Protect the integrity of measurement data acquired by a sensor device
By calculating the aggregate value of the measurement data on the sensor device side and signing it, the problem of high computing resources on the sensor device side is solved, ensuring the authenticity of the measurement data, and achieving resource saving and time resolution improvement.
Patent Information
- Application Number
- CN202111360221.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-17
- Filing Date
- 2021-11-17
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-11-17
AI Technical Summary
The prior art is difficult to ensure the authenticity of the acquired measurement data with less computing resources on the sensor device side, especially when facing economic threats to forged data.
The aggregate value of the measured data is calculated by treating the measurement data as a forced independent variable, the previously generated aggregate value is regarded as a predetermined aggregate function of the optional independent variable, and the signature of the aggregate value is calculated using the secret key of the sensor device when a specific condition is met.
It is realized to ensure the authenticity of the measurement data with less computing resource consumption. By aggregating multiple measurement values and signing the aggregate values, resource consumption is saved and time resolution is improved to locate invalid measurement values.
Smart Images

Figure CN114510744B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the authentication of measurement data acquired by a sensor device and transmitted via a process control network. Background Art
[0002] Automation industrial plans typically include many field devices that are directly related to an industrial production process. Many of these field devices include sensors for acquiring measurement data. The measurement data is transmitted via a process control network to other entities or servers that store and / or evaluate the measurement data.
[0003] In the sense that economic benefits can be obtained from the intentional forgery of this measurement data, some acquired measurement data is critical and thus it needs to be protected against such forgery. For example, sensor devices can be used to monitor an industrial plant's compliance with environmental regulations. Also, industrial processes may use controlled substances that require permits for handling and must be accounted for end to end. If such measurement data is forged, then this may allow the operation of the plant to violate environmental regulations for greater profit, or allow the theft of controlled substances.
[0004] WO2019 / 086969A1 discloses a technique for establishing secure communication between a condition monitoring device of an electric machine and a portable device for monitoring the condition of the electric machine. Based on measurements of electrical and / or mechanical parameters of the machine, an encryption key is used to secure the communication between the condition monitoring device and the portable device.
[0005] Cryptographic operations are expensive in terms of computing resources, which tend to be limited on the field device side.
[0006] Object of the Invention
[0007] The object of the present invention is to ensure the authenticity of measurement data acquired by a sensor device with less consumption of computing resources on the sensor device side.
[0008] This object is achieved by a method for protecting the integrity of measurement data and by a corresponding method for authenticating such protected measurement data. Summary of the Invention
[0009] The present invention provides a method for protecting the integrity of measurement data acquired by a sensor device. This method includes calculating an aggregated value of the measurement data by means of a predetermined aggregation function that takes the measurement data as a mandatory independent variable and a previously generated aggregated value as an optional independent variable.
[0010] In particular, in response to new measurement data being acquired, the sensor device determines whether an aggregated value has already been generated. If the aggregated value has not yet been obtained, a new aggregated value is created by feeding the measurement data into an aggregation function. If an aggregated value already exists, this aggregated value together with the new measurement data is fed into the aggregation function in order to obtain an updated aggregated value.
[0011] This process can continue until a predetermined condition is met. Such a predetermined condition may include, for example, the following:
[0012] ● A predetermined time period has expired; and / or
[0013] ● The new aggregated value has been generated a predetermined number of times; and / or
[0014] ● The sensor device has received a request for a signature from another device; and / or
[0015] ● A previous calculation of the signature has been completed.
[0016] If the predetermined condition is met, the sensor device calculates a signature of the aggregated value using the secret key of the sensor device. This signature is output via the communication interface of the sensor device and / or it is stored in a memory. Such a memory may be internal or external to the sensor device. After that, the aggregated value may be cleared, and with the next measurement data acquired, a new aggregated value may be created.
[0017] Here, "secret" should not be regarded as a limitation with respect to the encryption scheme. The encryption scheme used for signing can be symmetric, such that the signature can be verified using the same secret key. The encryption scheme used for signing can also be asymmetric, such that the signature can be verified using the public key corresponding to the secret key. Thus, the "secret key" is merely a key and can belong to any suitable encryption scheme, and no unauthorized third party has access to the key.
