Method for generating security control data for a local machine

By performing some computations in a cloud application outside the local machine and checking the security of control data in the local software application, the problems of limited local hardware resources and unreliable cloud connections are solved, enabling secure and efficient generation and processing of control data.

CN115310054BActive Publication Date: 2026-04-17TEH TEHI COMPUTER TECH AKCHEN GESELLSCHAFT
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TEH TEHI COMPUTER TECH AKCHEN GESELLSCHAFT
Filing Date
2022-03-16
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Local machines have limited hardware resources, making it difficult to handle complex security control data calculations. At the same time, cloud computing networks are not reliable enough to meet security requirements, making it impossible to effectively outsource security-critical computing tasks.

Method used

By performing some computations in a cloud application outside the local machine and checking the control data generated by the cloud application within the local software application to ensure that only data within the safe parameter range is used to control the local machine, outsourced computation includes sensor data and additional information to improve computational efficiency.

Benefits of technology

This enables the use of cloud computing resources to improve computing power and efficiency, reduce the burden on local hardware, and ensure the timeliness and security of control data, while ensuring the safe operation of local machines.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115310054B_ABST
    Figure CN115310054B_ABST
Patent Text Reader

Abstract

Methods and systems for generating security control data to control and / or monitor a local machine, wherein a local software application executes on a secure hardware device of a security device, the local software application performs calculations based on input data to generate the security control data, wherein software in the cloud, i.e., a so-called "cloud application," is executed on hardware external to the security device, and wherein the local software application sends a request to the cloud application, the request including a request to perform one or more defined calculations on at least one cloud application and specific input data that will be used by at least one cloud application to perform one or more defined calculations, and wherein if the local software application receives the control data of the requested calculation in a timely manner, it checks whether the control data is within a security parameter range, and if the control data is within a security parameter range, the control data is identified as security control data and will be used to control and / or monitor the local machine.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This invention relates to a method for generating security control data to control a local machine, such as a technical device, like a vehicle, particularly an automobile, wherein security devices are assigned to the local machine, wherein the security devices include security hardware devices, the security devices are provided with input data associated with the local machine, and wherein the security devices include a local software application executed on the security hardware device of the security devices, wherein the local software application is a security software application, the local software application performing calculations based on the input data to generate the security control data, such as control data conforming to the security requirements of the local machine.

[0002] Furthermore, the present invention relates to a system for performing a method according to the invention to generate security control data to control a local machine, the local machine being, for example, a technical device such as a vehicle, particularly an automobile, wherein the system includes a security device assigned to the local machine, wherein the security device includes security hardware, the security device being provided with input data associated with the local machine, and wherein the security device includes a local software application executed on the security hardware of the security device, wherein the local software application is a security software application configured to perform calculations based on the input data to generate the security control data, the security control data being, for example, control data conforming to the security requirements of the local machine.

[0003] To control a machine, the so-called "local machine," various software programs are now used. This software executes on the local hardware of the local machine (such as the local CPU and memory) to calculate the behavior of the local machine. For example, the software performs calculations to generate control data, based on which the local machine is controlled and / or monitored. Typically, multiple sensors are provided to monitor the local machine and / or the physical processes running on / in the local machine and / or the environment in which the local machine exists. Based on this monitoring, the sensors provide input data to the software, which performs the calculations described above. The control data delivered by these calculations is typically transmitted to multiple actuators that control the local machine (movement, physical processes, etc. on the local machine) based on this control data.

[0004] The software that we execute on the local hardware of the local machine to generate control data for the local machine, and in particular for the actuators of the local machine, is called a "local software application".

[0005] For example, a local machine can be a robot in a factory, a mobile device such as a vehicle (car, etc.), or an airplane. Examples of physical processes are the control of conveyor belt speeds and robotic arms in a factory, the trajectory and speed of vehicles, and the control of valves and other equipment that can be controlled by electronics and motors. These actuators are controlled in such a way that the local machine is controlled according to its safety requirements. This means that the local machine operates based on control data (according to safety requirements) within a defined range of so-called "safety" parameters, wherein said control data must be provided within defined time limits (according to safety requirements) so that the actuators can be controlled in a timely manner according to the local machine, particularly its actual state and / or its environment, particularly the local machine's situation relative to its environment.

[0006] Some of the software used to generate control data may be part of safety-critical or safety-related functions. For example, in automobiles, automated cruise control is a safety-critical / related function.

[0007] Typically, the control data that ensures the safe operation of the local machine controlled according to these control data, i.e., the control data based on the safety requirements of the local machine, is referred to as "safety control data." In this context, it should be noted that the safety requirements, particularly the range of safety parameters for the control data, and the defined ("safety") time limits within which the control data (e.g., the transmission to actuators) must be provided, depend on the respective local machine (car, robot, etc.), especially its specifications, and / or on the specific state / situation in which the local machine operates at the corresponding moment in consideration.

[0008] Control data that allows a local machine to be operated safely (i.e., according to its security requirements) is called "security control data".

[0009] For example, “safe” or “safe operation” means that there are no catastrophic consequences for the local machine(s) or the local machine environment (A. Bondavalli, S. Bouchenak, H. Kopetz (Eds.)). Cyber- Physical Systems of Systems , Springer (2016). Therefore, "safe operation" of a local machine means that the local machine operates in a way that prevents catastrophic consequences from occurring. As mentioned above, the control data that ensures the safe operation of the local machine is called "safety control data".

[0010] As explained above, security requirements can be provided for the local machine. For control data to represent security control data, the control data must meet the security requirements of the local machine. In any case, the use of "security" control data prevents the local machine from entering an unsafe state, in which the local machine would not be able to operate safely, for example, under conditions contained in the specifications of the local machine and its environment.

[0011] To ensure safety, general software, or particularly native software applications, must be developed according to strict software design rules as defined, for example, in the ISO 26262 standard. Specifically, the ISO 26262 standard defines automotive Safety Integrity Levels (ASILs) from ASIL A (least critical ASIL) to ASIL D (most critical ASIL). To ensure safety, hardware or general equipment must be developed according to strict software design rules as defined, for example, in the ISO 26262 standard. Specifically, the ISO 26262 standard defines automotive Safety Integrity Levels (ASILs) from ASIL A (least critical ASIL) to ASIL D (most critical ASIL).

[0012] Software (or software applications) designed to generate security control data is called "security software".

[0013] Hardware designed to generate security control data is called "security hardware".

