the message.
[0254] - Transmission module, in which
[0255] - The transmission module transmits the message to the nodes of the distributed database system according to the message control data record.
[0256] - The node controls the data recording in advance via messages.
[0257] - For example, a communication interface uses a transmission device to transmit messages.
[0258] exist Figure 1 The diagram illustrates a first node N1, a second node N2, a third node N3, and a fourth node N4, which form the nodes of the blockchain BC of the distributed database system. One of these nodes, such as the first node N1, includes the aforementioned device and / or write control module and / or transmission device. Alternatively, the different nodes N1-N4 may each include their respective components, namely the aforementioned device and / or write control module and / or transmission device. These nodes are connected to each other, for example, via a first communication network NW1.
[0259] also, Figure 1 Block B of blockchain BC is shown, such as first block B1, second block B2 and third block B3, wherein a portion of blockchain BC is shown here in particular as an example.
[0260] Block B contains multiple transactions T. These transactions T may include control transactions and / or confirmation transactions.
[0261] For example, the first block B1 includes the first transaction T1a, the second transaction T1b, the third transaction T1c, and the fourth transaction T1d.
[0262] Block B2 includes, for example, the fifth transaction T2a, the sixth transaction T2b, the seventh transaction T2c, and the eighth transaction T2d.
[0263] Block B3 includes, for example, transactions T3a (ninth), T3b (tenth), T3c (eleventh), and T3d (twelfth).
[0264] Block B also includes, respectively, one of the concatenation checksums and CRCs formed based on the direct preceding block. Thus, the first block B1 includes a first concatenation checksum CRC1 from its preceding block, the second block B2 includes a second concatenation checksum CRC2 from the first block B1, and the third block B3 includes a third concatenation checksum CRC3 from the second block B2.
[0265] The corresponding concatenated checksums CRC1, CRC2, and CRC3 are preferably formed via the block header of the corresponding leading block. Preferably, the concatenated checksum CRC can be formed using a cryptographic hash function, such as SHA-256, KECCAK-256, or SHA-3. For example, the concatenated checksum can be additionally calculated via the block checksum, or the header can include the block checksum (explained later).
[0266] Additionally, each block in a block can include a block checksum. This block checksum can be implemented, for example, using a hash tree.
[0267] To form a hash tree, a transaction checksum (e.g., also a hash value) is calculated for each transaction in the data (block). Alternatively or additionally, this can continue to use the transaction checksum preferably created by the transaction producer (Erzeuger) when the transaction is generated.
[0268] Typically, for hash trees, such as Merkle trees or Patricia trees, the root hash value / root checksum of the Merkle tree or Patricia tree is preferably stored in the corresponding block as the checksum of the corresponding data block.
[0269] In one variant, the data block checksum is used as the concatenation checksum.
[0270] In addition, blocks can have timestamps, digital signatures, proof-of-work evidence, as explained in embodiments of the invention.
[0271] Blockchain BC itself is implemented through a blockchain infrastructure with multiple blockchain nodes (nodes N1, N2, N3, N4, and other blocks). Nodes can be, for example, blockchain oracles or trusted nodes.
[0272] These nodes are interconnected via a network NW1 (such as a communication network, like the Internet or Ethernet). Using the blockchain infrastructure, at least some or all of the data blocks B of blockchain BC are replicated for some or all nodes of the blockchain.
[0273] The devices and / or write control modules and / or transmission devices and / or verification devices may be components of a distributed database system or variations of a communication infrastructure (e.g., a point-to-point system, a distributed communication infrastructure). The devices and / or write control modules and / or transmission devices and / or verification devices may communicate with each other, for example, via a distributed database system or, in variations, via a communication infrastructure (e.g., a point-to-point system, a distributed communication infrastructure).
[0274] Figure 2 The functionality of the device is illustrated by way of example in other embodiments, and the functionality of the testing device is also illustrated in variations of this embodiment. For example, the device and / or testing device may be referred to as an apparatus.
[0275] Figure 2 An apparatus 100 is shown for calculating a cryptographic checksum (CRC) for a data structure DS, wherein the data structure DS includes, for example, object-specific data of an object O. The data structure DS and the cryptographic checksum (CRC) are, for example, in a data record D, wherein the data record D is stored, for example, as a transaction in a distributed database system. For this purpose, the transaction may include an additional checksum (e.g., a transaction checksum), which is generated, for example, by means of a cryptographic key assigned to or used by the entity (e.g., a private cryptographic key). The entity may, for example, be an operator, measurement station, or processing station that controls, processes, or manages the object O. The data record D may also be, for example, a message or a transaction, depending on the implementation.
[0276] Depending on the implementation variant, if, for example, the data structure DS includes a data field for storing a password checksum and CRC, or if a password checksum is appended to the data structure, then the data structure DS may also correspond to the data record D. As already explained, the data structure DS and / or the data record D may, in particular, be stored or included by a message or transaction. Alternatively, the data structure DS and / or the data record D may, for example, be a message or transaction.
[0277] The nodes of the distributed database system (e.g., blockchain nodes) and / or the distributed database system may additionally include one or more other components, such as processors, storage units, other communication interfaces (e.g., Ethernet, WLAN, USB, fieldbus, PCI), input devices, particularly computer keyboards or computer mice, and display devices (e.g., monitors). The processor may include, for example, multiple other processors, which may be used to implement other embodiments.
[0278] For example, Figure 1 The nodes in the process may include device 100 or be configured as device 100 or Figure 1The nodes in the data structure can be connected to device 100 via data lines or communication networks. Similarly, the verification device can also be configured to verify the cryptographic checksum and CRC used in the data structure DS.
[0279] To create a password checksum and CRC, the device includes a detection module 110, a calculation module 120, a password module 130, a protection module 140, and a communication module (e.g., a network interface) 101, which are interconnected in a communicative manner via a bus (e.g., a PCI bus, a CAN bus, a USB, or a data cable) 102.
[0280] The detection module 110 is configured to detect the individual characteristics M of an object O using a detection device A. For this purpose, the detection device A is connected to the detection device A via a (wireless or wired) data connection (e.g., using USB, LAN, W-LAN, Bluetooth, FireWire). For example, the detection device A detects / measures the surface roughness, which is an individual characteristic of the object O, using a scanning beam S.
[0281] The calculation module 120 is configured to calculate the characteristics of the individual object based on individual characteristics M. When calculating the characteristics of the individual object, a tolerance value may be considered, for example, to account for the measurement inaccuracies of the detection device A, as mentioned later in the determination of the first cryptographic key. For example, in a variant implementation that provides the cryptographic key based on individual characteristics, the calculation module may be omitted.
[0282] The cryptographic module 130 is configured to provide a first cryptographic key based on individual characteristics and / or the properties of the object individual.
[0283] The provision can be implemented in different ways. For example, individual characteristics and / or properties of an object can be compared with reference values, where corresponding tolerance values are considered, for example. If (e.g., after considering the tolerance values) the individual characteristics and / or properties of the object match the reference values, a first cryptographic key is loaded, for example, from a secure data storage device. The reference values can be detected or stored, for example, during the device initialization and / or installation phases. Preferably, the device initialization and / or installation phases can be performed only once.
[0284] Alternatively, the first cryptographic key is calculated based on individual characteristics and / or the properties of the object, by using these characteristics as input data for the key derivation function. Other data may also be used in this case. For example, a string (e.g., a secret password) may be associated with the individual characteristics and / or the properties of the object, and then this associated data is used, for example, to calculate the first cryptographic key using a key derivation function (e.g., PBKDF2).
[0285] Protection module 140 is configured to cryptographically protect the data structure using a cryptographic checksum and CRC, wherein the protection module calculates the cryptographic checksum and CRC using a first cryptographic key. The cryptographic checksum can, for example, utilize a Keyed-Hash Message Authentication Code (HMAC) (e.g., HMAC in the case of MD5, SHA1, or SHA256). In other implementation variations, the cryptographic checksum can be implemented as a digital signature or digital certificate, where, depending on the cryptographic method used (symmetric or asymmetric), the first cryptographic key is used, for example, as a private key for generating the digital signature. To verify the digital signature, for example, a public key is derived from the first cryptographic key and provided through a trusted entity (e.g., a trusted server), so that in a variant of the verification device, the verification device can access the corresponding key. If, for example, a private key has been generated and stored, for example, in the memory of cryptographic module 130, then, for example, the corresponding individual characteristics of the object can be altered or rendered unusable, so that the first cryptographic key can no longer be derived. This can be done, for example, by polishing the corresponding location on the surface of the object, washing away the color / particles from the object (e.g., with the aid of a solvent), or additionally applying the color / particles to the object to render the corresponding individual characteristics unusable or alter them. It is also possible, for example, to render the individual characteristics unusable so that the first cryptographic key can no longer be directly calculated from the individual characteristics; however, considering tolerance values, the characteristics of the individual object can still be calculated from the altered individual characteristics to provide or calculate the public key, for example, through the cryptographic module of the verification device.