[0018] The inventors have found that, compared to updating the aggregated value, the signature operation is a much more computationally expensive operation. For example, in a typical constellation, updating a hash value as the aggregated value may take on the order of milliseconds, while signing such a hash value may take on the order of seconds. Therefore, many resource consumptions can be saved by aggregating multiple measurement values and then signing the aggregated value. If the signature of the aggregated value is successfully verified, this means that all the measurement values that have been incorporated into this aggregated value are genuine. If the signature is not successfully verified, this means that one or more of those measurement values may have been corrupted and / or tampered with.
[0019] Thus, the number of measurements entering into an aggregate value can be used to set a trade-off between savings in computing resources on the one hand and time resolution, by means of which invalid measurements can be accurately located, on the other hand.
[0020] For example, while measurements may be needed at a very frequent pace for the purpose of ad-hoc process control, the need to authenticate the measurements may only occur infrequently. For example, if measurement data represents the emission of pollutants or the whereabouts of controlled substances, the need to authenticate them may only occur during spot checks by regulatory agencies. For such purposes, it may be sufficient to combine measurements over several hours or even an entire day into a single aggregate value, which is then signed.
[0021] Reducing the number of signatures that have to be computed is only one contribution to savings in computing resources. The computational cost also depends on the amount of data to be signed. Aggregation of measurement data greatly reduces this amount of data to be signed.
[0022] In particular, starting the computation of a new signature in response to the completion of a previous signature computation allows the signature to be computed using only CPU cycles that would otherwise be spent in an idle state. Whenever the CPU of the sensor device has nothing else to do, it continues to work on computing the signature for an aggregate value that has previously been formed. As soon as the CPU is needed for something else, this computation is interrupted and resumed later when the CPU is idle again. At the same time, using the measurement data that continues to be generated, the next aggregate value is already being formed. When the signature computation will be completed is not known in advance; only it is certain that it will be completed at some time, depending on the utilization of the CPU of the sensor device. When the computation is completed, the computation of the next signature for the next aggregate value available at that time can be started.
[0023] As will be explained in more detail in the discussion of the corresponding method for authenticating measurement data, measurements cannot be authenticated individually. Instead, at least one aggregate value (in which the measurements are included) needs to be recomputed, and the signature obtained from whatever source needs to be verified based on the assumption that this recomputed aggregate value is the value that was actually signed by the sensor device. That is, part of the burden of ensuring the authenticity of the measurement data is transferred from the sensor device that generates the signature to the device that later uses a given signature to authenticate a given set of measurement data.
[0024] In a particularly advantageous embodiment, the aggregation function is a hash function that maps measurement data or a combination of measurement data and one or more additional independent variables to a hash value of a fixed size as the aggregated value. Preferably, such a hash function is cryptographically secure in the sense that it is very difficult to find two distinct input values that map to the same output value through the hash function. If the signature of such a hash value is successfully verified, this even better guarantees that all the measurement data that has gone into this hash value is authentic.
[0025] In a further particularly advantageous embodiment, the aggregation function further treats the configuration information of the sensor device as an additional independent variable. This configuration information controls the behavior of the sensor device and / or controls the acquisition of measurement data by the sensor device. In this way, the successful verification of the signature of the aggregated value also ensures that the configuration of the sensor device was in a certain defined state when the measurement data was acquired.
[0026] To permit the verification of the signature, the configuration information can, for example, be passed from the sensor device to the device that authenticates the measurement data, or stored where such an authentication device can retrieve it. However, this is not required. Instead, the authentication device can also calculate the aggregated value and verify the signature based on the nominal and / or expected values of the configuration information. For example, when certain configuration information is used to set up the sensor device, this configuration information can be saved for later signature verification.
[0027] In this way, it is also possible to detect whether the configuration of the sensor device has intentionally or unintentionally deviated from a certain expected or nominal state. Such a deviation may meaningfully render the measured values less reliable than previously acquired measured values.
[0028] For example, in a setup where bacteria and / or bioenzymes are utilized to produce a desired chemical compound, the concentration of the bacteria or enzyme may not be directly measurable. Instead, such a concentration can be indirectly measured in the activity that unfolds on a test reactant when a sample containing the bacteria and / or enzyme is brought into contact with the test reactant. This is a particularly sensitive way to determine the concentration of the enzyme because when catalyzing a reaction in one unit of the test reactant, the unit of the enzyme is not "used up". Instead, one unit or the same unit of the enzyme can be reused to catalyze reactions in additional units of the test reactant, resulting in a large amplification of the measurement signal. A key parameter in such activity measurements is the temperature at which the measurement is performed. One and the same enzyme can exhibit much more activity at 37 °C compared to 20 °C. Thus, if the reaction temperature in a sensor device should normally be set to 20 °C and additional processing of the measurement data is based on the assumption that the reaction temperature is 20 °C, a configuration of the sensor device to a reaction temperature of 37 °C will cause measured values with the correct measurement units to be output, but the interpretation of these measured values will be incorrect.