[0014] A device designed to generate security control data is called a "security device". A security device is, for example, security hardware or includes security hardware, or (or includes) security hardware and software, particularly security software, running on said security hardware.

[0015] To obtain the best and most efficient results from software-executed calculations, large amounts of data, especially input data, are considered to need to be processed in calculations that are sometimes highly complex. Unfortunately, locally available hardware (e.g., electronic control units - ECUs) is typically limited in terms of processing power and available memory. Other limitations, such as the heat generated and available energy, may also apply.

[0016] Since these local hardware components (such as ECUs) are typically connected via network, it is possible to store and process some data in the cloud. This may especially refer to non-time-critical data, such as data needed to optimize production processes in a factory or vehicle routes based on traffic conditions. Because this data is not safety-critical / relevant to the operation of local machines, some preprocessing can even be performed in the cloud, thus alleviating this burden on local hardware.

[0017] Unfortunately, network connections to the cloud are not reliable enough to meet certain security requirements of local machines. However, it would be preferable to outsource as much processing power and storage as possible to the cloud (including security-critical and security-related computing / accounting).

[0018] The object of this invention is to enable the use of control data of a local machine computed externally on the local machine, for example, through software located in the cloud, while still ensuring the secure operation of the local machine.

[0019] This objective is achieved using the method described above, wherein at least one software application in the cloud, a so-called "cloud application," is provided. This cloud application is a software application that executes on hardware outside the security device, particularly outside the local machine. The at least one cloud application is configured to perform calculations based on specific input data provided by a local software application to the at least one cloud application to generate control data for controlling and / or monitoring the local machine. The local software application sends a request to the at least one cloud application, for example, in one or more request messages, wherein the request includes…

[0020] • Information about which one or more definitions' computations will be performed by at least one cloud application, and

[0021] • The specific input data will be used by at least one cloud application to perform one or more defined computations.

[0022] And among them

[0023] - If a local software application and / or a security device receives one or more requested, defined computational control data from at least one cloud application within a defined time period or before a defined time point, then the local software application or the security device, for example, by checking software executed on the security hardware of the security device, checks whether the control data is within the range of security parameters.

[0024] If the control data is within the security parameter range, then the control data is deemed qualified as secure control data, and in addition to, or in lieu of, secure control data generated by calculations performed by the local software application, the control data will be used to control the local machine.

[0025] If the control data is outside the security parameter range, it will not be considered secure control data and will not be used to control the local machine. Only secure control data generated through calculations performed by the local software application will be used to control the local machine.

[0026] Control data provided by at least one cloud application that is not received by the local software application and / or security device within the defined time period or before the defined time point will not be used to control the local machine, and only security control data generated by calculations performed by the local software application will be used to control the local machine.

[0027] This objective is also achieved using the aforementioned system, which further comprises: hardware external to the security device, particularly external to the local machine, and at least one software application in the cloud, a so-called "cloud application," which is a software application executing on the external hardware. The cloud application is configured to perform calculations based on specific input data provided by the local software application to the cloud application to generate control data for controlling and / or monitoring the local machine. The local software application is configured to, for example, send a request to the at least one cloud application in one or more request messages, wherein the request includes…

[0028] • Information about which one or more definitions' computations will be performed by at least one cloud application, and

[0029] • The specific input data will be used by the cloud application to perform one or more defined computations.

[0030] And among them

[0031] The local software application and / or security device is configured to receive control data for the calculation of one or more requests for the following:

[0032] - If the local software application and / or security device receives one or more requested defined computational control data from the cloud application within a defined time period or before a defined time point,

[0033] The control data is checked, for example, by a local software application or by a security device, such as by checking software running on the security hardware of the security device, to see if it is within the range of security parameters.

[0034] If the control data is within the safety parameter range, then the control data is considered safe control data, and in addition to, or in lieu of, safe control data generated by calculations performed by the local software application, the control data will be used to control the local machine.

[0035] If the control data is outside the security parameter range, it will not be considered secure control data and will not be used to control the local machine. Only secure control data generated through calculations performed by the local software application will be used to control the local machine.

[0036] Control data provided by the cloud application that is not received by the local software application and / or security device within the defined time period or before the defined time point will not be used to control the local machine, and only security control data generated by calculations performed by the local software application will be used to control the local machine.

[0037] Control data includes one or more parameters. For a parameter to be classified as a safe parameter, its value must fall within certain limits / margins (“safety margins”), such as depending on the corresponding state and / or environment of the local machine. This range between safety margins is called the “safe parameter range.” Control data including more than one parameter can be classified as safe control data if all parameters are within their safe parameter range (“control data within safe parameter range”). For example, in the case where the local machine is a vehicle, the control data may include one or more of the following parameters: speed, acceleration / deceleration, direction of movement, trajectory, etc.

[0038] Furthermore, control data must be available in a timely manner to ensure safe control of the local machine under given circumstances. Therefore, this control data must also be available within a defined time period, or before or no later than a defined time, depending on the specific circumstances. Control data that is provided promptly within the specified safety parameters represents safety control data.

[0039] Native software applications (which are security software) are included in security devices, which include security hardware (devices) on which the native software applications are executed. In this context, the term "security" refers to the hardware and / or security devices on which the native applications are executed, and the native software is preferably developed according to strict design rules as defined, for example, in the ISO 26262 standard. In particular, the ISO 26262 standard defines automotive safety integrity levels (ASILs) from ASIL A (least critical ASIL) to ASIL D (most critical ASIL).

[0040] Therefore, the control data provided by safety equipment is safety control data, because safety equipment ensures that the generated control data is within the range of safety parameters and is provided in a timely manner.

[0041] This invention provides a method for integrating cloud computing / accounting into the computation of a local machine's behavior without sacrificing the security required for critical functions that allow the machine to operate according to security requirements as demanded by a particular type of application.

[0042] Local software applications themselves can provide safety margins for cloud application control data and / or defined time periods (or defined time points), or different additional software, such as additional software for security devices, can provide safety margins and / or defined time periods (or defined time points).

[0043] The check can be performed via local software applications and / or via specific checking software executed within a security device, preferably on the security hardware of the security device, to check whether control data from the cloud was received within a defined time period (or up to a defined point in time) and / or to check whether the control data is security control data. The checking software can be specific software, or this functionality can be implemented via the additional software mentioned above.