[0286] Alternatively or additionally, the public key can also be included in or applied to an object as a (digital) fingerprint in the form of an individual characteristic (e.g., surface roughness, a dye with a specific spectrum that decays, for example, after a predetermined time, in order to encode the storage period in particular). This fingerprint or individual characteristic cannot be identified / read by the naked eye and / or without knowledge of its type and location, or can only be identified with considerable technical effort. Correspondingly, information used to detect the individual characteristic can be located in a protected memory of the device, preventing unauthorized access to the information. The included fingerprint / individual characteristic can, for example, be a surface roughness generated during the manufacture of the object or further processing of the object. Alternatively or additionally, the fingerprint can be achieved by applying color or particles, whereby, for example, color or particles are applied to generate an individual spectrum for the object. For this purpose, different colors / particles can be distributed on the surface of the object, such as generating a geometric spectrum, so that, for example, a pre-given spectrum can be measured at a specific location on the object. For example, the spectrum or color / particles are selected such that they are not within the spectrum visible to the human eye. This could, for example, be a spectrum exceeding 800 nm.
[0287] The use of tolerance values is advantageous in order to account for (or compensate for) measurement inaccuracies, for example, when calculating characteristics or detecting individual features, so as to reproducibly calculate the characteristics or individual features of an object when necessary for a specific object.
[0288] For example, a tolerance value can be selected such that, in the case of the spectral characteristics of an object, such as food, if the object or food is no longer sufficiently fresh, a first key is not provided (or a valid first key cannot be provided). If the object is, for example, bananas, the tolerance value for the spectral characteristics of the banana surface can be selected such that when a large area of the banana turns brown, a first key is not provided or generated for these bananas (or a valid first key cannot be provided). Correspondingly, at the point of transport or at an intermediary, bananas or a supply of bananas containing these bananas can no longer be confirmed / stored as "fresh" in the supply chain by means of a message with a data structure or in a distributed database system using that data structure. In the same way, for example, other objects in the form of perishable goods can be monitored in a distributed database system by means of a message / data structure. Then, a corresponding tolerance value is selected so that if perishable goods, for example, deteriorate too much (e.g., the food's shelf life has expired or the food has rotted), a first key is not provided if necessary. Alternatively, for example, an alternative key can be provided when the tolerance value is exceeded, based on which points in the record of the object's transport have exceeded the tolerance value.
[0289] Correspondingly, the aforementioned tolerance value can be used not only for the characteristics of an individual object, but also when a first cryptographic key should be provided based on individual characteristics. This may be necessary, for example, in situations where individual characteristics (which may also be referred to as the characteristics of the individual object) should be compared with reference values to release the first cryptographic key if the corresponding values match, or where individual characteristics are applied as input parameters to a key derivation function and, for example, errors regarding reproducible key derivation should be prevented due to measurement inaccuracies.
[0290] For example, the present invention can advantageously be used in supply chain management or when monitoring the supply chain. In particular, if, for example, data related to an object (e.g., goods such as food, electronic components, gemstones, etc.) from different entities involved in the manufacture, transport, or sale of the object (e.g., manufacturers, multiple logistics companies, sales departments, buyers) is generated at different points in the handling / processing of the object and / or at different times for record-keeping reasons, this invention is especially advantageous if the participating entities do not trust each other, because the corresponding data is protected, for example, by password verification and / or verification by the corresponding entity. For example, the device could be part of a transport container for, for example, transporting food such as bananas or milk, or multiple devices of the same type could exist at different points in the handling / processing of the object or at the time of doing so.
[0291] For example, at a processing location (e.g., when an object is handed over to a logistics company), object-specific data (e.g., which object, type, manufacturer, unique identifier / UID, etc., and the time of arrival at the logistics company) is detected and stored in an object data record or a document data record. The object data record / document data record can then, for example, be stored in a data structure and protected using a cryptographic checksum, as explained, by providing a first cryptographic key based on an interpretation. For example, it is also conceivable to generate two different sets of object-specific data for an object, where, for this purpose, the first data set and the second data set are stored in data structures respectively (e.g., stored in a first data structure and a second data structure). For example, the corresponding data structures may include cryptographic keys to verify the cryptographic checksum (which may also be called the first cryptographic checksum). Depending on the implementation variant, the data structure DS and / or data record D may include an object data record and / or a document data record. For example, in a variant, it is also possible that the object data record corresponds to a document data record.
[0292] For example, a data set includes both mutable data related to an object and immutable data related to an object. For instance, the first data set / data structure includes immutable data about the object; immutable data may describe, for example, the object's type (electronic component, food, raw material such as diamond), type, manufacturer, unique identifier / UID, etc.
[0293] For example, the second data group / data structure includes variable data of the object. The variable data may be, for example, data of the entity processing the object (name, address, digital signature), the time of processing, work steps, processing conditions (e.g., temperature during the transport / manufacturing / processing of the object), and the duration of processing (e.g., the duration of transport, or the duration of the execution of processing steps during the production of the object).
[0294] The first and / or second data structures are cryptographically protected by a first cryptographic key, for example, by generating a cryptographic checksum, for example, in the form of a digital signature for the corresponding data structure. The corresponding data structures can then be stored in messages or transactions within a distributed database system (e.g., a blockchain) by corresponding processing entities, whereby, for example, the corresponding entities generate transaction checksums for the messages or transactions by means of the entity's cryptographic key. The transaction checksum can also, in particular, be a digital signature.
[0295] When processing / transporting an object, such as by different entities performing digital document creation at corresponding moments, it is possible, for example, to protect corresponding messages / transactions with corresponding data related to the object during transportation at a predetermined time, according to one of the interpreted methods or variations thereof, by means of cryptographic checksums, and write them, for example, to a distributed database system. For this purpose, the device may include, for example, a communication module (e.g., a mobile radio module such as a UMTS, LTE, or 5G module). This application is advantageous, for example, when the temperature of an object (e.g., milk or fish) is recorded during transportation using data related to the object. In this case, the individual characteristics of the object may be, for example, the surface structure or spectral data of the transport container or the spectrum of the object.
[0296] By using individual characteristics to provide the first cryptographic key, corresponding objects, especially physical objects, can be more closely associated with each other through the "digital world." If an object is transported, for example, over a long period of time, or altered through processing / transportation, such that it no longer conforms to the corresponding tolerance value, the exceeding of the tolerance value or the inappropriate handling of the object can be seamlessly verified, for example, via a distributed database system. This also confirms whether an object has been replaced by another object, which is relevant, for example, in the case of product counterfeiting.
[0297] If the object is now replaced by a counterfeit object, the corresponding individual characteristics will change. For example, this may be relevant to medical products in order to determine whether, for example, a silicone implant is actually a genuine silicone implant from the manufacturer and not a counterfeit implant. To this end, for example, during the manufacture of the object (implant), the corresponding data for the object is written into a distributed database system according to one of the variations mentioned above. Logistics companies, sales companies, and clinics that transport, trade, and implant the object record the corresponding processing steps, times, and other relevant data performed by them according to the methods mentioned above (description of the respective entities). The individual characteristics of the implant may be, for example, surface characteristics of the implant (e.g., the surface of a silicone pad or the surface of a metal implant). In the case of a silicone pad, the individual characteristics may also be, for example, the measured spectrum of the silicone pad content (silicone). The invention is not limited to silicone pads. Other implants with other fillers can also be examined. It is also possible to verify the authenticity of other medical products, such as drugs (e.g., via spectroscopy) or medical technology devices, such as MRI, CT, and their electronic components (e.g., by means of test signals or noise signals).
[0298] This allows us to record when and where object manipulation was performed, as individual characteristics change in this case and this could potentially lead to a change in the first cryptographic key. If, for example, there exists a first data structure with immutable object data, then the digital signature will change. For example, the digital signature will be identical for the first three entries. If, for example, a fourth entity in the supply chain attempts to replace the implant with a counterfeit made of inferior materials, this will be recorded, for example, by this invention. While the fourth entity can still generate the correct entry in the distributed database system, at the latest by the time the counterfeited object is processed by the fifth entity, a correct digital signature / cryptographic checksum can no longer be generated for the corresponding first data structure. The corresponding entities preferably also generate corresponding second data structures, for example, to store mutable data.
[0299] Because each entity generates a transaction checksum using its own cryptographic key (the entity's key) for each of its transactions with corresponding data structures, it is possible to determine, if necessary, which entities have been cheated. While it is desirable to securely store as much information as possible about manufacturing / processing / selling / manufacturing / shipping in data structures and transactions, it may be sufficient, for example, for only the manufacturer to do so. For this, a distributed database is not necessarily required. Other databases (such as hierarchical SQL databases) or cloud services from trusted entities can also be used.
[0300] With the aid of this invention, for example, the corresponding data structure can be transmitted from the manufacturer / distributor to the buyer immediately upon ordering the object, or the corresponding data structure can be transmitted to the buyer after the object is manufactured. Here, the corresponding data structure, or the corresponding data structure (if using first and second data structures), is protected using a corresponding cryptographic checksum as described. The corresponding data structure can either be transmitted directly to the buyer or provided to the buyer by means of a database system (e.g., a distributed database system). If the object is supplied to the buyer, the buyer can verify, based on the object and the data structure, whether the object is indeed an object for which the distributor / manufacturer has provided a corresponding data structure or has stored the corresponding data structure in a database system.
[0301] To this end, the buyer can, for example, generate a corresponding checksum for the data in the first data structure by detecting the individual characteristics of the object (as already explained) and providing a first cryptographic key based on those characteristics, so that a corresponding cryptographic checksum can be generated. If the corresponding cryptographic checksums match, then it actually pertains to the object delivered by the manufacturer / distributor and no manipulation has occurred in the transportation route and / or intermediate sales.
