Method and configurable hardware module for monitoring hardware - applications

By using configurable hardware modules and firewall mechanisms in embedded devices, monitoring and controlling the communication of hardware application components, the security and reliability issues of hardware application components in embedded devices are solved, and protection of untrusted applications and safe operation of hardware components is achieved.

CN113728319BActive Publication Date: 2025-07-18SIEMENS AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080032687.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-16
Filing Date
2020-02-26
Publication Date
2025-07-18
Estimated Expiration
2040-02-26

AI Technical Summary

Technical Problem

The prior art is difficult to effectively monitor and control the incoming and outgoing communications of hardware application components in embedded devices, especially when facing untrusted third-party applications, there is a security and reliability risk, and it is impossible to ensure the secure operation of hardware application components and not maliciously tampered with.

Method used

Using configurable hardware modules, especially field programmable gate arrays (FPGAs), the monitoring and control of communications by instantiating hardware application components in an execution environment and using trusted hardware components and firewall mechanisms, including the use of kernel modules and switching modules or controllers.

Benefits of technology

It realizes security monitoring and control of hardware application components, prevents unauthorized access and tampering, ensures the security and reliability of devices, supports flexible hardware reconfiguration and adaptation to changing industrial environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113728319B_ABST
    Figure CN113728319B_ABST
Patent Text Reader

Abstract

Monitor and control the incoming and outgoing communication of a hardware-application component (HAG) during its operation. In this way, a firewall (NBF, SBF) is provided to ensure the secure and unchanged operation of a hardware-application (HA) that executes security-critical functions on a field-programmable gate array (CHM). The hardware-application component can interact directly and / or via an on-chip bus with other components. Monitoring the incoming and / or outgoing communication is particularly advantageous when using third-party hardware-applications or software-applications (i.e., applications developed by untrusted parties). Another advantage is the possibility of monitoring and controlling all communication between a hardware-application, between a hardware-application and a software-application, between a hardware-application and a peripheral device (PD), an IO controller, etc. This is particularly beneficial in cases where the hardware-application is compromised and attempts to compromise the rest of the embedded device (ED), or where a damaged software-application attempts to compromise the associated hardware-application during runtime.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Embedded devices such as electronic control units (ECUs), industrial personal computers (PCs), or Internet of Things (IoT) devices are used for various tasks in industrial processes. The correct and unmanipulated operation of such devices is crucial since they are also used to monitor and / or control critical processes (e.g., availability, reliability, real-time performance, and safety). Additionally, the growing trend of Industry 4.0 scenarios has led to an increase in the networking of industrial devices for various purposes such as monitoring, remote control, and analysis. With the increase in networked devices, industrial devices have become more vulnerable to attacks.

[0002] Since industrial embedded devices serve in the field (industrial environment) for long usage periods (typically 10 to 20 years, and sometimes 30 to 40 years), they experience a dynamically changing environment. This may lead to the requirement to develop flexible embedded devices that can cope with the ever-changing environment. This can be achieved by adopting an approach similar to that of smartphone applications, which can be downloaded / installed / upgraded at runtime. In the future, industrial devices will support a similar approach.

[0003] In addition to software applications, hardware-application components can also be implemented by using reconfigurable hardware. Hardware-application components utilize the partial reconfiguration features of, for example, field-programmable gate arrays (FPGAs), FPGA system-on-chips (SoCs), application-specific integrated circuit (ASIC) SoCs with embedded FPGAs, and application-specific standard product (ASSP) SoCs with embedded FPGAs. The hardware-application can be a separate stand-alone application such as a hardware-application component, or it can be part of a software-hardware-application bundle.

[0004] FPGAs that utilize partial reconfiguration to reconfigure parts of the hardware on-the-go are available on the market, such as Intel Cyclone V, Intel Arria 10. On a partially reconfigurable FPGA, the hardware-application can be instantiated as a hardware-application component within the partial reconfiguration region of the reconfigurable hardware.

[0005] The object of the present invention is to improve the security of configurable hardware modules that execute hardware-applications.

[0006] According to the method for monitoring a hardware-application, the following steps are performed:

[0007] - A hardware - application is received by a configurable hardware module, particularly a field - programmable gate array, wherein the received hardware - application includes configuration data that describes an instantiation as a hardware - application component on the configurable hardware module.