[0044] According to the invention, a local software application running on a secure hardware device, configured to generate security control data by performing calculations, "outsources" one, more, or all of the calculations it is performing to an external cloud application. The local machine, particularly the local application, sends a request to the external cloud application, anticipating a result within a defined time period or up to a defined point in time. This time period or point in time is specific to the particular request, particularly to the calculation to be performed by the cloud application, as it depends on the (time) criticality of the required functionality or control data.

[0045] Local software applications are configured to calculate safety control data themselves, and to calculate safety margins or safety parameter ranges, such as the range / domain of control data values, where control data within that range / domain is classified as safety control data.

[0046] The local software application anticipates results within a defined time period (or up to a defined point in time), i.e., control data generated by the cloud application. Typically, this time period (or point in time) is known a priori to the local software application. However, it can also be specified that the local software application is configured to calculate the "defined" time period (or defined point in time) such that, for example, different time periods (or different points in time) can be considered depending on the actual conditions / state of the local machine.

[0047] Typically, the defined time period begins from a starting point within the defined time. For example, the starting point within the defined time could be the point at which the request begins to be transmitted to one or more cloud applications, or the point at which the request has already left the local application or security device.

[0048] Instead of defining a time period, it is possible to specify that control data generated by cloud applications must arrive at a defined time point, where the defined time point can be a fixed time point, or the local application can calculate a specific defined time point for some requests or for each request.

[0049] In a further description, if the invention is described based on a defined time period, the invention will work similarly when a defined point in time is used instead of a defined time period.

[0050] According to the present invention, security control data is used only to control and / or monitor the local machine—in cases where there is no cloud application request for defined computation delivery receiving control data within a defined time period or up to a defined point in time, or where there is no defined computation delivery receiving control data within a defined time period or up to a defined point in time within the security parameter range, security control data generated by the local software application is used only to ensure that the local machine operates within the security parameters.

[0051] Preferred embodiments (methods and systems) of the invention may be provided individually or in any arbitrary combination below, as described.

[0052] For each defined calculation, a specific time period or a specific time point can be provided, or only one defined time period or only one defined time point can be provided for all calculations.

[0053] Defined computations can be distinguished from each other by the type of computation and / or by the “time point” in which the computation is performed (or by the time point in which the result needs to be computed).

[0054] For example, the first calculation delivers control dates for a first set of actuators, while the second calculation delivers control data for a second set of actuators; therefore, the two calculations are different in the “type” of calculations.

[0055] Furthermore, for example, the results / control data of the first calculation (the first type of calculation) are always expected to occur within the same time period—in this case, two "first calculations" performed at different times are indistinguishable from each other. However, it can also be specified that the results of the first calculation performed now will be expected to occur earlier / later than the same first calculation performed later. In this case, these first calculations are calculations with different definitions.

[0056] External hardware used for cloud applications can be secure hardware and / or cloud applications can be secure software applications.

[0057] However, preferably, the external hardware used for the cloud application is insecure hardware and / or the cloud application is insecure software, i.e., it is not developed according to the security standards of the security device and / or the security standards of the local application. In this case, it is easier and / or cheaper to provide more performant hardware and / or software.

[0058] External hardware running one or more cloud applications may be more powerful than security hardware devices, and / or at least one cloud application may be more powerful than a local software application.

[0059] It can be stipulated that the range of security parameters is calculated by local software applications, for example, based on input data related to the local machine.

[0060] It can be stipulated that if the calculation result is within the range of security parameters, the local software application or security device, such as inspection software, shall check the calculation defined for each request separately.

[0061] If the results of some calculations are received within the defined time period or up to the defined point in time, but not all results are within the security parameter range, then at least some results—that is, the results of calculations within the security parameter range—can be used to control and / or monitor the local machine. Alternatively, if only one result of the defined calculations included in the request is not within the security parameter range, then none of the results from the request can be used.

[0062] At least one cloud application can be configured to perform at least some, preferably all, of the computations that can be performed by a local application.

[0063] Cloud applications can function like local software applications. A cloud application can be configured to perform only a portion of the computations that a local software application is configured to perform. A cloud application can be configured to perform the same computations as a local software application, and can also be configured to perform additional computations that cannot be performed by a local software application.

[0064] When a particular computation can be performed by a local software application and the same computation can be performed by a cloud application, we refer to these computations as “corresponding computations”.

[0065] A specific computation performed by a cloud application using the same input data as the corresponding computation performed by a local software application will (in the absence of failures) deliver at least the same output as the corresponding computation performed by the local software application, such as the same control data. Typically, because cloud applications are more powerful than local software applications and / or run on more powerful hardware, specific computations performed on cloud applications will generally deliver their outputs faster than those of local software applications, and / or the outputs of cloud applications will be more refined.

[0066] Instead of the results of calculations performed by local software applications, particularly the results of corresponding calculations performed on local software applications, control data provided by specific calculations from at least one cloud application, which is identified as security control data, can be used.

[0067] In addition to the results of calculations performed by local software applications, particularly the results of corresponding calculations performed on local applications, control data provided by specific calculations from at least one cloud application may be used, which is identified as security control data.

[0068] It can be specified that input data and / or specific input data related to the local machine include

[0069] - Sensor data from one or more sensors (e.g., cameras, radar, lidar, ...) monitoring the surrounding environment of the local machine; and / or

[0070] - Sensor data from one or more sensors (e.g., cameras, radar, lidar, ...) monitoring the local machine and / or the processes being executed on the local machine; and / or

[0071] - Data describing the state of the local machine, such as data provided by one or more actuators of the local machine, subsystems of the local machine, or configuration data of the local machine.

[0072] Preferably, the specific input data is the same as the input data associated with the local machine, or includes all input data associated with the local machine, or the specific input data is a proper subset of the input data associated with the local machine. Set A True subset If set A is a subset, then the subset is not equal to set A.

[0073] Specific input data may include information about security devices and / or local software applications, particularly information about the type of local application.

[0074] This allows cloud applications to identify which functions / computations a local software application must perform and which actuators on the local machine must be controlled. This can be particularly advantageous when different security devices are provided, such as different security devices on different local machines, where the same local application is executed on said different security devices. In this case, a cloud application can perform computations and provide control over two or more local applications running on different security devices.

[0075] Two or more cloud applications may be provided, which are configured to perform different computations, wherein preferably, the request message is routed to a defined cloud application based on specific input data contained in the request message, particularly based on information about security devices and / or local software applications.

[0076] Therefore, the request can be routed to the appropriate cloud application, which is configured with regard to the overall capabilities of the device and the intended purpose of the local software application.