[0302] For example, individual characteristics may be encoded into a cryptographic key, which could be used, for instance, to verify a manufacturer's / distributor's data structure using a cryptographic checksum. To verify the data structure, a verification device, as briefly explained below, can be used, with functionality similar to that implemented in the explained device.
[0303] Verification devices for checking cryptographic checksums of data structures include:
[0304] - For example, a receiving module for receiving data structures, where the data structures are protected by means of cryptographic checksums;
[0305] - For example, a detection module (110) for detecting individual characteristics (M) of an object (O) by means of a detection device (A);
[0306] - For example, a calculation module (120) for calculating the characteristics of an individual object based on its individual features;
[0307] - For example, a cryptographic module (130) for providing a first cryptographic key based on individual characteristics and / or the properties of an individual object;
[0308] - For example, a verification module used to verify the cryptographic checksum with the aid of a first cryptographic key.
[0309] For example, this verification can provide control data, which, if necessary, confirms the authenticity of the object if the password verification is correct, and, for example, prompts the manufacturing machine to further process the object or prompts the logistics system to further transport the object.
[0310] For example, the location or instructions regarding how and where to find individual features of the object can be specified randomly during production or at other times (e.g., to make manipulation of features on the object difficult): These instructions may be provided. A corresponding configuration with instructions on how and where individual features should be detected includes data on the geometric points and / or interfaces through which the detection device can detect individual features. This configuration is preferably stored in the device or inspection equipment in an access-protected manner. In this case, access protection means, for example, that only authorized personnel can access the data / configuration by means of: the authorized personnel canceling passwords and / or mechanical and / or electromechanical protections, if necessary, for example, by entering a password / personal identification number. If someone attempts to read the configuration through improper manipulation of the device, the corresponding device (or inspection equipment) can detect this using corresponding sensors (e.g., anti-drilling protective film, temperature sensor, light sensor) and, if necessary, delete the configuration from the device's memory.
[0311] The device and / or inspection device may also utilize different individual characteristics, wherein the individual characteristics used for inspection are preferably encoded with a pre-given key (e.g., as a fingerprint). The different individual characteristics are then located, for example, at different locations on the object.
[0312] Alternatively, individual characteristics are not specified randomly, but are located in a known / assigned position in the case of the corresponding object (e.g., on the base of the object or on an uneven area of the implant).
[0313] In one variant, the device used to calculate the cryptographic checksum may also discard the characteristics of the individual object or its calculation. Such a device, for example, includes the following features:
[0314] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0315] - For example, a cryptographic module (130) is used to provide a first cryptographic key based on individual characteristics;
[0316] - For example, a protection module (140) is used to cryptographically protect a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of a first cryptographic key.
[0317] For example, the device can also be used as a hardware wallet for blockchain or distributed ledger applications in a manner where, for example, the object is an electronic device that protects transactions using cryptographic verification (e.g., as a digital signature). For this purpose, the object includes the device, and the detection device detects individual characteristics (e.g., noise signals or signals of the object) and generates a first cryptographic key so that a digital signature can be created. For example, the data structure can be a message or transaction to be protected. If a data structure or transaction including the transaction data desired by the user has been created and protected by a digital signature, the digital signature is submitted to the distributed ledger / distributed database. The distributed ledger / distributed database can then, for example, verify the corresponding transaction (which includes the data structure, transaction data, and digital signature). For this purpose, the device and / or object, for example, have an input interface for inputting transactions and / or an output interface for transmitting transactions to the distributed database system.
[0318] In a variant of the verification device, individual characteristics and / or properties of the object individual can be used to verify the cryptographic checksum. Such a verification device includes the following features:
[0319] - For example, a receiving module for receiving data structures, where the data structures are protected by means of cryptographic checksums;
[0320] - For example, a detection module (110) for detecting individual characteristics (M) of an object (O) by means of a detection device (A);
[0321] - For example, a calculation module (120) for calculating the characteristics (I) of an individual object based on individual characteristics;
[0322] - For example, a verification module used to check cryptographic checksums by means of individual characteristics and / or the properties of an individual object, wherein
[0323] - For example, providing control data based on the results of this test.
[0324] - For example, generating additional cryptographic checksums for data structures based on individual characteristics and / or the properties of individual objects.
[0325] - For example, if another cryptographic checksum matches the cryptographic checksum, the data structure and / or object will be accepted as real and / or correct.
[0326] In this variant, a corresponding method can also be used to compensate for measurement inaccuracies, for example, by means of tolerance values. This is done through corresponding preprocessing, as already explained.
[0327] Individual characteristics and / or properties of an object are used as secrets, for example, to calculate password checksums, such as message verification codes (MAC; German: Nachrichtenauthentifizierungscode).
[0328] For example, in this variant, to verify the data structure, an additional data structure protected by a cryptographic checksum can be read from, for instance, a distributed database system. This additional data structure is protected, for example, by using individual characteristics and / or properties of the object (the same object), in that the cryptographic checksum is generated for the additional data structure based on the individual characteristics and / or properties of the object. If, for example, the data structure content of the data structure is the same as the data structure content of the additional data structure, then the corresponding cryptographic checksum of the data structure is preferably consistent. For this verification, for example, the corresponding data structure content of the additional data structure can be read to provide the corresponding data structure content. Alternatively or additionally, for example, only the cryptographic checksum can be provided for the data structure (e.g., by the distributed database system). This cryptographic checksum is then verified by regenerating the cryptographic checksum via the data structure.
[0329] If, for example, the password checksum matches, the object is accepted as genuine, or the original and / or data structure is accepted as genuine. If the checksum does not match, the object and / or data structure is rejected, and control instructions and / or control signals are provided as necessary to react to the rejection (e.g., not processing the object, not further transporting the object, or notifying personnel to manually verify the object). The determination of whether, for example, the object and / or data structure is accepted as genuine depends, for example, on the trust relationship in the inspection situation. If the object is assumed to be trustworthy or an original, the authenticity of the data structure is determined by means of the object, for example. If, for example, the data structure with its password checksum is trustworthy, the authenticity of the object can be determined.
[0330] Correspondingly, the verification module can be set up to verify the cryptographic checksum with the aid of the first cryptographic key, wherein, for example, if the cryptographic checksum is successfully verified, the data structure and / or object is accepted as real and / or correct and / or complete.
[0331] Variations of the testing equipment include features such as the following:
[0332] - For example, a receiving module for receiving data structures, where the data structures are protected by means of cryptographic checksums;
[0333] - For example, a detection module (110) for detecting individual characteristics (M) of an object (O) by means of a detection device (A);
[0334] - For example, a verification module used to check password checksums by means of individual characteristics, where
[0335] - For example, providing control data based on the results of this test.
[0336] - For example, generating additional cryptographic checksums for data structures based on individual characteristics.
[0337] - For example, if other cryptographic checksums are consistent with the cryptographic checksum, the data structure and / or object will be accepted as real and / or correct and / or complete.
[0338] In a variant of this device, individual characteristics and / or properties of individual objects can be used to compute the cryptographic checksum of the data structure. This device includes the following features:
[0339] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0340] - For example, the calculation module (120) is used to calculate the characteristics (I) of an individual object based on its individual characteristics;
[0341] - For example, a protection module (140) is used to cryptographically protect a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of individual characteristics and / or the characteristics of an individual object.
[0342] In this variant, a corresponding method can also be used to compensate for measurement inaccuracies, for example, by means of tolerance values. This is done through corresponding preprocessing, as already explained.
[0343] Individual characteristics and / or properties of an object are used as secrets, for example, to calculate password checksums, such as message verification codes (MAC; German: Nachrichtenauthentifizierungscode).
[0344] A variant of this device may include the following features:
[0345] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0346] - For example, a protection module (140) is used to cryptographically protect a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of individual characteristics.
[0347] For example, a distribution device or system, including other storage for orderly data storage, may be used to quickly locate, when necessary, corresponding transactions in a distributed database system for which data records have been stored. For instance, the device and / or verification device may, in appropriate variations, include a distribution device or system. Figure 3 and Figure 4 Other embodiments may also include a dispensing device or a dispensing system in corresponding variations.
[0348] The allocation device or other memory may be, for example, a hash table, hash graph, or lookup table. The allocation device or allocation system may also implement a distributed hash table or other memory corresponding to a distributed memory in the form of a distributed hash table.
[0349] If, for example, a data structure with a cryptographic checksum is written to or stored in a distributed database system via a message or transaction, then an entry is written to the distribution device, for example. This entry includes a key and a transaction-specific data record. The key can be, for example, the following data or a combination of the following data:
[0350] - Individual characteristics
[0351] - Characteristics of individual objects
[0352] - Data related to immutable objects (First data set)
[0353] - First cryptographic key
[0354] - Password checksum
[0355] - Hash of the data mentioned
[0356] - Regarding the hash value of the data structure.
[0357] In this context, the key can also be called the distribution key.
[0358] Transaction-specific data records may include, for example, the following data or a combination of the following data:
[0359] - The block number of a block in a blockchain / distributed database system, where the block includes transactions with a corresponding data structure.
[0360] - The transaction number of the transaction, which includes transactions with corresponding data structures.
[0361] - The storage location or address of the message, which includes messages with corresponding data structures.