[0008] - The received hardware - application is instantiated as a hardware - application component in an execution environment of the configurable hardware module, particularly in a partial reconfiguration area, by a trusted hardware component, particularly on - chip logic located within the configurable hardware module, and

[0009] - The incoming and / or outgoing communications of the hardware - application component are monitored while the hardware - application component is running.

[0010] A configurable hardware module for monitoring a hardware - application includes:

[0011] - At least one execution environment that is configurable to execute a hardware - application component.

[0012] - A trusted hardware component that is configured to instantiate the hardware - application as a hardware - application component within the execution environment, and

[0013] - A first unit and / or a second unit that is configured to monitor the incoming and / or outgoing communications of the hardware - application component while the hardware - application component is running.

[0014] The following advantages and explanations are not necessarily the result of the purpose of the independent claims. Instead, they may be advantages and explanations that apply only to certain embodiments or variants.

[0015] Within each partial reconfiguration area of the reconfigurable hardware, only a single hardware - application can be instantiated simultaneously. However, a hardware / software application bundle can contain several hardware - applications, and each hardware - application can be instantiated as a hardware - application component within the same partial reconfiguration area of the reconfigurable hardware at different points in time. Additionally, other hardware - applications can be instantiated as hardware - application components within other partial reconfiguration areas of the reconfigurable hardware. The monitoring of the incoming and / or outgoing communications of the hardware - application components can be performed for only a single hardware - application component, for several hardware - application components, or for all hardware - application components.

[0016] The hardware - application component can interact directly and / or via an on - chip bus with other components. Incoming and / or outgoing communications mean any kind of interaction along the communication path to and from the hardware - application component, such as access operations, inputs, and outputs. The monitoring can be implemented by a "firewall" mechanism, which will be described in more detail below.

[0017] In connection with the present invention, "hardware - application" can be understood to mean a component, for example, written in Very High - Speed Integrated Circuit Hardware Description Language (VHDL) or in Verilog HDL and instantiated on a configurable hardware module (e.g., an FPGA). The configuration data of the hardware - application describes the layout of the hardware - application component, which can be instantiated in the hardware on the configurable hardware module. Thus, the hardware - application describes, for example, the configuration of a digital circuit that can be uploaded in the execution environment of the configurable hardware module. A hardware - application component is a hardware - application that is instantiated and executed. The configurable hardware module can include a plurality of re - configurable parts described by a configuration specification. The configuration specification includes, for example, a floor plan that describes which parts of the configurable hardware module are re - configurable at runtime. This has the advantage that, at runtime, hardware - applications including, for example, different and / or other hardware functions can be uploaded onto the configurable hardware module.

[0018] Ensuring the secure (i.e., malicious - free) and unchanged operation of the hardware - application is crucial, especially if the hardware - application instantiated as a hardware - application component on the configurable hardware module performs security - critical functions (such as encryption / decryption, key management, key agreement) or enables safety - critical operations, for example, by controlling device I / O.

[0019] Monitoring incoming and / or outgoing communications is particularly advantageous when using third - party hardware - applications or software applications (i.e., applications developed by untrusted parties).

[0020] The hardware - application can be received from a trusted software component, in particular a re - configuration and update manager.

[0021] In a preferred embodiment, all communications of all hardware - application components can be monitored and controlled.

[0022] The advantage of this embodiment is the possibility of monitoring and controlling all communications between the hardware - application, between the hardware - application and software applications, between the hardware - application and peripherals, I / O controllers, etc. This embodiment introduces the ability to monitor and filter all inputs and outputs of the hardware - application. This is particularly beneficial in cases where the hardware - application is compromised and attempts to compromise the rest of the device, or where a damaged software application attempts to compromise the associated hardware - application at runtime.

[0023] In an embodiment of the method, the monitored communications are incoming from and / or outgoing to the following:

[0024] - The kernel of the operating system executed by the processor,

[0025] - Software applications executed by the processor,

[0026] - Another hardware-application component,

[0027] - General-purpose input / output,

[0028] - Computer ports,

[0029] - Peripherals, and / or

[0030] - On-chip logic.

[0031] The monitored communications can be incoming from and / or outgoing to any number of these examples and their combinations, such as 1 core, 17 hardware-application components, 64 general-purpose input / outputs, 8 computer ports, 7 peripherals, and 1 on-chip logic. The on-chip logic can be any logic / IP core within a configurable hardware module, such as an encryption core.