[0029] In another embodiment, the configuration may include one or more of the following:
[0030] ● The measurement range of the sensor device;
[0031] ● The measurement units used by the sensor device;
[0032] ● A schedule according to which the sensor device acquires measurement data;
[0033] ● One or more processing steps that the sensor device applies to at least one sensor signal and / or measurement data; and
[0034] ● At least a portion of the firmware of the sensor device, and / or a hash value computed thereon.
[0035] For example, attempts to deliberately conceal high emissions of pollutants or steal controlled substances may include changing the measurement schedule in order to create appropriate temporal "blind spots". Also, manipulation of the firmware can be used for the same purpose.
[0036] However, including configuration information in the calculation of the aggregate value can also help detect accidental configuration changes. For example, an operator who physically accesses a sensor device in a plant and wishes to display the current temperature measurement in Kelvin instead of in °C may press the wrong key that switches data acquisition instead of just switching the display from °C to Kelvin. If the temperature to be monitored is a fairly high absolute temperature (such as the temperature inside a furnace), then an incorrect value deviating from 273.15 K may still seem plausible at first glance.
[0037] In a further particularly advantageous embodiment, the predetermined condition for triggering the calculation of the signature may be made dependent on the utilization of at least one processing resource of the sensor device required for calculating the signature. In this way, the signature can be calculated as frequently as possible without disturbing the main function of the sensor device.
[0038] For example, the sensor device may also include one or more actors acting on the industrial process in which the measurement data is acquired. For example, a stirrer process module may include a plurality of valves for feeding reactants into a reaction vessel and discharging the product from this vessel, a motor for driving a stirrer within the vessel, a heater for heating the vessel to a desired temperature, and also a thermometer for sensing the temperature within the vessel, all coordinated and combined together by a single CPU. There may be times when the processor is running without an urgent need for actions, such that the CPU is almost idle and a large part of the CPU capacity may be available for calculating the signature. However, there may also be times when the CPU is very busy coordinating the various actions in the stirrer module, so that only 20% or even less of the CPU capacity may be available for calculating the signature. In this case, for example, the time interval during which the signature is calculated may become longer.
[0039] In a further advantageous embodiment, the aggregation function may take the epoch index as an additional independent variable. This epoch index may, for example, initially be set to 0 or 1. Whenever the predetermined condition is met and the signature is calculated, it is incremented. This can be used, for example, to check whether the measurement data submitted for authentication is complete, thus making it more difficult to suppress a part of the measurement data.
[0040] In the example of emission monitoring, if there is a time period during which pollution exceeding regulatory limits is emitted, an attempt may be made to make the measurement data collected during this time period "disappear" as if it had never been there.
[0041] In another example, pharmaceutical compounds or other substances in their purest form may have an astronomical value per unit volume (up to several 100,000 € for a single beaker of the substance), but if a prescribed manufacturing protocol is violated, then that value may be lost immediately. For example, if the substance has been heated too hot in one of the processing steps of the manufacturing protocol, then it is no longer suitable for medical use and must be discarded. In the case of such an accident, it may seem economically attractive to simply "forget" about it and continue processing the substance as if nothing had happened.
[0042] If a time index enters into the calculation of an aggregated value, then such manipulation becomes considerably more difficult. If measurement data is supplied for inspection and the data includes records associated with time indices 1, 2, 3, and 5, then it is immediately obvious that a record with time index 4 is missing and thus some records are incorrect. One might try to disguise this by changing the time index of the last part of the measurement data from 5 to 4. But then, the verification of the signature will always fail because the aggregated value calculated for verifying the signature will be different from the aggregated value that was actually signed. The signature can only be successfully verified if everything that has gone into the calculation of the signed aggregated value - measurement data, configuration information, time index, and anything else - is exactly the same when the aggregated value is later reconstructed and it is checked whether this aggregated value has been validly signed.