[0362] - Checksums of the corresponding blocks and / or transactions and / or messages
[0363] - Data about entities that have already been entered
[0364] - Other data that may seem relevant.
[0365] Here, transaction-specific data records can also be referred to as metadata about transactions or entries in the distributed database, if necessary. For example, an entry can be a transaction, message, data block, block, or storage address, which, for example, stores a data structure with a corresponding cryptographic checksum.
[0366] If an entry is written to a distributed database system, and an entry does not yet exist for the key, then for example, an entry is created and the corresponding transaction-specific data record is entered.
[0367] If an entry already exists for the corresponding key, the relevant transaction-specific data record can be overwritten using the current transaction-specific data record. In other words, an existing entry is overwritten using the transaction-specific data record to be entered. Alternatively, the current / new transaction-specific data record can be appended to an existing transaction-specific data record, where, in this variant, the transaction-specific data record is implemented as a list or vector containing transaction-specific data records. For example, the transaction-specific data records can be written into the list or vector in an ordered or sorted manner, such that the most recent / latest transaction-specific data record is, for example, the first or last entry. Correspondingly, the list / vector can be sorted, for example, according to the time of input. Other sorting or ordering is also possible here. For example, entries can be sorted according to location, postal code, GPS location, etc. The transaction-specific data record, or the transaction-specific data record itself, can also be referred to as metadata of the corresponding data structure, which can be stored and / or provided, for example, through a distributed database system.
[0368] This allocation device enables the rapid retrieval of corresponding entries within a distributed database system, whereby these entries are assigned to objects. First, a corresponding key for each object is generated, for example, by detecting or calculating individual characteristics and / or properties of the object. Then, corresponding data for determining the key can be calculated based on this data.
[0369] If the key is available / provided, the corresponding transaction-specific data record can be read via the distribution device or distribution system. Based on the transaction-specific data record, the corresponding entry / transaction can then be read from the distributed database system if necessary. Thus, for example, a corresponding transaction with a data structure for the object entered by another entity or at an earlier time can be found very quickly. This is advantageous when the authenticity of the object and / or (current) data structure should be verified using an authentication device with the aid of an earlier / older data structure (e.g., a data structure written into the distributed database system by another entity). As already mentioned, the corresponding data structure is protected using a corresponding cryptographic checksum, as described in this embodiment or other embodiments.
[0370] Here, the distribution device or distribution system may include the following modules:
[0371] - For example, the key providing module, where
[0372] - For example, a key providing module is set up to provide keys.
[0373] - For example, the key is calculated based on the input data, or
[0374] - For example, the key is retrieved or transmitted to the key providing module via a data interface.
[0375] - For example, the metadata provider module, where
[0376] - For example, a metadata provider module is set up to provide metadata for entries in a database (such as a distributed database system).
[0377] - For example, metadata is calculated through a metadata provider module, such as by submitting a reference or link to an entry to the metadata provider module, and the metadata provider module, for example, reading the corresponding metadata for the entry from the database, or
[0378] - For example, metadata is retrieved from or transmitted to the metadata provider module via a data interface.
[0379] - For example, storage modules, where
[0380] - The storage module is set up to store data pairs consisting of a key and corresponding metadata.
[0381] The equipment and testing equipment are then explained, each including a corresponding distribution device or distribution system. In this case, "including" can be interpreted broadly, such as meaning that the corresponding distribution device or distribution system is also connected to the equipment or testing equipment via a communication interface / data interface (e.g., Ethernet, LAN, mobile radio interface). Alternatively, the equipment and / or testing equipment includes the corresponding distribution device or distribution system as an integral component. Alternatively, the corresponding distribution device or distribution system is configured as one or more nodes of a distributed database system.
[0382] The equipment in this variant includes the following modules:
[0383] - For example, a detection module is used to detect the individual characteristics of an object with the help of a detection device;
[0384] - For example, a calculation module is used to calculate the characteristics of an individual object based on its individual features;
[0385] - For example, a cryptographic module for providing a first cryptographic key based on individual characteristics and / or the properties of an individual object;
[0386] - For example, a protection module is used to cryptographically protect a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of a first cryptographic key;
[0387] - For example, writing a module, where
[0388] - For example, a write module is set up to write data structures into a database (such as a distributed database system).
[0389] - For example, the write module generates a key (also known as an allocation key) for an entry in the database, which may include a data structure (the data structure is stored in the entry).
[0390] - For example, the write module uses a key to write metadata about entries in the database into the distribution device.
[0391] In other variants, the equipment includes the following modules:
[0392] - For example, a detection module is used to detect the individual characteristics of an object with the help of a detection device;
[0393] - For example, a cryptographic module for providing a first cryptographic key based on individual characteristics and / or the properties of an individual object;
[0394] - For example, a protection module is used to cryptographically protect a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of a first cryptographic key;
[0395] - For example, writing a module, where
[0396] - For example, a write module is set up to write data structures into a database (such as a distributed database system).
[0397] - For example, the write module generates a key (also known as an allocation key) for an entry in the database, which may include a data structure (the data structure is stored in the entry).
[0398] - For example, the write module uses a key to write metadata about entries in the database into the distribution device.
[0399] In other variants, the equipment includes the following modules:
[0400] - For example, a detection module is used to detect the individual characteristics of an object with the help of a detection device;
[0401] - For example, a protection module is used to cryptographically protect a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of individual characteristics and / or the characteristics of an individual object;
[0402] - For example, writing a module, where
[0403] - For example, a write module is set up to write data structures into a database (such as a distributed database system).
[0404] - For example, the write module generates a key (also known as an allocation key) for an entry in the database, which may include a data structure.
[0405] - For example, the write module uses a key to write metadata about entries in the database into the distribution device.
[0406] The testing equipment in this variant includes the following modules:
[0407] - For example, a receiving module for receiving data structures, wherein the data structures are protected by means of cryptographic checksums;
[0408] - For example, a detection module (110) for detecting individual characteristics (M) of an object (O) by means of a detection device (A);
[0409] - For example, a calculation module (120) for calculating the characteristics of an individual object based on its individual features;
[0410] - For example, a cryptographic module (130) for providing a first cryptographic key based on individual characteristics and / or the properties of an individual object;
[0411] - For example, a verification module used to verify a cryptographic checksum with the aid of a first cryptographic key, wherein
[0412] - For example, the verification module forms keys for data structures and / or objects (also known as assigning keys).
[0413] - For example, a verification module is set up to load metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0414] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0415] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0416] For example, if the corresponding checksums match, the data structure and / or object is accepted as real.
[0417] In other variations, the testing equipment includes the following modules:
[0418] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0419] - For example, a cryptographic module (130) is used to provide a first cryptographic key based on individual characteristics;
[0420] - For example, a verification module is used to verify the cryptographic checksum of a data structure with the aid of a first cryptographic key.
[0421] In other variations, the testing equipment includes the following modules:
[0422] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0423] - For example, a cryptographic module (130) is used to provide a first cryptographic key based on individual characteristics;
[0424] - For example, a verification module is used to verify the cryptographic checksum of the data structure using a first cryptographic key, wherein...
[0425] - For example, the verification module forms keys for data structures and / or objects (also known as assigning keys).
[0426] - For example, a verification module is set up to load metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0427] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0428] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0429] In other variations, the testing equipment includes the following modules:
[0430] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0431] - For example, a verification module is set up to verify the cryptographic checksum of the data structure, where
[0432] - For example, the verification module forms keys for data structures and / or objects (also known as assigning keys).
[0433] - For example, a verification module is set up to load metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0434] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0435] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0436] In other variations, the testing equipment includes the following modules:
[0437] - For example, a verification module is set up to verify the cryptographic checksum of the data structure, where
[0438] - For example, the verification module forms keys for data structures and / or objects (also known as assigning keys).
[0439] - For example, a verification module is set up to load metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0440] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0441] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0442] In other variations, the testing equipment includes the following modules:
[0443] - For example, a detection module (110) is used to detect individual characteristics (M) of an object (O) by means of a detection device (A);
[0444] - For example, a verification module is set up to verify the cryptographic checksum of the data structure, where
[0445] - For example, the verification module generates keys (also known as assigning keys) for data structures and / or objects based on individual characteristics (M) and / or the properties of individual objects.
[0446] - For example, a verification module is set up to load metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0447] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0448] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0449] In the aforementioned implementation methods and variations, the corresponding cryptographic checksum may be written to the data structure, depending on the chosen implementation. This data structure can be stored in a separate storage system to store as little data as possible, for example, in a distributed database system. In other words, the data structure can also be stored indirectly in a distributed database system, for example, as a reference to a corresponding storage location in another storage system (e.g., a database), such as a transaction in the database system, a cryptographic checksum, and a corresponding location in another storage system.
[0450] For example, instead of a distributed database system, a method that allows for the trusted storage of messages / transactions can be used.
[0451] For example, in the context of this invention and its embodiments, implementations, and variations, trusted databases, cloud services, revision-resistant storage systems (e.g., revision-resistant databases), network communication systems (e.g., Ethernet communication systems, TCP-IP communication systems, mobile radio communication systems), distributed systems, distributed storage systems, or peer-to-peer systems can be used to reliably store and / or transmit and / or exchange corresponding transactions / messages between nodes. Write-protected memory can also be used, for example, to store transactions or messages using the described methods, where transactions or messages written once in the write-protected memory are stored in an immutable manner, wherein the corresponding message includes a corresponding data structure with a cryptographic checksum, and the transaction / message is optionally protected with a transaction checksum.