[0032] Embodiments of the method include the additional step of controlling at least some of the incoming and / or outgoing communications of a hardware-application component while the hardware-application component is running, particularly by blocking and / or modifying at least some of the incoming and / or outgoing communications of the hardware-application component.

[0033] This embodiment provides a solution for monitoring, controlling, and filtering the inputs and outputs to each hardware-application. Additionally, in the case of applications developed by third parties, it can ensure that possible backdoors cannot be effectively used. It provides a mechanism to restrict hardware-applications such that they cannot access other components and data on the device, particularly the security-critical parts of the device.

[0034] By constraining the communication paths to and from untrusted applications, only the allowed data can be exchanged using the allowed set of interfaces. Thus, it supports sandboxing of hardware-applications such that compromised or untrusted hardware-applications are constrained from accessing the rest of the device. Additionally, controlling the incoming and / or outgoing communications can help ensure that the deployed hardware-applications can never obtain sufficient privileges to compromise the operation of the rest of the device - i.e., software-applications, operating systems, other hardware-applications, etc.

[0035] This embodiment can also facilitate the authentication of security-critical (and even potentially safety-critical) applications because it allows a certain degree of separation of concern. This opens up the possibility of a composite authentication process in which only the modified parts of the product need to be evaluated.

[0036] In another embodiment of the method, the monitoring step includes: detecting unauthorized access to and / or from the hardware-application component, and the control step includes:

[0037] - Blocking unauthorized access,

[0038] - Disabling access to at least one function of the hardware-application component and / or the configurable hardware module,

[0039] - Blocking all communications of the hardware-application component,

[0040] - Logging the unauthorized access,

[0041] - Replacing the hardware-application component with a secure hardware-application component, and / or

[0042] - Terminating the hardware-application component.

[0043] While the first three measures can be performed by the first unit and / or the second unit as described below, the other steps can be performed by different entities. For example, logging can be performed by a kernel module. The replacement of the hardware-application component can be performed by instantiating a known secure hardware-application component in the execution environment. Termination can be performed by disabling the clock signal of the hardware-application component. A single or any combination of the six measures of this embodiment can be implemented.

[0044] In a further embodiment of the method, the monitoring step and the control step are performed by the first unit and / or the second unit.

[0045] For example, both units are capable of monitoring and controlling communications, but handle different types of communications.

[0046] In another embodiment of the method, the first unit is a kernel module that monitors and controls communications incoming from and / or outgoing to:

[0047] - The kernel of the operating system executed by the processor, and / or

[0048] - Software applications executed by the processor.

[0049] The kernel module is customized and contains code for extending the running kernel or the so-called base kernel of the operating system.

[0050] In another embodiment of the method, the second unit monitors and controls communications incoming from and / or outgoing to:

[0051] - At least one other hardware-application component,

[0052] - At least one general purpose input / output,

[0053] - At least one computer port,

[0054] - At least one peripheral device, and / or

[0055] - At least one on-chip logic.

[0056] In another embodiment of the method, the second unit:

[0057] - Is instantiated in the instantiation step as a wrapper around the hardware-application within the execution environment,

[0058] - Is a switching module, in particular an IP core, which gates all inputs and outputs of the hardware-application component, or

[0059] - Is a controller.

[0060] The wrapper is the logic that controls all inputs and outputs of the instantiated hardware-application.

[0061] The controller can be implemented as a custom interface controller. The incoming and / or outgoing communication of the hardware-application component passes through the controller. For example, the controller can be an extension of a peripheral bus controller or be directly integrated into the peripheral bus controller.

[0062] In another embodiment of the method, the first unit and / or the second unit implements a fixed policy and / or a reconfigurable policy for controlling the incoming and / or outgoing communication of the hardware-application component.

[0063] The fixed policy and / or the reconfigurable policy consists of, for example, rules. The fixed policy can also be implicitly included in the static logic of the second unit.

[0064] These policies provide a mix of static and loadable rules that can be personalized for each hardware-application.

[0065] Since each hardware-application may communicate with a different set of on-chip peripheral devices, controllers, or other hardware-applications, these policies can be personalized for each hardware-application in order to apply sufficient security measures in all implementation scenarios. Thus, the embedded devices in the field are protected from not only hardware attacks (such as hardware trojans, compromised hardware-applications, side-channel attacks, fault injection, IC depackaging and delayering), but also software attacks.