[0077] Preferably, one or more distribution units are provided, either on the local machine or outside the local machine, such as in the cloud, through which the local software application can communicate with one or more cloud applications.

[0078] As mentioned above, cloud applications can perform computations for two or more identical local software applications running on different security devices.

[0079] It can also be specified that the local software application communicates with two or more cloud applications, where different cloud applications can perform different computations for the local software application. It can also be specified that two or more cloud applications perform the same computation, allowing the local software application to decide which results to use (e.g., based on the time point at which it receives control data and / or depending on the "quality" of the control data).

[0080] It can also be specified that exactly one cloud application is provided, which is configured to perform all the computations of the local software application.

[0081] Preferably, the safety equipment is specified as part of the local machine.

[0082] It can be defined that a cloud application is a software application that is connected to a local software application via the Internet.

[0083] In addition, it can be specified that, in response to a request message from a local software application, the cloud application sends a response message to the local software application, wherein the response message includes control data for computation defined by the local software application.

[0084] For example, the message may contain control data for one or more actuators on the local machine. If the control data for the actuators is deemed safe control data and therefore can guarantee that the behavior of the local machine is kept within safe boundaries, then the control data will be verified by the local software application and used.

[0085] It can be specified that response messages from cloud applications include information indicating whether this is the final message from the cloud application or whether the cloud application intends to send one or more additional response messages.

[0086] Control data received via partial responses from cloud applications can be used by local software applications to control and / or monitor the local machine if the control data is deemed to be security control data.

[0087] Control data computed by a cloud application in response to a specific computing request is transmitted to the local application via one or more response messages. The sum of all response messages necessary to transmit all control data for a specific request is called a "response." (In cases where all control data for a specific computing request is transmitted via only one response message, that response message is referred to as a "response.")

[0088] When a response consists of two or more response messages, and the local software application has received at least one but not all of the response messages, the local software application has received what is called a "partial response".

[0089] Now, in the case of receiving a partial response, as long as the machine is operating within the safety parameters, the control data contained in the partial response can be identified as safety control data and can be used to control and / or supervise the local machine.

[0090] It can be stipulated that the cloud application is notified of the termination message that no further computation is required. The termination message is preferably sent by the requesting local software application. Preferably, the termination message includes information about the reason for termination, such as, for example, that a defined time period has been exceeded and / or that the received computation result is not within the range of security parameters, and / or preferably includes the actual state implemented by the local machine.

[0091] Preferably, the cloud application is specified to take additional inputs, particularly additional input data, into its (one or more) computations, wherein the additional inputs, particularly the additional input data, are available to the cloud application but not to the local software application.

[0092] Such additional inputs or additional data may include, for example, overall configuration data for different devices (such as the local machine and other devices that work together but are not directly connected, so that the local machine has little or no information about the other devices), route optimization for the local machine based on traffic and track information (e.g., if the local machine is a car), information on synchronization of different devices (such as the local device) based on available resources, etc., so that the quality of control data provided by the cloud application can be improved relative to the corresponding control data provided by the local application.

[0093] In a manufacturing plant, various pieces of equipment (local machines) are provided, such as conveyors, valves, gripping arms, etc. Typically, all these devices work together, but they may not necessarily be directly connected to each other. The same can be true for vehicles.

[0094] Control data provided by cloud applications, using the additional input data described above, can help coordinate the collaboration of such devices.

[0095] For example, if a vehicle or warehouse machine needs to be moved from point A to point B, there may be multiple paths. One path might be blocked, which is unknown to the device's local software application (i.e., the local machine), or one of the paths might be better, which is only known to the cloud application through additional input data. Therefore, while the local software application cannot consider this information (the additional input data) in its calculations, the cloud application can. Consequently, the control data provided by the cloud application can be better than the control data determined by the local software application through its corresponding calculations.

[0096] Furthermore, cloud applications may have additional available data in the cloud, which could lead to different outcomes, also within the scope of security. Such data may be preferred when received within the required timeframe.

[0097] The local software application must ensure the safe operation of the local machine. This is highly dependent on the type of local machine. For a vehicle, this might mean that if the local software application does not support safe operation, it must stop. For a conveyor belt in a factory, continuous operation at a constant speed may still be possible.

[0098] Control data delivered by cloud applications can improve the behavior of local machines. For example, a car traveling along a road can maintain a constant speed along that road without additional control data from the cloud application. If an obstacle is encountered that cannot be avoided, pulling the car over to the side of the road (a safe state) may be necessary. In the cloud, the obstacle may be known, and control data from the cloud application can guide the vehicle to an alternative route without the obstacle.

[0099] In a factory, as long as there is no blockage on the subsequent belt, the conveyor belt operates at a constant speed and must be stopped until the blockage is eased. By utilizing control data from a cloud application, the belt speed can be adjusted in a timely manner, as the cloud application has a better overall understanding of the situation, thus preventing blockages.

[0100] In the following sections, illustrative and non-limiting embodiments are discussed to further illustrate the invention, as shown in the accompanying drawings, wherein:

[0101] Figure 1 The system according to the present invention,

[0102] Figure 2 This is an example of a message stream according to the present invention.

[0103] Figure 3 This is another example of a message flow according to the present invention.

[0104] Figure 4 This is yet another example of a message flow according to the present invention.

[0105] Figure 5 Here are examples of the structures for request messages, response messages, and termination messages;

[0106] Figure 6 and 6a This is an example of generating security control data based on existing technology.

[0107] Figure 7 and 7a This is an example of generating security control data according to the present invention, and

[0108] Figure 8 and 8a This is another example of generating security control data according to the present invention.

[0109] We will now discuss some of the many implementations of the invention. Unless otherwise stated, all details described in connection with specific examples are applicable not only in conjunction with those examples but also to the general scope of protection of the invention.

[0110] like Figure 1 As shown, the local machine L-MACH includes at least one safety device S-DEV, which is connected to one or more sensors SEN1-SEN3, ... and is connected to one or more actuators ACT1-ACT2, ...

[0111] One or more sensors SEN1-SEN3 are monitoring, for example, the local machine and / or its environment and / or physical processes running on the local machine, and providing sensor data to the safety device S-DEV. This sensor data is used to generate control data for controlling and / or monitoring the local machine L-MACH.