[0452] For example, different methods can be used for different checksums or cryptographic checksums. Thus, for example, a transaction checksum (or a message checksum in the case of a message) can be implemented as a digital signature, and the cryptographic checksum of the data structure is, for example, a message verification code (MAC). Alternatively, a data structure with a cryptographic checksum can implement digital certificates for objects in such a way that: for example, object-specific information / data is stored in the data structure and / or individual characteristics and / or properties of the object are stored in the data structure.
[0453] In particular, when combined with testing equipment, cryptographic devices can be used to associate objects or individual characteristics of objects (especially physical objects, which can also be called non-digital objects) with digital twins or images of objects.
[0454] Since the message or data structure protected by the device through cryptographic verification is immutably stored in the corresponding storage system (e.g., a distributed database system or one of the mentioned alternatives), the verification device can, if necessary, verify in a simple manner, by means of a determined first cryptographic key, whether it actually involves the object used by the device.
[0455] The device and / or testing device and / or dispensing apparatus and / or dispensing system may additionally include, for example, one or more other components, such as a processor, storage unit, other communication interfaces (e.g., Ethernet, WLAN, USB, fieldbus, PCI), input devices, particularly a computer keyboard or computer mouse, and display devices (e.g., a monitor). The processor may include, for example, multiple other processors, which may be used to implement other embodiments.
[0456] Embodiments not shown in the figures relate to systems including devices and inspection equipment. Corresponding devices and / or inspection equipment may also be implementations, embodiments, or variations thereof.
[0457] Figure 3 An embodiment involving a write control module is shown, which can be used, for example, to ensure that: in Figure 2 The data structures explained herein are written into a distributed database system or database system that meets pre-defined security requirements, such as those pre-defined in the data write configuration. Embodiments of the present invention are particularly applicable when using… Figure 1 Explain in the context of Figure 1 The interpretation of the reference numerals in the accompanying drawings also applies accordingly. Figure 3 .
[0458] The write control module includes a communication interface (such as a network card), a verification module, and a transmission control module, which are interconnected via a bus.
[0459] A communication interface is set up for transmitting messages, such as messages to a distributed database system.
[0460] A verification module is set up to load the data write configuration, which specifies the conditions under which messages will be written to the distributed database system. Here, the verification module verifies, for example, whether the conditions for writing messages to the distributed database system are met. For example, the data write configuration may be stored in the write control module or stored within the distributed database system.
[0461] The transmission control module is configured to control the transmission of messages to the distributed database system via a communication interface based on the inspection results of the inspection module.
[0462] In a variation of the invention mentioned above, the distributed database system can, for example, be implemented in... Figure 2 One of the alternatives mentioned in the document can be used as a replacement.
[0463] The explanation then goes on to explain how the data write configuration conditions are used to ensure that a corresponding message is only written when the corresponding other node has already written the message to the distributed database system.
[0464] For this purpose, for example, the data write configuration is pre-defined: one or more pre-defined nodes have already written messages to the distributed database system, where the conditions of the data write configuration are pre-defined: the node's message already exists in the distributed database system.
[0465] The message can be, for example, in Figure 2 The data structure explained herein refers to transactions. Nodes can be entities or blockchain oracles, for which there is a correlation through data write configuration, which also exists in the physical world, for example. This should be considered in transportation. Figure 2 When objects are written to a database, a series of checkpoints are followed, where each checkpoint writes a corresponding transaction / message, for example, with a data structure protected by cryptographic verification, into the distributed database system.
[0466] In the first processing step S31, the first node A, for example, writes a transaction (e.g., transaction T1a) into the distributed database system. Here, the first node A may be a node that confirms the sending and / or manufacturing and / or processing / processing steps of the object (e.g., the object has been created by the first subcontractor and delivered to the supplier). When the second node B, which has a write control module, processes the object at the second subcontractor (e.g., the object becomes, for example, a workpiece), it reads transaction T1a or searches for the transaction written by the first node regarding the object in the distributed database system. This is then performed in processing step S32.
[0467] For example, the data write configuration specifies which data from which nodes must exist in the distributed database system so that a second node or write control module can allow other messages to be written to the distributed database system. The data write configuration may alternatively or additionally predefine a time window, which the messages from the nodes must adhere to. For example, the data write configuration may predefine that the corresponding message from a node cannot be older than 24 hours (alternatively 1 hour, 5 minutes). Based on this information, the second node B can then search for the corresponding entry / transaction in the distributed database system, where the corresponding entry / transaction preferably includes a timestamp. Alternatively or additionally, blocks may also include timestamps. The corresponding timestamps are then used to determine which blocks / transactions to search and / or whether the conditions of the data write configuration are met. Other information can also be used when searching for corresponding messages. This is, for example, Figure 2 Data in the data structure or object-specific data.
[0468] If the conditions or requirements for data write configuration are met, then, for example, the second node B writes the corresponding message, such as a message or transaction with a data structure protected by cryptographic verification, into the distributed database system in processing step S33. This message could then be, for example, transaction T3a.
[0469] For example, the write control module may additionally include one or more other components, such as a processor, a storage unit, other communication interfaces (e.g., Ethernet, WLAN, USB, fieldbus, PCI), input devices, particularly a computer keyboard or computer mouse, and a display device (e.g., a monitor). The processor may include, for example, multiple other processors, which may be used to implement other embodiments.
[0470] Figure 4 Embodiments involving transmission devices are shown. For example, depending on the application scenario, Figure 1 Nodes or in a distributed database system Figure 2 or Figure 3The nodes in the diagram may include transmission devices. For example, a node or standalone device may include a device and / or a write control module and / or a verification device and / or a transmission device. For example, such a node or device may also include corresponding variants, implementations, and embodiments of these inventions (devices and / or write control modules and / or verification devices and / or transmission devices).
[0471] The transmission device includes a message data detection module (e.g., network card to network card connection), a determination module, and a transmission module, which are interconnected via a bus in a communicative manner.
[0472] The message data inspection module is configured to read priority data records from messages. This message can, in particular, be a message or transaction that includes a data structure with a cryptographic checksum, as exemplified in this example. Figure 2 As explained in [the document]. Here, priority or priority data records can be, for example, by [the relevant entity / entity]. Figure 2 The device in the message is given in advance. Alternatively or additionally, the message has been generated by another device. This device may be, for example, a control and monitoring device for manufacturing machines or technical systems (e.g., power plants, energy distribution networks, field devices). The message or data structure may include, for example, control instructions for controlling other devices to control switching signals of the control device or other processing steps for the object during manufacturing and / or maintenance, for example, based on sensor values of the monitoring device.
[0473] The message data detection module reads the target NR of the message (as in, for example, in...). Figure 1 The distributed database system shown (or another device processing the message) preferably includes a destination address (UID or network address) or other information (message name, device type) to determine the destination address of the target NR (which can also be referred to as the receiver). Additionally, transmission parameters are assigned to priorities for message delivery. This means, for example, the following:
[0474] Priority 0: Low priority, message delivery time and / or successful delivery are not mandatory. For example, delivery can be done as broadcast or multicast.
[0475] Priority 1: Normal priority, the message should be delivered to the target NR within a pre-defined delivery time (e.g., 5 minutes, 1 hour, 5 hours).
[0476] Priority 2: High priority. Messages should be delivered to the target NR faster than messages with normal or low priority (e.g., within 5 or 10 seconds). For this purpose, processing of lower priority messages may be interrupted by the node if necessary (e.g., during replication within a distributed database system), and high priority messages are processed first.
[0477] Priority 3: Critical priority. This type of message must be transmitted to the target NR as quickly as possible.
[0478] The allocation of transmission parameters can be pre-defined through a distributed database system, for example, by means of smart contracts / chaincode.
[0479] The allocation or configuration of transmission parameters can be performed locally, for example, by storing the corresponding configuration in the transmission device. Alternatively or additionally, the allocation and configuration of transmission parameters can be performed through a distributed database system, for example, by implementing the corresponding control using smart contracts, which are stored, for example, in transactions within the distributed database system.
[0480] The determination module is configured to generate message control data records for controlling the transmission of messages based on the target and priority, wherein the message control data records are assigned to the message. In particular, transmission parameters are considered in the determination.
[0481] Alternatively or additionally, the determination module is configured to verify whether a valid route can be determined based on the target and priority, wherein, for example, message control data records for controlling the transmission of control messages are generated based on the results of the verification. In particular, transmission parameters are also considered in the determination.
[0482] Message control data records can, for example, be appended to a message and thus preferably form part of the message and / or the message control data record is transmitted via a UID (e.g., a random number, hash value, message number, etc.). Figure 2 The first cryptographic key in Figure 2 Password checksums, etc., are assigned to messages and stored separately in a distributed database system (e.g., as a hash graph, hash table, or lookup table).
[0483] The transmission module is configured to transmit messages to a node of a distributed database system (such as the distributed database system explained in the previous embodiments) based on a message control data record, wherein the node is provided in advance by the message control data record.