[0066] With the help of these personalized policies, a secure execution environment is provided for each hardware-application, even though each hardware-application may need to access different sets of input / output (I / O) interfaces and corresponding controllers.

[0067] In another embodiment of the method, the reconfigurable policies of the first unit and / or the second unit are updated while the configurable hardware module is running.

[0068] For example, if the second unit is instantiated as a wrapper around the hardware-application within the execution environment during the instantiation step, then in order to update the reconfigurable policies, the wrapper and the hardware-application can be reinstantiated within the execution environment.

[0069] Embodiments of the configurable hardware module include field programmable gate arrays, application specific integrated circuits, or application specific standard products.

[0070] In another embodiment of the configurable hardware module,

[0071] - The configurable hardware module is a field programmable gate array or includes a field programmable gate array,

[0072] - The execution environment is a partial reconfiguration area, and / or

[0073] - The trusted hardware component is on-chip logic, particularly PR logic.

[0074] Due to the possibility of reconfiguring the partial reconfiguration area of a field programmable gate array, it is possible to use the hardware in a more flexible way and adapt the hardware according to changing needs and requirements. In particular, it is possible to reconfigure the configurable hardware module at runtime.

[0075] Another embodiment of the configurable hardware module includes a hardware bus that is used by hardware-application components for incoming and / or outgoing communication. The first unit and / or the second unit are configured to monitor the communication incoming from and / or outgoing to at least one device or component connected to the hardware bus.

[0076] In another embodiment of the configurable hardware module, the hardware bus is selected from a group of hardware buses including at least the following: Advanced Microcontroller Bus Architecture, Advanced High-Performance Bus, Advanced eXtensible Bus, Wishbone Bus, and / or Peripheral Component Interconnect Express Bus.

[0077] In another embodiment of the configurable hardware module, the second unit is:

[0078] - A wrapper around the hardware-application within the execution environment,

[0079] - A switching module, in particular an IP core, which gates all inputs and outputs of the hardware-application components, or

[0080] - A controller.

[0081] In another embodiment, the configurable hardware module is configured to perform the method.

[0082] The embedded device includes a configurable hardware module.

[0083] The computer-readable storage medium includes a hardware / software application package, and the hardware / software application package includes configuration information required for automated execution of the method. The configuration information includes at least one hardware-application, and the at least one hardware-application can be instantiated as a hardware-application component and executed by an execution environment. The configuration information further includes fixed policies and / or reconfigurable policies for automated monitoring and / or control of incoming and / or outgoing communications of the hardware-application components.

[0084] In an embodiment of the computer-readable storage medium, the hardware / software application package further includes a software application and a signature. The software application includes instructions executable by a processor.

[0085] When read in conjunction with the accompanying drawings, the foregoing and other aspects of the present invention are best understood from the following detailed description. For purposes of illustrating the present invention, the presently preferred embodiments are shown in the drawings. However, it is to be understood that the present invention is not limited to the specific means disclosed. The following figures are included in the drawings:

[0086] Figure 1 A schematic diagram showing a specific example for illustrating the monitoring of a hardware-application using a configurable hardware module,

[0087] Figure 2 A diagram showing the hardware / software application package, and

[0088] Figure 3 A flowchart showing a possible exemplary embodiment of the method for monitoring a hardware-application.

[0089] In the following description, various aspects of the present invention and its embodiments will be described. However, those skilled in the art will understand that the embodiments can be practiced using only some or all of their aspects. For purposes of explanation, specific numbers and configurations are set forth to provide a thorough understanding. However, it will also be clear to those skilled in the art that the embodiments can be practiced without these specific details.

[0090] Figure 1Schematically shows a specific example of monitoring a hardware - application according to the present invention using a configurable hardware module. In the illustrated exemplary embodiment, an embedded device ED (e.g., an industrial device) may include a configurable hardware module CHM (such as an FPGA) and a processor CPU. The configurable hardware module CHM and the processor CPU are provided as separate components. In an alternative embodiment, the processor CPU and the configurable hardware module CHM may be implemented by a system - on - chip design, where these components are implemented on a single chip. In another alternative embodiment, the processor CPU is provided by a reconfigurable ASIC. Thus, a software application can deploy a hardware - application to the hardware, either to use the hardware in a more flexible way or simply to reuse available resources in a more efficient way.