[0043] In a further particularly advantageous embodiment, the communication interface of the sensor device for outputting the signature is configured to output data from the sensor device but is not configured to accept data into the input of the sensor device. In this way, the communication interface cannot be misused to maliciously take over control of the sensor device by deliberately sending invalid data to the sensor device. For example, an attacker might try to send more data to the sensor device than it expects in order to trigger a "buffer overflow" attack and execute arbitrary code on the sensor device. The attacker could also pursue such a goal by supplying out-of-bounds values (such as a timestamp with a minute field exceeding 60 or a negative setpoint for the rotational speed of a stirrer). Every software that accepts untrusted input is in principle vulnerable to such attacks unless each and every untrusted input is properly sanitized before use.
[0044] For example, the communication interface can encode the data output by the sensor device with the value of the current drawn by the communication interface and / or the sensor device from a current loop (such as a 4 - 20 mA current loop). There is no way to feed information back to the sensor device on such an interface.
[0045] The sensor device can output at least a portion of the data via a communication interface, and the sensor device calculates an aggregated value based on at least a portion of the data. This data can include measurement data, configuration data, epoch indices, and any other information that has been incorporated into the aggregated value (which is then signed). However, a device that authenticates given measurement data based on a given signature can obtain all of these pieces of information from whatever source (even from multiple sources). For example, the measured values can be obtained from some memory (where the sensor device previously placed the measured values), but the signature for some aggregated value can be created by the sensor device later on demand.
[0046] The present invention also provides a method for authenticating measurement data that has been acquired by a sensor device and protected using the method described above. That is, a given signature that has been generated for some aggregated value derived from this measurement data is available.
[0047] Thus, the method begins with obtaining the measurement data and obtaining at least one signature of the aggregated value that depends on this measurement data. The aggregated value is reconstructed at least in part based on the measurement data. That is, the same predefined aggregation function that is also applied on the sensor device side is applied to the measurement data and all other information that has gone into the determination of the aggregated value on the sensor device side.
[0048] The signature is verified against the reconstructed aggregated value. That is, it is determined whether the obtained signature is a valid signature of the reconstructed aggregated value. This means that if the reconstructed aggregated value does not correspond to the aggregated value previously obtained on the sensor device side, or if the signature was not made using the correct secret key of the sensor device, then the authentication of the signature will fail. If the signature algorithm is symmetric, then the signature verification can be performed using the same secret key used on the sensor device side; or if the signature algorithm is asymmetric, then the signature verification can be performed using the public key corresponding to the secret key of the sensor device.
[0049] If the verification of the signature is successful, then it is determined that the measurement data is authentic.
[0050] In a particularly advantageous embodiment, the reconstruction is at least in part based on candidate values for the measurement data and / or additional independent variables on which the aggregated value is based. If the signature verification is not successful, then new candidate values are determined and a new aggregated value is reconstructed at least in part based on the new candidate values.
[0051] That is, it is not known exactly what has been incorporated into the aggregated value (which is then signed), and one or more guesses have to be made about this effect.
[0052] For example, it may not be known exactly how many measurements have been aggregated to form the aggregated value on the sensor device side. It can be any number of measurements between 2 and 100. The aggregated value can then be reconstructed first based on 2 measurements, then based on 3 measurements, and so on, until a given signature can be successfully verified on such an aggregated value. Once the signature is successfully verified, this indicates how many measurements were aggregated on the sensor device side at the same time.
[0053] In particular, this can occur if the calculation of the signature on the sensor device side is performed "back-to-back" (i.e., as soon as the previous calculation is completed, a new signature calculation using other free CPU cycles is started). The authentication device has no way of knowing which measurements went into the signed aggregated value because this depends on the utilization of the CPU of the sensor device. Therefore, the authentication device needs to try candidate compositions of measurements until the signature is finally successfully verified.
[0054] A similar process can be carried out using the epoch index or the configuration information of the sensor device that has gone into the aggregated value. For example, if a thermometer can be configured to measure in °C, Kelvin, or °F, then the aggregated value can first be determined for the configuration to measure in °C, then for the configuration to measure in Kelvin, and then for the configuration to measure in °F.