[0112] Figure 1 The safety device S-DEV further illustrates that it includes at least one local software application L-APP, which executes on the safety device, specifically on the safety hardware device of the safety device S-DEV. The local software application L-APP is configured to generate so-called "safety control data" based on input data (which is data, specifically all data delivered by sensors, such as raw sensor data or preprocessed sensor data), as described in the introduction of this document. This safety control data is used to control and / or supervise the local machine L-MACH, as the local software application (or the safety device S-DEV) provides safety control data to actuators ACT1-ACT3.

[0113] In addition, at least one cloud application (C-APP) is provided, and the cloud application and security device (S-DEV) as described above form what is called a "system" (SYS). The cloud application (C-APP) is a software application that executes on hardware external to the local machine (L-MACH). Specifically, the cloud application resides "in the cloud," meaning it resides on remote hardware. Typically, the security device and / or the local software application communicate with the cloud application via the Internet.

[0114] Since the local computing resources (e.g., CPU, memory, power, and temperature limits) of the safety device S-DEV are typically limited, especially for performing complex calculations, the local application L-APP is configured to outsource the calculations used to generate control data to at least one cloud application C-APP and use the results of the cloud application's calculations, for example, by including the control data delivered by the cloud application C-APP into the control data it has already calculated, or by using the control data from the cloud application C-APP instead of the control data it generates itself.

[0115] Typically, cloud applications and / or the hardware on which they run are more powerful than native software applications (L-APP) and / or security hardware devices, enabling cloud applications to perform computations faster and / or deliver better results than native software applications.

[0116] Furthermore, cloud applications (C-APPs) can have access to supplemental cloud data (C-DATA), which provides additional information that the cloud application can consider to generate control data for local machine L-MACH. This supplemental cloud data (C-DATA), which is unavailable to local software applications, often helps improve the computational results of the cloud application.

[0117] More specifically, the cloud application C-APP performs the aforementioned calculations to generate control data for controlling and / or monitoring the local machine L-MACH, based on specific input data provided to the cloud application C-APP by the local software application L-APP. The local software application sends a request to the cloud application C-APP, wherein the request includes...

[0118] • Information about which one or more definitions' computations will be performed by at least one cloud application, and

[0119] • The specific input data will be used by the cloud application C-APP to perform one or more defined computations.

[0120] The cloud application C-APP performs the required computations based on the request and, in response to the security device S-DEV and / or the local software application L-APP, sends the results of the computation, i.e., the control data for the computation. The response may include the results of one specific computation or two or more computations. The response may consist of one or more messages, which are specifically transmitted to the security device / local software application via the Internet.

[0121] The local application L-APP will consider this control data and check whether it falls within safety parameters, ensuring the local machine operates safely when the control data is forwarded to the appropriate actuator. In this context, it is specified that if the local software application L-APP and / or the security device S-DEV receive one or more requests for defined computational control data from the cloud application C-APP within a defined time period, the control data will be checked for being within safety parameters, for example, by the local software application L-APP or by the security device S-DEV, such as by checking software executed on the security hardware device of the security device S-DEV. If the control data is within the safety parameters, it is considered safe control data and will be used to control and / or monitor the local machine L-MACH.

[0122] As described, a defined time period can be specified, as detailed above, starting at a defined starting point ts, where only control data from the cloud application arriving at the local application within that defined time period can be considered. The starting point ts can be linked to an event (the sending of a request) as described above, or it can be specified by a schedule, particularly a cyclical schedule.

[0123] Alternatively, instead of a defined time period, a defined time point te can be provided until the cloud application's control data must arrive at the local application's defined time point te (also known as the "arrival time point"), so that they can be taken into account. The arrival time point te can be a fixed time point, it can depend on specific calculations, and / or it can be specified by a schedule, particularly a cyclical schedule.

[0124] If the control data is outside the safety parameter range, the control data will not be considered safety control data and will not be used to control and / or monitor the local machine L-MACH.

[0125] If control data provided by the cloud application C-APP is not received by the local software application L-APP and / or the security device S-DEV within a defined time period or up to a specific defined point in time, it will not be used to control and / or monitor the local machine L-MACH.

[0126] Figure 2 An example of a message flow implementing the method according to the invention is shown. Based on input, i.e., sensor data from one or more sensors SENS1-SENS3, a local application L-APP performs calculations to generate safety control data for one or more actuators ACT1-ACT3. The start of the calculation can be triggered by the receipt of input. Alternatively, the start of the calculation performed by the local application L-APP can be triggered based on a schedule.

[0127] According to the present invention, the local application L-APP sends a request message (1) with the content described above to the cloud application. The request message may include information about the device type of the security device (and / or the local machine) and / or the type of the local software application, so that—in the case of two or more cloud applications—the message can be routed to the correct cloud application C-APP.

[0128] Based on the available input data, the local software app L-APP begins to calculate the safety control data required for actuators ACT1-ACT3 to control and / or monitor the local machine L-MACH.

[0129] The defined time period, within which at least a portion of the expected response from the cloud application C-APP, including at least some control data, begins at a defined point in time, such as the point at which the request is first sent.

[0130] In addition, local software applications must calculate security parameters within a certain range, and cloud applications' control data must also be within this range.

[0131] A cloud application receives a request from a local application and uses the specific inputs included in the request to begin performing one or more of the requested computations.

[0132] Optionally, if present, additional cloud data C-DATA may be included in one or more compute operations of the cloud application.

[0133] In the example shown, the cloud application calculates first control data, such as control data for the first actuator ACT1. This first control data is transmitted to the local application L-APP via response (2), particularly via a partial response, and is received in the local application within a defined time period. The local application checks whether the control data from the cloud application is within the range of security parameters, and if the check is positive, the first control data is identified as secure control data and will be "included" in the secure control data. This means that, instead of or in addition to the secure control data or some of the secure control data calculated by the local application, this first control data will be used, for example, to control the first actuator ACT1.

[0134] according to Figure 2 In the example shown, the cloud application further calculates second control data, which is sent to the local application (3), specifically via a separate partial response. Again, this control data is received within a time period defined in the local application, and accordingly checked to ensure it falls within the safety parameter range. If the check is positive, this second control data is considered safety control data and will also be used to control / monitor the local machine, as the safety control data is transmitted to the relevant actuators, such as actuators ACT2 and ACT3.

[0135] In this example, the response consists of two partial responses (2) and (3).

[0136] Preferably, the local application notifies the cloud application C-APP via a termination message (4), for example, about the successful merging of computational control data for the actuator in this example.