[0091] Due to the changing industrial environment, the use of the configurable hardware module CHM in the embedded device ED is on the rise. In the context of a partially reconfigurable FPGA, the hardware - application HA is instantiated within an execution environment PRR (e.g., the partially reconfigurable region of the FPGA).

[0092] A trusted software component - namely, a reconfiguration and update manager RUM - assigns an execution environment PRR to each hardware - application HA and manages the corresponding user and kernel - space settings. The kernel K of the operating system is executed by the processor CPU and forms an interface between the hardware - application component HAC and the user space US with the software application SA, and includes drivers for the operating system.

[0093] On the configurable hardware module CHM side, a corresponding on - chip logic PRL implements a partial reconfiguration logic (PR - logic). The on - chip logic PRL takes over the reconfiguration process and locks each execution environment PRR to its assigned hardware - application HA. The kernel K in combination with the on - chip logic PRL ensures that each execution environment PRR can only be configured by the assigned software application SA. Additionally, the kernel K and / or the on - chip logic PRL ensure that during reconfiguring the execution environment PRR with an appropriate hardware - application HA (e.g., different hardware - application HAs such as partial bitstreams), the corresponding interface settings for monitoring the incoming and / or outgoing communication of the hardware - application component while the hardware - application component is running are put into place. These interface settings can be a firewall configuration (e.g., a firewall configuration with policies) and will be described in detail below.

[0094] The non - volatile storage device NVS stores all the information necessary for restarting the embedded device ED. This information includes the operating system and a hardware / software application package HSP, which includes interface settings / firewall configurations in the form of policies.

[0095] In combination with the present invention, each hardware / software application package HSP includes one or more hardware-applications HA. Each hardware-application HA may be, for example, a partial bitstream that can be uploaded in an execution environment PRR, which is, for example, a partially reconfigurable region. The partial bitstream can be used to configure the execution environment PRR and instantiate hardware-application components HAC in the execution environment PRR, such that a software application SA can use the execution environment PRR for further processing. The partial bitstream specifies how the execution environment PRR will be configured and the hardware-application components HAC that will be instantiated.

[0096] In Figure 1 exemplarily shows two hardware-application components HAC instantiated in two execution environments PRR. The number of hardware-application components HAC on the configurable hardware module CHM and the number of execution environments PRR are not limited to Figure 1 the number shown in Figure 2 It is quite conceivable that additional execution environments PRR and hardware-application components HAC can be generated and instantiated. It is also possible to swap the currently instantiated hardware-application HA within the execution environment PRR with another hardware-application HA. As Figure 2 shown in

[0097] To monitor or even control the incoming and / or outgoing communication of the hardware-application components during their operation, a firewall mechanism is used. Firewalls are known from computer networks. Using policies in the form of a rule set, they allow or block the incoming and / or outgoing network communication of network devices. Regarding the described embodiments, the term "firewall" is used as an analogy.

[0098] The monitored communication can be incoming from and / or outgoing to the kernel K, the corresponding software application SA executed by the processor CPU, another hardware-application component HAC, general-purpose input / output GPIO, computer ports, peripheral devices PD, and / or on-chip logic PRL.

[0099] It is possible to block and / or modify at least some of the incoming and / or outgoing communication of the hardware-application components HAC during their operation.

[0100] The monitored incoming and / or outgoing communication of the hardware-application components HAC can include access operations originating from the hardware-application components HAC, such as bus accesses or accesses to peripheral devices PD.

[0101] When the monitoring detects unauthorized access, it can block the unauthorized access and / or log the unauthorized access (logging can include providing information to a reconfiguration and update manager RUM so that the latter can decide on the actions to take), generate an alert, or terminate the operation of the hardware-application component HAC, for example, by deactivating its clock signal. Additionally, or as an alternative, access to certain functions of the hardware-application component HAC and / or the configurable hardware module CHM can be disabled, or sensitive data of the hardware-application component HAC can be erased.

[0102] However, detecting unauthorized access in advance is not necessarily required to block it, since certain bus signals of, for example, the interface of the hardware-application component HAC can simply be gated.

[0103] To implement such monitoring and control of the interactions of the hardware-application component HAC within the embedded device ED, a first unit NBF and a second unit SBF are used. The first unit NBF can be understood, using the analogy from above, as a "northbound firewall".