[0055] If there are multiple constituents of the aggregated value (for which corresponding candidate values need to be explored), then these constituents can span a multi-dimensional search space that may need to be exhaustively searched until the signature is successfully verified. However, this search can be performed by any powerful computing system that receives the measurement data and the signature. In contrast, the sensor device that generates the signature typically has very limited computing power. One reason is that industrial plants usually include a very large number of sensor devices, so the additional cost of equipping the sensor devices with more computing power is multiplied by this large number of devices. Another reason is energy consumption. Sensor devices (which output their measurements by the way they draw current from a current loop) are also powered by that current loop. In a 4-20 mA current loop system, this means that sometimes there may only be 4 mA available to power the entire sensor device. In battery-powered wireless sensor devices, energy is even more scarce.
[0056] Therefore, it makes sense to have a small responsibility for generating the signature on the sensor device side (merely performing any aggregation and signing that aggregation) and to shift the larger part of the responsibility (searching the constellations for which the aggregated value is determined) to the device that authenticates the measurement data.
[0057] The methods described herein may be embodied in software that may be loaded onto a sensor device, a process controller, or any other suitable computing device. Accordingly, the present invention also relates to a computer program having machine-readable instructions that, when executed by one or more computers, cause the one or more computers to upgrade to the interface device described above.
[0058] The computer program may be sold, for example, on a non-transitory computer-readable storage medium or in the form of a download product (which, for example, allows for immediate implementation after purchase from an online store). Accordingly, the present invention also relates to a non-transitory computer-readable storage medium having the computer program or a download product. The present invention also relates to one or more computers having the computer program and / or having the non-transitory computer storage medium and / or the download product. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In the following, the present invention is illustrated using drawings without any intention of limiting the scope of the present invention. The drawings show:
[0060] Figure 1 : A exemplary embodiment of a method 100 for protecting the integrity of measurement data 2;
[0061] Figure 2 : A exemplary embodiment of a method 200 for authenticating measurement data 2;
[0062] Figure 3 : A exemplary collaboration between a sensor device 1 and a device 10 for authenticating measurement data 2. DETAILED DESCRIPTION
[0063] Figure 1 is a schematic flowchart of an embodiment of a method 100 for protecting the integrity of measurement data 2.
[0064] Method 100 reacts to event 105 (the recording of measurement data 2 has been acquired by sensor device 1). In step 110, it is then determined by sensor device 1 whether an aggregated value 3 of the recording of measurement data 2 has been generated. If this is not the case (truth value is 0), then the measurement value 2 is optionally mapped, together with the configuration information 1a of sensor device 1 and / or the running epoch index 5, to a newly generated aggregated value 3 by means of a predetermined aggregation function H, where the aggregated value 3 at this time relates to only a single recording of measurement data 2. However, if the aggregated value 3 already exists (truth value is 1 at diamond 110), then the same aggregation function H is used in step 130 to update the aggregated value 3. That is, the aggregated value 3 that previously related to n recordings of measurement data 2 is transformed into a new aggregated value 3' that relates to n + 1 recordings of measurement data 3. Similar to step 120, if the epoch index 5 is used, then this can also go into the updated aggregated value 3'. Also, the configuration information 1a of sensor device 1 can go into the updated aggregated value 3'. If this configuration information 1a has been updated since the last update of the aggregated value 3, then such updated configuration information 1a can be used.
[0065] Method 100 also reacts to event 140 (a predetermined condition is satisfied) (such as the expiration of a predetermined time period, the generation of a certain number of new aggregated values 3' or a specific request for a signature 4 from another device 10 that wishes to authenticate measurement data 2). According to block 141, the predetermined condition (such as the time period or the number of new aggregated values 3') may depend on the utilization of the processing resources of sensor device 1 required for calculating the signature 4.
[0066] If the running epoch index 5 is used, then this can be updated in block 145 in response to the predetermined condition being satisfied.
[0067] In step 150, a signature 4 of the aggregated value 3 is calculated using the secret key of sensor device 1. This signature 4 can then be output via the communication interface of sensor device 1 in step 160, and / or stored in a memory inside or outside sensor device 1 in step 170. For the purpose of authenticating measurement data 2 later, it is only important that the device 10 that will perform such authentication retrieves the measurement data 2 and the signature 4 from whatever source. According to block 161, other information that has gone into the aggregated value 3 (such as the epoch index 5 or the configuration information 1a) can also be output to assist in the authentication.