[0137] The actuator's "final" safety control data, namely the safety control data generated by the local application along with the included first and second control data, is transmitted to the actuator by the local application. Regarding the meaning of "includes," referring to the explanation above, this could mean that in one extreme case, the safety control data used for the actuator includes both the safety control data generated by the local application and all control data generated by the cloud application; and in another extreme example, it could mean that all safety control data generated by the local application is replaced by control data generated by the cloud application. Clearly, all possible variations between these extreme positions are possible.

[0138] Figure 3 Another example of a possible message flow is shown. In this case, a configurable / definable time period expires (3) before the second (final) part of the response from the cloud application C-APP is received. The local application will consider the (first) control data of one or more actuators that have been received by the local application in a timely manner (step (2)) and check whether this first control data is within the safety parameter range. The second control data is discarded by the local application.

[0139] The local application L-APP can or will adjust the actuator's safety control data by including (see the definition of "including" above) the first control data of the cloud application, and preferably sends a termination message (4) to the cloud application C-APP. The termination message will notify the cloud application that no further data is needed, preferably including a reason (e.g., timeout) and / or the status of the local application, or the security device, or the local machine.

[0140] The “final” actuator control data is transmitted to the actuator.

[0141] Figure 4 Another example of a message flow is shown. In this case, the local application receives all partial final responses (2) and (3) within the configured / defined time period, but detects that the second control data delivered by the cloud application C-APP is not within the security parameter range.

[0142] Therefore, the second control data will be deemed unsafe control data and will not be used to control / monitor the local machine.

[0143] In this scenario, the local application will only "include" the first control data and send the final actuator control data to the actuator. Preferably, the local application will send a termination message (4) to the cloud application C-APP, where the reason is that the control data, particularly the second control data, has resulted in an unsafe state for the local machine. This may even occur before the local application receives the final message (partial response) from the cloud application.

[0144] Figure 5The possible formats and contents of what could be a request message, response message, or termination message are shown.

[0145] The header of a request message may include a request indicator indicating that the message is a "request," the type of security device, and the type of the local application sending the request. The "L-APP type" indicator may implicitly contain information about which computations will be performed by the cloud application, or the computations CAL1, CAL2, ... may be indicated in separate indicators within the message. Furthermore, the request message contains specific inputs that the cloud application must use to generate control data by performing the requested computations.

[0146] The header of a response message may include a response indicator indicating whether the message is a "response" message, an indicator whether it is a non-final or final message for a specific request, and control data generated by the cloud application, such as control data for actuators ACT1 and ACT3.

[0147] Preferably, the request indicator of the request message, or the request indicator of at least one request message, particularly the request indicator of a first request message for a specific request, includes an identifier that will be included in the response indicator of one or more response messages sent by the cloud application in response to the request message for the specific request.

[0148] The header of a termination message may include an indicator that the message is a "termination" message, the type of security device, and the type of local application that sent the termination message.

[0149] In addition, the termination message can include the reason for the requested termination and the status of the security device.

[0150] Figure 6 This illustration shows a scenario where only the local software application L-APP calculates safety control data for the actuators ACT1-ACT3 on the local machine. Safety control data means that, based on specific safety requirements, the control data is within the safety parameter range and is generated in a timely manner, so that it can (or has been) provided to the actuators in a timely manner to ensure safe operation.

[0151] Based on the local machine-related inputs provided by sensors SEN1-SEN3, in this simple and non-limiting example, the local application performs four different calculations, such as... Figure 6a As shown:

[0152] The first calculation CAL-1 provides safety control data D11, D12, and D13 to the first actuator ACT1. These control data form the first set of safety control data SA1.

[0153] The second calculation, CAL-2, provides safety control data D21, D22, and D33 to the second actuator, ACT2. These control data form the second set of safety control data, SA2.

[0154] The third calculation, CAL-3, provides safety control data D31, D32, and D33 to the third actuator, ACT3. These control data form the third set of safety control data, SA3.

[0155] Sets SA1, SA2, and SA3 are provided for "normal" safe operation of the local machine (e.g., vehicle driving, etc.). In this context, "normal" operation refers to the specified and expected operation of the machine in its actual state.

[0156] Alternatively, or as shown in this example, the local software application L-APP executes:

[0157] The fourth calculation, CAL-S, generates safety control data DSF1, DSF2, and DSF3. If a specific environment obviates the local machine L-MACH from operating in normal safe mode, these safety control data (in this case forming the fourth set of SSFs) are provided to put the local machine into a safe state. In this case, the local software application L-APP transmits the set of SSFs, instead of one, several, or all of the first, second, and third sets, to the actuator.

[0158] Figure 6 , 6a It describes a scenario where only the local software application generates control data for the actuators of the local machine.

[0159] Now, Figure 7 The illustration depicts a scenario where a native software application L-APP communicates with a cloud application C-APP according to the present invention. In the example shown, the native application sends a request REQ to the cloud application C-APP. The request REQ contains the computation requested to be performed by the cloud application C-APP and a specific input S-INPUT, based on which the cloud application must use to perform the computation.

[0160] In this example, the request REQ = REQ(CAL-1, CAL-S; S-INPUT) requests the cloud application to perform the first and fourth calculations CAL-1 and CAL-S to generate control data for the first actuator ACT1 and control data for putting the local machine into a safe state.

[0161] The specific input S-INPUT can be the same as the complete input used by the local software application L-APP, or it can include only data related to the requested calculations and / or the data used to put the local machine into a safe state, particularly sensor data.

[0162] Based on the request REQ, the cloud application C-APP performs the first and fourth calculations, CAL-1 and CAL-S. In addition to the specific input S-INPUT provided by the request REQ, the cloud application C-APP may also consider cloud data C-DATA, if such cloud data is available.

[0163] The cloud application (C-APP) sends the computation result as a response (RES) to the local application (L-APP). The response (RES) can consist of a single message or can be transmitted along with two or more messages.

[0164] The response RES contains a set of control data SA1-C for the first actuator ACT1 and control data SSF-C for the safety state.

[0165] Assuming that the control data provided by the cloud application C-APP arrives in a timely manner and is within the safety parameter range, the local software application will use this—now safe—control data from the cloud application to control and / or supervise the local machine, in order to provide the safety control data (in this case, the control data for the first actuator ACT1) instead of (as shown) or except (not shown) the corresponding safety control data of the local application L-APP to actuator ACT1.