[0104] The first unit NBF is a customized (loadable) kernel module that monitors and controls communications incoming from and / or outgoing to the kernel K and / or communications incoming from and / or outgoing to the software application SA executed by the processor CPU. In other words, the first unit NBF monitors the communication path between the hardware-application component HAC and its corresponding software application SA. For example, the first unit NBF can block access from any other unauthorized software application SA.

[0105] The second unit SBF can be understood, using the analogy from above, as a "southbound firewall". It monitors and controls communications incoming from and / or outgoing to other hardware-application components HAC, general-purpose input / output GPIO, computer ports, peripheral devices PD, IO controllers, and / or on-chip logic PRL. The hardware-application component HAC may access these directly or via an on-chip bus. The on-chip bus can be a hardware bus selected from a group of hardware buses including the following: advanced microcontroller bus architecture, advanced high-performance bus, advanced scalable bus, crossbar bus, or peripheral component interconnect express bus.

[0106] The first unit NBF and the second unit SBF implement fixed policies as well as reconfigurable policies for controlling the incoming and outgoing communications of the hardware-application component HAC. The fixed policy is a basic set of rules that is always in place. It can be developed by the device developer. The reconfigurable policy is an updatable set of rules that can be swapped (or updated) together with the hardware-application. In this way, access to security-critical interfaces can be restricted as needed.

[0107] As an alternative embodiment, only a fixed policy may be used. The fixed policy may be hard-coded in the configurable hardware module CHM.

[0108] The second unit SBF may be configured, for example, by the kernel K, in particular by the first unit NBF.

[0109] Figure 2 It shows that it can be transmitted to Figure 1 the hardware / software application package HSP shown in the embedded device ED. It consists of the following: a software application SA, one or more hardware-applications HA in the form of a first part bitstream PB-A and a second part bitstream PB-B, a manifest M, and a signature S. The manifest M includes meta-information about the hardware / software application package HSP. It includes general information GI and the reconfigurable policy as described in the previous paragraphs. In other words, the manifest M contains the configuration of the "firewall" for the execution environment PRR in which the hardware-application HA will be instantiated.

[0110] The hardware / software application package HSP can be stored on a computer-readable storage medium (e.g., a USB flash drive).

[0111] Returning to Figure 1 , the implementation of the second unit SBF can take various forms. It can be instantiated, for example, as a wrapper around the hardware-application HA within the execution environment PRR, either as part of the hardware-application component HAC or next to it. Then, it monitors and / or filters all inputs and outputs of the hardware-application HA. Additionally, it enforces the base policy as well as the reconfigurable policy, which define the set of allowed interactions between the hardware-application HA and the rest of the embedded device ED.

[0112] Another variant of the second unit is a switching module, in particular an IP core, which filters and / or gates all inputs and outputs of the hardware-application component HAC. The switching module enforces the base policy as well as the reconfigurable policy by enabling only the allowed interfaces. The base policy and / or the reconfigurable policy can be uploaded to the switching module either during system startup / initial configuration or when the hardware-application HA is loaded into the reconfigurable execution environment PRR. For example, the base policy can be uploaded to the switching module during initial configuration, and the reconfigurable policy can be uploaded to the switching module when the hardware-application HA is loaded into the execution environment PRR.

[0113] Another possibility for implementing the second unit SBF is an interface controller or a custom controller. In this scenario, all incoming and outgoing communications of the hardware-application component HAC pass through the interface controller, which is capable of enforcing both basic policies and reconfigurable policies. Additionally, the functionality of the second unit SBF can be integrated into a peripheral bus controller that uses basic and reconfigurable policies to determine whether a given access operation by the hardware-application component HAC is permitted.

[0114] Figure 3 A flowchart showing a possible exemplary embodiment of a method for monitoring a hardware-application is presented. In the illustrated exemplary embodiment, the method includes several main steps. In a receiving step S1, a hardware-application is received by a configurable hardware module, where the received hardware-application includes configuration data that describes the instantiation of a hardware-application component on the configurable hardware module.

[0115] In a further instantiation step S2, a trusted hardware component, particularly on-chip logic located within the configurable hardware module, instantiates the received hardware-application as a hardware-application component in the execution environment of the configurable hardware module, particularly in a partial reconfiguration area.

[0116] In a subsequent monitoring step S3, the incoming and / or outgoing communications of the hardware-application component are monitored while the hardware-application component is running.