[0484] For example, message control data records include routing via multiple nodes in a distributed database system. To determine the routing, the message transmission time between nodes is transmitted to the transmission device via the nodes, and the corresponding transmission time is considered, particularly when determining message control data records. Here, for example, when determining message control data records, the routing is determined by a determination module based on the results of priority checks and transmission times.
[0485] like Figure 4 As shown, messages are transmitted to the target NR via a distributed system (e.g., a distributed database system) and its nodes (e.g., nodes N1-N6). If, for example, a low-priority message is involved, the route C (X, N1, N2, N3, N6, N5, NR) calculated by the determining module is specified or calculated for that message using message control data records. To select a route, different parameters can be used, such as the transmission time between nodes being known, in a way that the transmission time is detected and exchanged between nodes during transmission. This slow route can also be selected for low-priority messages to open up a fast route for high-priority messages. For example, the node in route C could be a slow node with poor network connectivity.
[0486] The transmission module, based on the message control data record, preferably sends the message to the next node corresponding to the calculated route. From sender X, the next node for route C will be N1. If node N1 has just processed the message and / or determined the route and / or determined and / or verified the new route, then from node N1, the next node for route C will be N2.
[0487] If other messages with higher priority are sent, a route D(X, N2, N5, NR) can be specified for those other messages. If, for example, two messages arrive at node N2 simultaneously, the message with higher priority is processed first through node N2 if necessary.
[0488] A node (e.g., node N2), multiple nodes (e.g., nodes N1 to N3), all nodes (N1 to N6), the target NR, and / or the transmitter X may also include corresponding transmission means. This is advantageous in situations where message routing needs to be adapted, for example, if the transmission time of the selected route deteriorates, causing the message to fail to arrive at the target NR in a timely manner according to its priority. The corresponding node can also check the route to determine whether the transmission parameters for the message priority are still met. If it is determined here that the current route no longer meets the priority requirements or transmission parameters, the corresponding node can adapt the route so that the route again meets the requirements (and, for example, if a valid route cannot be determined, even a separate and / or direct communication channel may be used). If the current route still meets the requirements, the node does not adapt the route.
[0489] Message control data records may also include, for example, configuration data records. Here, for example, it is checked whether a message is transmitted, such that it follows pre-given priorities and / or transmission parameters (e.g., timely transmission). Based on the result of this check, configuration data is then generated, which pre-given routes or, for example, in cases of critical message priorities (e.g., control messages for emergency shutdown of manufacturing equipment), separate and / or direct communication channels (HPCs) are created, and if necessary, the message is transmitted directly to the target NR. The configuration data records are then used to configure, for example, the transmission module, such that separate and / or direct communication channels (HPCs) to the target NR are constructed for message transmission.
[0490] For example, message control data records may additionally include pre-configured data records that at least partially pre-define the transmission path or route of the message to the target.
[0491] If the distributed database system is, for example, a blockchain or distributed ledger, then the message verification process can be adapted according to priority, such as for unverified transactions. For example, in the case of implementation using a proof-of-work algorithm, the difficulty of the cryptographic puzzle can be adapted according to priority. For messages with high priority, the difficulty of the cryptographic puzzle used to solve the proof-of-work algorithm is adapted such that it does not exceed the time pre-given for the priority of transmission to the target. Therefore, the duration of solving the cryptographic puzzle can be adapted such that the transmission time / transmission time + the time required to solve the cryptographic puzzle from the nodes of the distributed database system (e.g., nodes N1-N6) to the target NR does not exceed the pre-given time. For example, a buffer time can also be considered for this purpose if necessary.
[0492] Therefore, the difficulty of the cryptographic puzzle is predetermined by the time allotted for solving it. This time is determined as follows:
[0493] Time allocated for solving the puzzle = (priority time given in advance) - (predicted transmission time to the target + buffer time)
[0494] Here, the buffer time can be determined by the maximum expected deviation of the transmission time. If no buffer time is used, this buffer time can be, for example, 0. This deviation can be detected by the nodes during message transmission and exchanged between the nodes.
[0495] By reducing the difficulty of cryptographic puzzles, messages for transactions can be provided faster than those in a distributed database system, when necessary.
[0496] Additionally or alternatively, messages with critical priority can be transmitted to the target NR via separate and / or direct communication channels (HPC).
[0497] The transmission device is advantageous in that it enables rapid transmission of corresponding messages to the target, for example, without using the replication mechanism of a distributed database system, and, for example, only by recording the receipt of acknowledgment transaction messages and / or the transmission of corresponding send transaction messages. This is advantageous so that messages are transmitted to the target as quickly as possible (e.g., in cases of critical priority), while still reliably recording transmission and reception via a distributed database system using acknowledgment and / or send transactions. For this purpose, a send transaction includes, for example, the send date and / or send time and / or the target (e.g., the target address), acknowledgment of the connection to the target, and / or acknowledgment of the transmission to the target, wherein the acknowledgment of the transmission is confirmed by the target, for example, by means of a checksum, such as a digital signature, via a corresponding acknowledgment message given to the transmission device (which may also be stored in the send transaction if necessary). Similarly, acknowledgment transactions can be constructed, for example. The confirmation transaction may include, for example, the date and / or time of receipt and / or the sending address (e.g., the address of the transmitting device), confirmation of the connection established with the transmitter, and / or confirmation of the transmitter's transmission, wherein the transmission confirmation is made by the transmitter, for example, through a checksum, such as a digital signature, by means of a corresponding confirmation message given to the transmitting device (which may also be stored in the transmission transaction if necessary). For example, the message itself may be protected by means of a transaction checksum. For example, the content of the message may also be stored in the confirmation transaction.
[0498] In a variant of this embodiment, after the target receives the message, the confirmation transaction is stored in a distributed database system.
[0499] The transmission device is advantageous in that it can, for example, record how quickly data transmission of a message proceeds to its destination. In this case, for example, the corresponding transmission time between the nodes of a distributed database system can be recorded. With the aid of transaction confirmation, the transmission device can then calculate which route through the infrastructure of the distributed database system is suitable for that priority.
[0500] The transmission device may additionally include one or more other components, such as a processor, storage unit, other communication interfaces (e.g., Ethernet, WLAN, USB, fieldbus, PCI), input devices, particularly a computer keyboard or computer mouse, and display devices (e.g., a monitor). The processor may include, for example, multiple other processors, which may be used to implement other embodiments.
[0501] The present invention is advantageous for implementing control systems for manufacturing equipment, infrastructure (e.g., water plants, wastewater control, building control), or power plants, for example, using a distributed database system, where messages are, if necessary, transactions within the distributed database system. Particularly advantageous is that, if necessary, transmission time and / or the time for resolving proof-of-work evidence can be adapted to messages with different high priorities. Thus, messages with particularly critical priorities can be stored or provided via the distributed database system faster than verified messages / transactions. For example, if an emergency switch for a power plant is operated, the switch sends a corresponding message with a control command for emergency shutdown to the power plant control unit, causing the message to shut down all relevant machines and equipment in the power plant via a communication network. If the power plant control unit is implemented using a distributed database system, then the corresponding message can be transmitted to the relevant machines and equipment significantly faster using the present invention.
[0502] If, for example, voltage peaks or voltage drops in the network are measured by transmitter X or an apparatus equipped with corresponding sensors, control of the energy supply network can be achieved in a similar manner if necessary. Transmitter X then sends messages with corresponding control commands and / or measured values to field devices and / or control devices and / or power storage facilities in the energy supply network, so as to compensate for the corresponding voltage fluctuations in the energy supply network as strongly as possible through the control of the field devices and / or control devices and / or power storage facilities. These messages preferably include priority data records with high or critical priority, where the priority is determined, for example, by the intensity of voltage fluctuations in the energy supply network.
[0503] In one variant, the transmission device for controlling message transmission includes the following modules:
[0504] - For example, the message data detection module, where
[0505] - For example, the message detection module reads priority data records with priority from the message.
[0506] - For example, the message data detection module reads the target message.
[0507] - For example, assigning transmission parameters for message delivery to priorities;
[0508] - For example, identify the module, where
[0509] - For example, the module determines message control data records based on the target and priority to control the transmission of the messages.
[0510] - For example, message control data records are assigned to the message.
[0511] - For example, a transmission module, where
[0512] For example, the transmission module sends messages to nodes in the distributed database system based on message control data records.
[0513] - For example, the node controls data records in advance via messages.
[0514] In a variation of the invention mentioned above, the distributed database system can, for example, be implemented in... Figure 2 One of the alternatives mentioned in the text is to replace it.
[0515] Figures 2 to 4 The devices and / or write control modules and / or transmission devices can be combined into a single device or system.
[0516] Here, the system additionally includes, for example, a generation module for generating messages for objects, wherein the messages include, for example, priority data records and / or data structures with priorities, as is the case here. Figures 2 to 4 As described in the embodiments and variations thereof.
[0517] For example, the generating module may additionally include a detection device for sensors or access devices to detect sensor data. For example, sensor data can be detected from an object and stored, for example, in a data structure (a second set of data / variable data or a first set of data / immutable data). For example, the target of the message is defined by the type of sensor value (e.g., operation of an emergency switch) and is stored, in particular, in the corresponding message. Alternatively or additionally, the generating device defines the target of the message.