[0166] In this simple, non-restrictive example, such as Figure 7 As shown, the response RES includes a set SA1-C of control data D11-C, D12-C, and D13-C for the first actuator ACT1 and a set SSF-C of control data DSF1-C, DSF2-C, and DSF3-C for the safety state.

[0167] In the example shown, according to Figure 7a The local application L-APP replaces its already computed security control data with control data delivered by the cloud application (which is classified as security control data), resulting in the following set of security control data:

[0168] SA1 → SA1' = {D11-C, D12-C, D13-C}

[0169] SA2 → SA2' = SA2 = {D21, D22, D23}

[0170] SA3 → SA3' = SA3 = {D31, D32, D33}

[0171] SSF → SSF' = {DSF1-C, DSF2-C, DSF3-C}

[0172] In this example, the set of control data for the first actuator ACT1 is the same as the set SA1-C provided by the cloud application, and the set of data for the safety state SSF' is the same as the set SSF-C provided by the cloud application.

[0173] The set used for the second and third actuators is still the set computed by the local application L-APP, because the cloud application C-APP has not yet been requested to perform the second and third computations.

[0174] Figure 8 and 8a Another example is shown. This example is related to... Figure 7 and Figure 7a The difference in the examples shown is that, according to Figure 8 The request REQ includes further calculations, namely a second calculation CAL-2, and the set of control data calculated by the cloud application C-APP for the first actuator ACT1 only includes control data D11-C and D13-C, excluding control data D12-C. Control data D12-C may not have been calculated by CAL1 on the cloud application, may have arrived at the local application too late, or may have been deemed insecure. In this example, it is assumed that the control data D12-C has not yet been calculated in the cloud application, so that it is not included in the response RES; however, the result is the same if it has not been calculated or received too late, etc.

[0175] The computation CAL-2 performed in the cloud application only delivers control data D22-C for the second actuator ACT2.

[0176] In this example, the resulting SA1' includes security control data D11-C and D13-C computed by the cloud application, but since control data D12-C is missing, control data D12 computed by the first compute CAL1 on the local application is used:

[0177] SA1' = {D11-C, D12, D13-C}

[0178] The second set SA2' of safety control data for the second actuator ACT2 includes locally computed safety control data D21 and D23. In this example, the locally computed safety control data D22 is not replaced, but rather "appended" to the safety control data D22-C computed by the cloud application C-APP. It will be apparent to those skilled in the art that, in this case, the safety control data is not simply added together, but rather combined in a manner tailored to the specific application:

[0179] SA2' = {D21, D22 + D22-C, D23}

[0180] Sets SA3' and SSF' and from according to Figure 7 The set of examples in / 7a is the same.

Claims

1. A method for generating security control data to control a local machine (L-MACH), wherein the local machine (L-MACH) is... A security device (S-DEV) is assigned to the local machine (L-MACH), and the security device (S-DEV) includes security hardware devices that are provided with input data related to the local machine (L-MACH). The security device (S-DEV) includes a local software application (L-APP) running on the security hardware of the security device (S-DEV). This local software application is a security software application that performs calculations based on the input data to generate the security control data. This security control data is control data that conforms to the security requirements of the local machine (L-MACH), allowing the local machine (L-MACH) to operate according to its security requirements. And among them Provide at least one software application in the cloud, namely a cloud application (C-APP), wherein the at least one cloud application (C-APP) is a software application that executes on hardware external to the security device (S-DEV), wherein The at least one cloud application (C-APP) is configured to perform calculations based on input data provided by the local software application (L-APP) to the at least one cloud application (C-APP) to generate control data for controlling the local machine (L-MACH), wherein A local software application (L-APP) sends a request to at least one cloud application (C-APP), wherein the request includes Information about which one or more definitions' computations will be performed by at least one cloud application, and The input data will be used by at least one cloud application (C-APP) to perform one or more defined computations. And among them If a local software application (L-APP) or a security device (S-DEV) receives one or more requested control data for defined computations from at least one cloud application (C-APP) within a defined time period or before a defined time point, then the local software application (L-APP) or the security device (S-DEV) checks whether the control data is within the range of security parameters. In addition to, or in lieu of, security control data generated by calculations performed by the local software application (L-APP), if the control data is within the security parameter range, then the control data is considered secure control data and will be used to control the local machine (L-MACH). If the control data is outside the security parameter range, it will not be considered secure control data and will not be used to control the local machine (L-MACH). Only secure control data generated through calculations performed by the local software application (L-APP) will be used to control the local machine. Control data provided by at least one cloud application (C-APP) that is not received by the local software application (L-APP) or security device (S-DEV) within the defined time period or before the defined time point will not be used to control the local machine (L-MACH), and only security control data generated by calculations performed by the local software application (L-APP) will be used to control the local machine.

2. The method of claim 1, wherein, For each defined calculation, provide a defined time period or a defined time point, or provide only a defined time period for all calculations.

3. The method of claim 1 or 2, wherein, The range of security parameters is calculated by the local software application (L-APP).

4. The method of claim 1 or 2, wherein, If the calculation result is within the range of security parameters, the local software application (L-APP) or the security device (S-DEV) checks the calculation for the definition of each request, respectively.

5. The method according to claim 1 or 2, wherein, The at least one cloud application (C-APP) is configured to perform at least some computations that can be performed by a local application (L-APP).

6. The method according to claim 1 or 2, wherein The control data generated by computations performed by a local software application (L-APP) or all control data provided by computations from at least one cloud application, instead of the results of computations performed by the local software application, is identified as security control data, and / or In addition to some or all of the results of calculations performed by a local software application (L-APP), the control data is identified as security control data, which is generated by calculations performed by a local software application (L-APP) or provided by calculations performed by at least one cloud application.

7. The method according to claim 1 or 2, wherein, Input data related to the local machine or input data includes Sensor data from one or more sensors monitoring the surrounding environment of the local machine; and / or Sensor data from one or more sensors monitoring the local machine and / or processes running on the local machine; and / or Data describing the state of the local machine. The input data is the same as the input data associated with the local machine, or includes all the input data associated with the local machine, or the input data is a proper subset of the input data associated with the local machine.

8. The method according to claim 1 or 2, wherein, The input data includes information about the security device (S-DEV) or the local software application (L-APP).

9. The method according to claim 8, wherein, Provide two or more cloud applications configured to perform different computations, wherein request messages are routed to defined cloud applications based on input data contained in the request message.

10. The method of claim 1 or 2, wherein the cloud application (C-APP) is a software application that is connected to a local software application (L-APP) via the Internet.