[0117] Finally, in a control step S4, at least some of the incoming and / or outgoing communications of the hardware-application component are controlled while the hardware-application component is running.

[0118] Of course, the monitoring step S3 and the control step S4 can be implemented either alternately or simultaneously. In the latter case, monitoring is part of the control.

[0119] The method can be performed by a processor (such as a microcontroller or a microprocessor), by an application-specific integrated circuit (ASIC), by any kind of computer (including mobile computing devices such as tablet computers, smartphones, or laptops), or by one or more servers in a control room or in the cloud. For example, the processor, controller, or integrated circuit of a computer system and / or another processor can be configured to implement the actions described herein.

[0120] The method described above can be implemented via a computer program product that includes one or more computer-readable storage media having instructions stored thereon that are executable by one or more processors of a computing system. Execution of the instructions causes the computing system to perform operations corresponding to the actions of the method described above.

[0121] Instructions for implementing the processes or methods described herein may be provided on a non-transitory computer-readable storage medium or memory, such as a cache, buffer, RAM, flash memory, removable media, hard drive, or other computer-readable storage medium. Computer-readable storage media include various types of volatile and non-volatile storage media. The functions, acts, or tasks illustrated in the figures or described herein may be executed in response to one or more instruction sets stored in or on the computer-readable storage medium. These functions, acts, or tasks may be independent of a particular type of instruction set, storage medium, processor, or processing strategy and may be executed by software, hardware, integrated circuits, firmware, microcode, etc., operating alone or in combination. Similarly, processing strategies may include multiprocessing, multitasking, parallel processing, and the like.

[0122] The present invention has been described in detail with reference to embodiments and examples of the invention. However, variations and modifications may be made within the spirit and scope of the invention as covered by the claims. The phrase "at least one of A, B, and C" as an alternative expression may specify that one or more of A, B, and C may be used.

Claims

1. A method for monitoring a hardware - application, comprising the following steps: - Receiving (S1) the hardware - application (HA) by a configurable hardware module (CHM), wherein the received hardware - application (HA) includes configuration data that describes the instantiation as a hardware - application component (HAC) on the configurable hardware module (CHM), - Instantiating (S2) the received hardware - application (HA) as a hardware - application component (HAC) in an execution environment (PRR) of the configurable hardware module (CHM) by a trusted hardware component within the configurable hardware module (CHM), and - Monitoring (S3) the incoming and / or outgoing communications of the hardware - application component (HAC) while the hardware - application component (HAC) is running, and - Having an additional step: Controlling (S4) at least some of the incoming and / or outgoing communications of the hardware - application component (HAC) while the hardware - application component (HAC) is running by blocking and / or modifying at least some of the incoming and / or outgoing communications of the hardware - application component (HAC), - wherein the monitoring step (S3) and the control step (S4) are performed by a first unit (NBF) and / or a second unit (SBF), - wherein the first unit (NBF) is a kernel module that monitors and controls communications incoming from and / or outgoing to: - The kernel (K) of an operating system executed by a processor (CPU), and / or - A software application (SA) executed by a processor (CPU), - wherein the second unit (SBF) monitors and controls communications incoming from and / or outgoing to: - At least one other hardware - application component (HAC), - At least one general - purpose input / output (GPIO), - At least one computer port, - At least one peripheral device (PD), and / or - At least one on - chip logic.

2. The method according to claim 1, wherein the monitored communications are incoming from and / or outgoing to: - The kernel (K) of an operating system executed by a processor (CPU), - A software application (SA) executed by a processor (CPU), - Another hardware - application component (HAC), - General - purpose input / output (GPIO), - Computer port, - Peripheral device (PD), and / or - On - chip logic located within the configurable hardware module (CHM).

3. The method according to claim 1, - Among them, the monitoring step (S3) includes: Detecting unauthorized access to and / or from the hardware - application component (HAC), and - wherein the control step (S4) includes: - Blocking unauthorized access, - Disabling access to at least one function of the hardware - application component (HAC) and / or the configurable hardware module (CHM), - Blocking all communications of the hardware - application component (HAC), - Logging unauthorized access, - Replacing the hardware - application component (HAC) with a secure hardware - application component (HAC), and / or - Terminating the hardware - application component (HAC).