[0518] Here, the system may include the following:
[0519] - For example, a generation module for generating messages for objects, wherein the message includes, for example, priority data records and / or data structures with priorities;
[0520] - For example, a device for calculating cryptographic checksums of data structures has:
[0521] - For example, a detection module (110) for detecting individual characteristics (M) of an object (O) using a detection device (A);
[0522] - For example, a calculation module (120) for calculating the characteristics of an individual object based on its individual features;
[0523] - For example, a cryptographic module (130) for providing cryptographic keys based on individual characteristics and / or the properties of an individual object;
[0524] - For example, a protection module (140) for cryptographically protecting a data structure with the aid of a cryptographic checksum, wherein the protection module uses a cryptographic key to calculate the cryptographic checksum;
[0525] - For example, writing a control module has:
[0526] - For example, a communication interface used to transmit messages, such as transmitting messages to a distributed database system;
[0527] - For example, the inspection module, where
[0528] For example, the module loads a data write configuration that specifies the conditions under which messages will be written to the distributed database system.
[0529] - For example, the verification module checks whether the conditions for writing messages to a distributed database system are met;
[0530] - For example, the transmission control module, in which
[0531] For example, the transmission control module controls the transmission of messages to the distributed database system via a communication interface based on the inspection results from the inspection module.
[0532] - For example, a transmission device for controlling the transmission of messages via multiple nodes, having:
[0533] - For example, the message data detection module, where
[0534] For example, the message data detection module reads priority data records with priority from the message.
[0535] - For example, the message data detection module reads the target message.
[0536] - For example, assigning transmission parameters for message delivery to priorities;
[0537] - For example, identify the module, where
[0538] - For example, the module determines the message control data records used to control message transmission based on the target and priority.
[0539] - For example, message control data records are assigned to the message.
[0540] - For example, a transmission module, where
[0541] For example, the transmission module sends messages to nodes in the distributed database system based on message control data records.
[0542] - For example, the node controls data records pre-defined via messages.
[0543] - For example, a communication interface uses a transmission device to transmit messages.
[0544] Figure 5 Other embodiments of the invention are illustrated in the flowchart of the method shown.
[0545] This method is preferably implemented in a computer-aided manner.
[0546] In detail, this embodiment illustrates a method for calculating a password checksum in a computer-aided manner.
[0547] The method includes a first method step 510, which is used to detect individual characteristics with the aid of a detection device.
[0548] The method includes an optional second method step 520 for calculating the characteristics of an individual object based on individual characteristics.
[0549] The method includes a third method step 530, for providing a first cryptographic key based on individual characteristics and / or the properties of the object individual.
[0550] The method includes a fourth method step 540 for cryptographically protecting the data structure with the aid of a cryptographic checksum, wherein the cryptographic checksum is calculated with the aid of a first cryptographic key.
[0551] Other embodiments of the present invention, not shown in the figures, relate to a method for verifying cryptographic checksums in a computer-aided manner.
[0552] This method is preferably implemented in a computer-aided manner.
[0553] The method includes a first method step for receiving a data structure, wherein the data structure is protected by a cryptographic checksum.
[0554] The method includes a second method step for detecting individual characteristics of an object using a detection device.
[0555] The method includes an optional third method step for calculating the characteristics of an individual object based on individual features.
[0556] The method includes a fourth method step for providing a first cryptographic key based on individual characteristics and / or the properties of the object individual.
[0557] The method includes a fifth method step for verifying the cryptographic checksum using the first cryptographic key.
[0558] Figure 6 Other embodiments of the invention are illustrated as flowcharts of methods.
[0559] This method is preferably implemented in a computer-aided manner.
[0560] In detail, this embodiment illustrates a method for controlling data transmission in a computer-aided manner.
[0561] The method includes a first method step 610 for transmitting a message, such as transmitting the message to a distributed database system.
[0562] The method includes a second method step 620, used to verify the data write configuration, wherein...
[0563] - Data write configuration instructions specify the conditions under which messages will be written to the distributed database system.
[0564] - Verify whether the conditions for writing messages to a distributed database system are met;
[0565] The method includes a third method step 630, which transmits a message to a distributed database system via a communication interface, wherein...
[0566] - Control the transmission based on the verification results of the data write configuration.
[0567] Figure 7 Other embodiments of the invention are illustrated as flowcharts of methods.
[0568] This method is preferably implemented in a computer-aided manner.
[0569] In detail, this embodiment illustrates a method for controlling the transmission of messages via multiple nodes in a computer-aided manner.
[0570] The method includes a first method step 710, used to read messages from priority data records that have message priorities, wherein...
[0571] - The target of reading the message,
[0572] - The priority is assigned transmission parameters for message transmission.
[0573] The method includes a second method step 720 for determining a message control data record for controlling the transmission of messages based on priority and objective, wherein the message control data record is assigned to a message.
[0574] The method includes a third method step 730, which transmits a message to a node of a distributed database system based on a message control data record, wherein the node is provided with the message control data record in advance.
[0575] The modules mentioned in the embodiments can be implemented as independent nodes and can be connected to each other communicatively via a communication infrastructure (e.g., a distributed system or a distributed database system). Correspondingly, multiple modules of the same structural type can be provided to, for example, ensure improved reliability of the corresponding modules.
[0576] Other embodiments not shown in the figures are briefly explained in the following paragraphs.
[0577] Another embodiment relates to a computer-aided method comprising the following steps:
[0578] - For example, providing a key, where
[0579] - For example, the key is calculated based on the input data, or
[0580] - For example, retrieving, transmitting, or receiving keys via a data interface;
[0581] - For example, providing metadata for entries in a database (such as a distributed database system), where
[0582] - For example, calculating metadata can be done by: submitting or receiving references or links to entries, and retrieving corresponding metadata from a database, or
[0583] - For example, retrieving, transmitting, or receiving metadata via a data interface;
[0584] - For example, storing data pairs consisting of keys and metadata.
[0585] Another embodiment relates to a computer-aided method comprising the following steps:
[0586] - For example, using detection equipment to detect the individual characteristics of an object;
[0587] - For example, calculating the characteristics of an individual based on its individual features;
[0588] - For example, providing a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0589] - For example, using a checksum to protect a data structure, where the checksum is calculated using a first cryptographic key;
[0590] - For example, writing data structures into a database (such as a distributed database system), where
[0591] - For example, forming a key (also known as assigning a key) for an entry in a database, which may include a data structure (the data structure is stored in the entry).
[0592] - For example, metadata about entries in the database is written to the distribution device using a key.
[0593] Another embodiment relates to a computer-aided method comprising the following steps:
[0594] - For example, using detection equipment to detect the individual characteristics of an object;
[0595] - For example, providing a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0596] - For example, using a checksum to protect a data structure, where the checksum is calculated using a first cryptographic key;
[0597] - For example, writing data structures into a database (such as a distributed database system), where
[0598] - For example, forming a key (also known as assigning a key) for an entry in a database, which may include a data structure (the data structure is stored in the entry).
[0599] - For example, metadata about entries in the database is written to the distribution device using a key.
[0600] Another embodiment relates to a computer-aided method comprising the following steps:
[0601] - For example, using detection equipment to detect the individual characteristics of an object;
[0602] - For example, cryptographic protection of data structures can be achieved using cryptographic checksums, where the checksums are calculated using individual characteristics and / or the properties of individual objects;
[0603] - For example, writing data structures into a database (such as a distributed database system), where
[0604] - For example, forming a key (also known as assigning a key) for an entry in a database, which may include a data structure (the data structure is stored in the entry).
[0605] - For example, metadata about entries in the database is written to the distribution device using a key.
[0606] Another embodiment relates to a computer-aided method comprising the following steps:
[0607] - For example, receiving a data structure, wherein the data structure is protected by a cryptographic checksum;
[0608] - For example, using detection equipment to detect the individual characteristics of an object;
[0609] - For example, calculating the characteristics of an individual based on its individual features;
[0610] - For example, providing a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0611] - For example, using the first cryptographic key to verify the cryptographic checksum, where
[0612] - For example, forming keys for data structures and / or objects (also known as assigning keys).
[0613] - For example, loading metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0614] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0615] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0616] Another embodiment relates to a computer-aided method comprising the following steps:
[0617] - For example, using detection equipment to detect the individual characteristics of an object;
[0618] - For example, providing a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0619] - For example, using the first cryptographic key to verify the cryptographic checksum.
[0620] Another embodiment relates to a computer-aided method comprising the following steps:
[0621] - For example, using detection equipment to detect the individual characteristics of an object;
[0622] - For example, providing a first cryptographic key based on individual characteristics and / or the properties of the individual object;
[0623] - For example, using the first cryptographic key to verify the cryptographic checksum, where
[0624] - For example, forming keys for data structures and / or objects (also known as assigning keys).
[0625] - For example, loading metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0626] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0627] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0628] Another embodiment relates to a computer-aided method comprising the following steps:
[0629] - For example, using a detection device (A) to detect the individual characteristics (M) of an object (O);
[0630] - For example, verifying the cryptographic checksum of a data structure, where
[0631] - For example, forming keys for data structures and / or objects (also known as assigning keys).
[0632] - For example, loading metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0633] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0634] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0635] Another embodiment relates to a computer-aided method comprising the following steps:
[0636] - For example, verifying the cryptographic checksum of a data structure, where
[0637] - For example, forming keys for data structures and / or objects (also known as assigning keys).