11. The method according to claim 1 or 2, wherein, In response to a request message from the local software application (L-APP), the cloud application (C-APP) sends a response to the local software application (L-APP), wherein the response includes control data for the computation defined by the local software application (L-APP).

12. The method according to claim 1 or 2, wherein, Control data received via partial responses from the cloud application (C-APP), if deemed secure control data, will be used by the local software application (L-APP) or security device (S-DEV) to control or monitor the local machine (L-MACH).

13. The method according to claim 1 or 2, wherein, No further computation is required by terminating the message notification cloud application (C-APP).

14. The method according to claim 1 or 2, wherein, The cloud application (C-APP) incorporates additional inputs into one or more of its computations, wherein the additional inputs are available to the cloud application but not to the local software application.

15. The method according to claim 1 or 2, wherein the external hardware of the cloud application (C-APP) is insecure hardware and / or the cloud application is insecure software application, and / or wherein the external hardware on which at least one cloud application is executed is more powerful than a secure hardware device, and / or at least one cloud application is more powerful than a local software application.

16. The method of claim 1, wherein the local machine (L-MACH) is a technical device.

17. The method of claim 16, wherein the technical device is a vehicle.

18. The method of claim 17, wherein the vehicle is an automobile.

19. The method of claim 1, wherein the local software application (L-APP) sends a request to at least one cloud application (C-APP) in one or more request messages.

20. The method of claim 1, wherein the local software application (L-APP) is inspection software executed on a security hardware device of a security device (S-DEV).

21. The method according to claim 1, wherein the at least one cloud application (C-APP) is a software application executed on hardware external to the local machine (L-MACH).

22. The method according to claim 3, wherein, The range of security parameters is calculated by the local software application (L-APP) based on input data associated with the local machine (L-MACH).

23. The method according to claim 5, wherein, The at least one cloud application (C-APP) is configured to perform all computations that can be performed by a local application (L-APP).

24. The method of claim 6, wherein the result of the calculation performed by the local software application is the result of a corresponding calculation performed on the local software application (L-APP).

25. The method of claim 7, wherein the one or more sensors are cameras, radar, or lidar.

26. The method of claim 7, wherein the data describing the state of the local machine is data provided by one or more actuators of the local machine, a subsystem of the local machine, or configuration data of the local machine.

27. The method of claim 8, wherein the information about the local software application (L-APP) is information about the type of the local application.

28. The method according to claim 11, wherein, The cloud application (C-APP) sends a response to the local software application (L-APP) in the form of one or more response messages.

29. The method according to claim 11, wherein, Response messages from a cloud application (C-APP) contain information indicating whether this is the final message from the cloud application (C-APP) or whether the cloud application intends to send one or more additional response messages.

30. The method according to claim 13, wherein, The termination message is sent by the requesting local software application (L-APP).

31. The method according to claim 30, wherein, The termination message includes information about the reason for the termination.

32. The method according to claim 31, wherein, The information regarding the reason for termination is that the defined time period has been exceeded and / or the received calculation result is not within the range of security parameters, and / or includes the actual state implemented by the local machine (L-MACH).

33. The method according to claim 14, wherein, The additional input is additional input data (C-DATA).

34. A system (SYS) for performing the method according to any one of claims 1-33 to generate security control data to control a local machine (L-MACH), said local machine (L-MACH), wherein said system includes a security device (S-DEV) assigned to the local machine (L-MACH), said security device including security hardware devices, said security device (S-DEV) being provided with input data associated with the local machine (L-MACH), and The security device (S-DEV) includes a local software application (L-APP) executed on the security hardware device of the security device (S-DEV), wherein, The local software application is a security software application (L-APP) configured to perform calculations based on the input data to generate the security control data. This security control data conforms to the security requirements of the local machine (L-MACH) and allows the local machine (L-MACH) to operate according to its security requirements. in The system (SYS) further includes: at least one software application, namely a cloud application (C-APP), located outside the security device (S-DEV) and in the cloud, the at least one cloud application (C-APP) being a software application executing on the external hardware, wherein the cloud application (C-APP) is configured to perform calculations based on input data provided by a local software application (L-APP) to the cloud application (C-APP) to generate control data for controlling a local machine (L-MACH), and wherein the local software application (L-APP) is configured to send a request to the at least one cloud application (C-APP), wherein the request includes Information about which one or more definitions' computations will be performed by at least one cloud application, and The input data will be used by the cloud application (C-APP) to perform one or more defined computations. Furthermore, the local software application (L-APP) or security device (S-DEV) is configured to receive control data defined by one or more requests for the following: If the local software application (L-APP) or the security device (S-DEV) receives one or more requested control data sets for defined computations from the cloud application (C-APP) within a defined time period or before a defined time point, then the local software application (L-APP) or the security device (S-DEV) checks whether the control data is within the range of security parameters. In addition to security control data generated through calculations performed by the local software application (L-APP), or instead of security control data, if the control data is within the security parameter range, then the control data is considered security control data and will be used to control the local machine (L-MACH). If the control data is outside the security parameter range, it will not be considered secure control data and will not be used to control the local machine (L-MACH). Only secure control data generated through calculations performed by the local software application (L-APP) will be used to control the local machine. Control data provided by the cloud application (C-APP) that is not received by the local software application (L-APP) or the security device (S-DEV) within a defined time period or before the defined time point will not be used to control the local machine (L-MACH), and only secure control data generated by computations performed by the local software application (L-APP) will be used to control the local machine, wherein the external hardware used for the cloud application (C-APP) is not secure hardware and / or the cloud application is not secure software application, and / or the external hardware on which at least one cloud application is executed is more powerful than the secure hardware device, and / or at least one cloud application is more powerful than the local software application.

35. The system (SYS) of claim 34, wherein the local machine (L-MACH) is a technical device.

36. The system (SYS) of claim 35, wherein the technical device is a vehicle.

37. The system (SYS) of claim 36, wherein the vehicle is an automobile.

38. The system (SYS) of claim 34, wherein the local software application (L-APP) sends a request to at least one cloud application (C-APP) in one or more request messages.

39. The system (SYS) of claim 34, wherein the local software application (L-APP) is inspection software executed on a security hardware device of a security device (S-DEV).

40. The system (SYS) of claim 34, wherein the at least one cloud application (C-APP) is a software application executed on hardware external to the local machine (L-MACH).

Citation Information

Patent Citations

  • Server, method, and computer-readable storage medium for automated parking

    US20190371175A1