[0068] Figure 2It is a schematic flow chart of method 200 for authenticating measurement data 2, which has been protected using the above-mentioned method 100. In step 210, measurement data 2 and at least one signature 4 of an aggregation value 3 depending on this measurement data 2 are obtained. In step 220, aggregation value 3 is reconstructed at least partly based on measurement data 2. In theory, aggregation value 3 could also be obtained from whatever source in step 210 and used immediately without reconstructing it. However, it is better for security to always reconstruct aggregation value 3 in step 220 because this reconstruction proves that aggregation value 3 actually belongs to the supplied measurement data 2. In the case of such evidence, successful verification of signature 4 with respect to aggregation value 3 also implies the sought authenticity of measurement data 2.
[0069] In step 230, signature 4 is verified with respect to aggregation value 3. If this verification is successful (true value is 1), then in step 240 it is determined that measurement data 2 is authentic.
[0070] According to block 221, reconstruction 220 of aggregation value 3 can be based on candidate values C for measurement data 2 and / or additional independent variables, from which aggregation value 3 is obtained. That is, if some of this information is not actually known, it can be searched for by trying candidate values C: if the verification fails (true value at diamond 230 is 0), then new candidate values C can be determined in step 250. * 。These new candidate values C * can be fed back into the reconstruction of aggregation value 3 in block 221, such that a new aggregation value is produced. Then the given signature 4 can be verified with respect to this new candidate value 3.
[0071] Figure 3 Illustration of the cooperation between sensor device 1 and device 10 for authenticating measurement data 2. As Figure 3 illustrated and as discussed in detail previously, sensor device 1 calculates aggregation value 3 according to steps 120 and 130 of method 100 based on the recording of measurement data 2, configuration information 1a of the sensor device, and the running epoch index 5. Sensor device 1 calculates signature 4 of this aggregation value 3 using its secret key according to step 150 of method 100.
[0072] The measurement data 2 and the signature 4 can be supplied from the sensor device 1 to the device 10 that desires to authenticate the measurement data 2. The same applies to the configuration information 1a and to the epoch index 5. This can be used as an aid in authenticating the measurement data 2, but it is not required. Instead, the device 10 that desires to authenticate the measurement data 2 can obtain all the information from any source. After all, the main advantage of authentication is that successfully authenticated measurement data 2 can be freely used even if they are from an untrusted source. For example, if the authentication device 10 is a process controller connected to the same network as the sensor device 1, then the configuration information 1a can even be supplied from the authentication device 10 to the sensor device 1.
[0073] As previously discussed, in the authentication device 10, according to step 220 of method 200, the aggregated value 3 is reconstructed based on the measurement data 2, the configuration information 1a, and the epoch index 5. Then, according to step 230 of method 200, the signature 4 is verified with respect to the reconstructed aggregated value 3.
[0074] List of reference symbols
[0075] 1 Sensor device
[0076] 1a Configuration information of sensor device 1
[0077] 2 Measurement data
[0078] 3, 3' Aggregated value
[0079] 4 Signature of aggregated value 3
[0080] 5 Epoch index
[0081] 10 Authentication device
[0082] 100 Method for protecting the integrity of measurement data 2
[0083] 105 Acquisition of measurement data 2
[0084] 110 Determine whether the aggregated value 3 already exists
[0085] 120 Create a new aggregated value 3
[0086] 130 Update the existing aggregated value 3
[0087] 140 Meet the predetermined conditions
[0088] 141 Vary the predetermined conditions based on resource utilization
[0089] 145 Update the epoch index 5
[0090] 150 Calculate the signature of the aggregated value 3
[0091] 160 Output the signature via the interface
[0092] 161 Output information and use it to calculate the aggregated value 3
[0093] 170 Store the signature 4
[0094] 200 Method for authenticating measurement data 2
[0095] 210 Obtain measurement data 2 and signature 4
[0096] 220 Reconstruct the aggregated value 3
[0097] 221 Based on candidate values C, C * to reconstruct
[0098] 230 Verify the signature 4 against the reconstructed aggregated value 3
[0099] 240 Determine that the measurement data 2 is authentic
[0100] 250 Determine a new candidate value C *
[0101] C, C * Candidate value
[0102] H Aggregation function
Claims
1. A method (100) for protecting the integrity of measurement data (2) acquired by a sensor device (1), comprising: in response to the measurement data (2) being acquired, determining by the sensor device (1) whether an aggregated value (3) has been generated, and: if the aggregated value (3) has not been obtained yet, mapping the measurement data (2) to the aggregated value (3) by means of a predetermined aggregation function (H) that takes the measurement data (2) as a mandatory independent variable and the previously generated aggregated value (3) as an optional independent variable; while if the aggregated value (3) has been obtained, mapping the combination of this aggregated value (3) and the measurement data (2) to a new aggregated value (3') by means of the aggregation function (H); and in response to a predetermined condition being satisfied, using a secret key of the sensor device (1) to calculate a signature (4) of the aggregated value (3); and outputting the signature (4) via a communication interface of the sensor device (1), and / or storing the signature (4) in a memory, wherein the aggregation function (H) is a hash function that maps the measurement data (2) or a combination of the measurement data (2) and one or more additional independent variables to a hash value of a fixed size as the aggregated value (3).