4. The method according to claim 1, wherein the second unit (SBF) is: - instantiated in the instantiation step (S1) as a wrapper around the hardware-application within the execution environment (PRR), - a switching module that gates all inputs and outputs of the hardware-application component (HAC), or - a controller.

5. The method according to claim 1, - wherein the first unit (NBF) and / or the second unit (SBF) implement a fixed policy and / or a reconfigurable policy for controlling the incoming and / or outgoing communication of the hardware-application component (HAC).

6. The method according to claim 5, - wherein the reconfigurable policy of the first unit (NBF) and / or the second unit (SBF) is updated when the configurable hardware module (CHM) is running.

7. The method according to claim 1, - wherein the configurable hardware module (CHM) is a field-programmable gate array or includes a field-programmable gate array.

8. The method according to claim 1, - wherein the trusted hardware component is on-chip logic (PRL).

9. The method according to claim 1, - wherein the execution environment (PRR) is a partial reconfiguration area.

10. The method according to claim 4, - wherein the switching module is an IP core.

11. A configurable hardware module (CHM) for monitoring a hardware-application (HA), comprising: - at least one execution environment (PRR) configurable for executing a hardware-application component (HAC), - a trusted hardware component configured to instantiate (S2) the hardware-application (HA) as a hardware-application component (HAC) within the execution environment (PRR); and - a first unit (NBF) and a second unit (SBF) configured to monitor the incoming and / or outgoing communication of the hardware-application component (HAC) when the hardware-application component (HAC) is running, - wherein the first unit (NBF) is a kernel module configured to monitor and control communication incoming from and / or outgoing to: - the kernel (K) of an operating system executed by a processor (CPU), and / or - a software application (SA) executed by a processor (CPU), - wherein the second unit (SBF) is configured to monitor and control communication incoming from and / or outgoing to: - at least one other hardware-application component (HAC), - at least one general-purpose input / output (GPIO), - at least one computer port, - at least one peripheral device (PD), and / or - at least one on-chip logic.

12. The configurable hardware module (CHM) according to claim 11, - including a field-programmable gate array, an application-specific integrated circuit, or an application-specific standard product.

13. The configurable hardware module (CHM) according to claim 11, wherein - the configurable hardware module (CHM) is a field-programmable gate array or includes a field-programmable gate array, - the execution environment (PRR) is a partial reconfiguration area, and / or - the trusted hardware component is on-chip logic (PRL).

14. The configurable hardware module (CHM) according to claim 11, - including a hardware bus, which is used by a hardware-application component (HAC) for incoming and / or outgoing communication, - wherein a first unit (NBF) and / or a second unit (SBF) are configured to monitor communication incoming from and / or outgoing to at least one device or component connected to the hardware bus.

15. The configurable hardware module (CHM) according to claim 14, - wherein the hardware bus is selected from a group of hardware buses including at least the following: Advanced Microcontroller Bus Architecture, Advanced High-Performance Bus, Advanced Scalable Bus, Swizzle Bus, and / or Peripheral Component Interconnect Express Bus.

16. The configurable hardware module (CHM) according to claim 11, wherein the second unit (SBF) is: - a wrapper around the hardware-application (HA) within an execution environment (PRR), - a switching module that gates all inputs and outputs of the hardware-application component (HAC), or - a controller.

17. The configurable hardware module (CHM) according to claim 11, - which is configured to execute the method according to any one of the preceding claims 1-10.

18. The configurable hardware module (CHM) according to claim 16, - wherein the switching module is an IP core.

19. An embedded device (ED), - which includes the configurable hardware module (CHM) according to any one of the preceding claims 11-18.

20. A computer-readable storage medium having stored thereon: - a hardware / software application package (HSP) including configuration information required for automated execution of the method according to any one of the preceding claims 1-10, - wherein the configuration information includes at least one hardware-application (HA), the at least one hardware-application (HA) being instantiable as a hardware-application component (HAC) and executable by an execution environment (PRR), and - wherein the configuration information includes fixed policies and / or reconfigurable policies for automated monitoring and / or control of incoming and / or outgoing communication of the hardware-application component (HAC).

21. The computer-readable storage medium according to claim 20, - wherein the hardware / software application package further includes a software application (SA) and a signature (S), and wherein the software application (SA) includes instructions executable by a processor (CPU).

Citation Information

Patent Citations

  • Configurable logic platform

    US20180089132A1