[0638] - For example, loading metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0639] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0640] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0641] Another embodiment relates to a computer-aided method comprising the following steps:
[0642] - For example, using a detection device (A) to detect the individual characteristics (M) of an object (O);
[0643] - For example, verifying the cryptographic checksum of a data structure, where
[0644] - For example, keys are formed for data structures and / or objects based on individual characteristics (M) and / or the properties of individual objects (e.g., also known as allocation keys).
[0645] - For example, loading metadata of entries from a database (e.g., a distributed database system) from an allocation device based on a key.
[0646] - For example, loading other data structures and / or other password checksums from the database based on the entry's metadata.
[0647] - For example, the verification can be performed by comparing the password checksum with other password checksums.
[0648] The mentioned embodiments, implementations and variations thereof may additionally include, for example, a communication interface (e.g., Ethernet, mobile radio such as 5G) or a data interface to receive, send and write necessary data (e.g. to a distributed database system) as needed.
[0649] This invention relates to an ecosystem of devices that autonomously interact with each other using blockchain technology. In particular, this invention utilizes blockchain infrastructure to achieve secure data processing of sensor or measurement data from objects. Application areas in this case include blockchain supply chain scenarios or industrial control applications.
[0650] Although the invention has been illustrated and described in more detail by way of examples, the invention is not limited to the disclosed examples and other variations can be derived by those skilled in the art without departing from the scope of protection of the invention.
[0651] [1]AndreasM. Antonopoulos "Mastering Bitcoin: Unlocking Digital Cryptocurrencies", O'Reilly Media, December 2014
[0652] [2] Roger M. Needham, Michael D. Schroeder “Using encryption for authentication in large networks of computers” ACM: Communications of theACM. Volume 21, Issue 12, December 1978,
[0653] [3]Ross Anderson "SecurityEngineering.A Guide to Building De-pendableDistributed Systems" Wiley, 2001
[0654] [4] Henning Diedrich „Ethereum: Blockchains, Digital Assets, SmartContracts, Decentralized Autonomous Organizations”, CreateSpace IndependentPublishingPlatform, 2016
[0655] [5] "The Ethereum Book Project / MasteringEthereum" https: / / github.com / ethereumbook / ethereumbook, as of October 5, 2017
[0656] [6] Leemon Baird "The SwirldsHashgraph Consensus Algorithm: Fair, Fast, Byzantine Fault Tolerance", Swirlds Tech Report SWIRLDS-TR-2016-01, May 31, 2016
[0657] [7] Leemon Baird "Overview of Swirlds Hashgraph", May 31, 2016
[0658] [8] Blockchain oracles
[0659] https: / / blockchainhub.net / blockchain-oracles / As of March 14, 2018.
Claims
1. An apparatus for calculating a cryptographic checksum for a data structure, the apparatus comprising: - Detection module (110) for detecting individual characteristics (M) of object (O) by means of detection device (A); - Calculation module (120) is used to calculate the characteristics of an individual object based on the individual characteristics, wherein the characteristics of an individual can be reproducibly generated for the same individual characteristics; - A cryptographic module (130) is configured to provide a first cryptographic key based on the individual characteristics and / or the properties of the object individual, wherein the properties and / or the individual characteristics are compared with corresponding reference values, and wherein the first cryptographic key is released by the cryptographic module when the reference value matches the properties and / or the individual characteristics; - Protection module (140) for cryptographically protecting a data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of the first cryptographic key.
2. The device according to claim 1, wherein - The characteristic is calculated taking into account a pre-given tolerance value for the individual characteristic. - Calculate the first cryptographic key based on the stated characteristics and / or the stated individual features and / or strings, or - A second cryptographic key is calculated based on the stated characteristics and / or the stated individual features and / or the string, and the second cryptographic key decrypts the first cryptographic key. The string can be secret and can only be read and / or accessed within the verification device and / or cryptographic module, or pre-given by other cryptographic keys or other cryptographic keys.
3. The device according to claim 2, wherein - The data structure includes object data records. - The object data record specifies the geometric points and / or interfaces at which the detection device can detect the individual features. - The object data record includes encrypted versions of the individual features and / or the characteristics of the individual object. - It is possible to decrypt the encrypted individual characteristics and / or the characteristics of the object individual using the first cryptographic key or the third cryptographic key. - The object data record includes other object-related data. - The device's sensors detect data about other objects in relation to the object. - The sensor is a GPS module and / or a temperature sensor and / or an optical sensor, which detects corresponding characteristics of the object.
4. The device of claim 3, wherein the other object-related data are measurements of the object, measurements about the object, manufacturing specifications of the object, and the location of the object.
5. The device according to claim 3 or 4, wherein - The first cryptographic key and / or the second cryptographic key and / or the third cryptographic key are additionally calculated taking into account the use of a secret character chain, and / or - The first cryptographic key and / or the second cryptographic key and / or the third cryptographic key are either the private keys of an asymmetric key pair or symmetric keys.
6. The device according to any one of claims 1 to 4, wherein - The data structure is a transaction of a distributed database system, and the cryptographic checksum is a transaction checksum. - The distributed database system is a blockchain. - The device is configured as a node or oracle in the distributed database system. - The cryptographic checksum is a digital signature.
7. Verification equipment for verifying cryptographic checksums of data structures, including: - A receiving module for receiving data structures, wherein the data structures are protected by means of a cryptographic checksum; - Detection module (110) for detecting individual characteristics (M) of an object (O) by means of detection device (A); - A calculation module (120) for calculating the characteristics of an individual based on the individual characteristics, wherein the characteristics of an individual can be reproducibly generated for the same individual characteristics; - A cryptographic module (130) for providing a first cryptographic key based on the individual characteristics and / or the characteristics of the object individual, wherein the characteristics and / or the individual characteristics are compared with corresponding reference values, and wherein the first cryptographic key is released by the cryptographic module when the reference value matches the characteristics and / or the individual characteristics; - A verification module for verifying the cryptographic checksum using the first cryptographic key.
8. A system having: - A generation module for generating messages for objects, wherein the messages include priority data records and data structures with priorities; - A device for calculating a cryptographic checksum for the data structure, the device having: - Detection module (110) for detecting individual characteristics (M) of object (O) by means of detection device (A); - Calculation module (120) is used to calculate the characteristics (I) of an individual object based on the individual characteristics, wherein the characteristics of an individual can be reproducibly generated for the same individual characteristics; - A cryptographic module (130) is configured to provide a cryptographic key based on the individual characteristics and / or the properties of the object individual, wherein the properties and / or the individual characteristics are compared with corresponding reference values, and wherein the cryptographic key is released by the cryptographic module when the reference value matches the properties and / or the individual characteristics; - A protection module for cryptographically protecting the data structure by means of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by means of the cryptographic key; - Write control module, with: - A communication interface for transmitting messages, wherein the messages are transmitted to a distributed database system; - Inspection module, in which - The verification module loads the data write configuration, which specifies the conditions under which the message will be written to the distributed database system. - The verification module verifies whether the conditions for writing the message into the distributed database system are met; - Transmission control module, in which - The transmission control module controls the transmission of messages to the distributed database system via the communication interface based on the inspection results of the inspection module. - A transmission device for controlling the transmission of the message via multiple nodes, comprising: - Message data detection module, in which - The message data detection module reads priority data records with priority from the message. - The message data detection module reads the target of the message. - The priority is assigned transmission parameters for message transmission; - Determine the module, where - The determining module generates message control data records for controlling the transmission of the message based on the target and the priority. - The message control data record is assigned to the message. - Transmission module, in which The transmission module transmits the message to the nodes of the distributed database system according to the message control data record. - The node controls the data records given in advance through the message. - The communication interface transmits messages using a transmission device.
9. A method for calculating a password checksum in a computer-aided manner, comprising the following steps: - Using detection equipment (A) to detect the individual characteristics (M) of the object (O); - Calculate the characteristics (I) of the object individual based on the individual characteristics, wherein the characteristics of the individual can be reproducibly generated for the same individual characteristics; - A first cryptographic key is provided based on the individual characteristics and / or the properties of the object individual, wherein the properties and / or the individual characteristics are compared with corresponding reference values, and wherein the first cryptographic key is released when the reference value matches the properties and / or the individual characteristics; - The data structure is cryptographically protected by means of a cryptographic checksum, wherein the cryptographic checksum is calculated using the first cryptographic key.
10. A method for verifying a password checksum in a computer-aided manner, comprising the following steps: - Receive a data structure, which is protected by a cryptographic checksum; - Using detection equipment (A) to detect the individual characteristics (M) of the object (O); - Calculate the characteristics (I) of the object individual based on the individual characteristics, wherein the characteristics of the individual can be reproducibly generated for the same individual characteristics; - A first cryptographic key is provided based on the individual characteristics and / or the properties of the object individual, wherein the properties and / or the individual characteristics are compared with corresponding reference values, and wherein the first cryptographic key is released when the reference value matches the properties and / or the individual characteristics; - The cryptographic checksum is verified using the first cryptographic key.
11. A computer program product having program instructions for performing the method according to any one of claims 9 to 10.
12. An apparatus for providing a computer program product according to claim 11, wherein the providing apparatus stores and / or provides the computer program product.
Citation Information
Patent Citations
Methods and systems for automatic object recognition and authentication
US10193695B1
System and method for decentralized title recordation and authentication
US20160300234A1