2. The method (100) according to claim 1, wherein, the aggregation function (H) further takes configuration information (1a) of the sensor device (1) as an additional independent variable, wherein the configuration information (1a) controls the behavior of the sensor device (1) and / or controls the acquisition of measurement data (2) by the sensor device (1).
3. The method (100) according to claim 2, wherein, the configuration information (1a) includes one or more of the following: the measurement range of the sensor device (1); the measurement unit used by the sensor device (1); a schedule according to which the sensor device (1) acquires measurement data (2); one or more processing steps applied by the sensor device (1) to at least one sensor signal and / or the measurement data (2); and at least a part of the firmware of the sensor device (1), and / or a hash value calculated thereon.
4. The method (100) according to any one of claims 1 to 3, wherein, the predetermined condition includes the following: a predetermined time period has expired; and / or the new aggregated value (3') has been generated a predetermined number of times; and / or the sensor device (1) has received a request for the signature (4) from another device (10); and / or a previous calculation of the signature (4) has been completed.
5. The method (100) according to any one of claims 1 to 3, wherein, the predetermined condition is made depending on the utilization of at least one processing resource of the sensor device (1) required for calculating the signature (4).
6. The method (100) according to any one of claims 1 to 3, wherein, The aggregation function (H) treats the epoch index (5) as an additional independent variable, and wherein the method (100) further comprises, in response to the predetermined condition being satisfied: incrementing the epoch index (5).
7. The method (100) according to any one of claims 1 to 3, wherein, the communication interface for outputting the signature (4) of the sensor device (1) is configured to output data from the sensor device (1), but is not configured to accept data for input to the sensor device (1).
8. The method (100) according to claim 7, wherein, the communication interface encodes the data output by the sensor device (1) with the value of the current drawn by the communication interface and / or the sensor device (1) from the current loop.
9. The method (100) according to any one of claims 1 to 3, further comprising outputting at least a portion of the data through the communication interface, and the sensor device (1) calculates an aggregate value (3) based on the at least a portion of the data.
10. A method (200) for authenticating measurement data (2), the measurement data (2) having been acquired by a sensor device (1) and protected using the method (100) according to any one of claims 1 to 9, the method (200) for authenticating measurement data (2) comprises: obtaining at least one signature (4) of the measurement data (2) and an aggregate value (3) depending on the measurement data (2); reconstructing the aggregate value (3) at least partly based on the measurement data (2); verifying the signature (4) against the reconstructed aggregate value (3); and if this verification is successful, determining that the measurement data (2) is authentic.
11. The method (200) for authenticating measurement data (2) according to claim 10, wherein, The reconstruction is at least partially based on candidate values (C) for the measurement data (2) and / or additional independent variables, the aggregated value (3) is obtained according to the candidate values, and wherein the method for authenticating the measurement data (2) further comprises: if the verification is unsuccessful, determining new candidate values (C * ) and at least partially based on the new candidate values (C * ) to reconstruct a new aggregated value (3').
12. A computer program product having a computer program comprising machine-readable instructions which, when executed by one or more computers and / or by a sensor device, cause the one or more computers and / or the sensor device (1) to perform the method according to any one of claims 1 to 11.
13. A non-transitory storage medium having a computer program comprising machine-readable instructions which, when executed by one or more computers and / or by a sensor device, cause the one or more computers and / or the sensor device (1) to perform the method according to any one of claims 1 to 11.
14. A sensor device having the non-transitory storage medium according to claim 13.
Citation Information
Patent Citations
Condition monitoring device and method for secure communication
WO2019086969A1
Techniques to secure computation data in a computing environment
CN107851167A
A safe vehicle crowd sensing method based on fog computing
CN109862114A