Method for providing computer-implemented functionality in computing system

By introducing security modules and access management into the vehicle computing system, using authorization key signature and management function requests, the complexity and security issues of key management in the vehicle computing system are solved, and secure access and management of multi-functions are achieved.

CN120200754APending Publication Date: 2025-06-24ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411889061.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-12-20
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When the prior art manages and implements different functions in a vehicle computing system, it is difficult to effectively manage and store a large number of authorization keys, resulting in complex management and difficult to ensure security.

Method used

By introducing a security module into the computing system, the provision request is signed using an authorization key stored by the security module, and through the coordinated work of access management and repository, the encryption and decryption of the functional container is achieved, ensuring that only authorized keys can access and implement specific functions.

Benefits of technology

This method allows secure access and implementation of a large number of functions that require authorization in the computing system, reducing the complexity of key management and improving the overall security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200754A_ABST
    Figure CN120200754A_ABST
Patent Text Reader

Abstract

The invention relates to a method for providing a computer-implemented function in a computing system having at least one computing unit and a security module, comprising: signing, by the security module, a provision request specifying the requested function using an authorization key stored by the security module; sending the signed provision request to an access manager; checking, by the access management, the authenticity of the signed provision request; if the check is successful, sending, by the access management, an access key for the requested function to the computing system; sending a container request for the requested function to a repository, the repository storing a function container having the requested function; and if the validity of the access key is confirmed, implementing, by the at least one computing unit, the function in the computing system using the function container.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for providing computer-implemented functions in a computing system, a method executed in a computing system, a computing unit for executing the method, and a computer program. Background Art

[0002] Functions implemented in a vehicle can be defined by software, where a control device executes a computer program to implement a specific function. Here, the parameters of the computer program can be varied to change the scope of the function. For example, in the engine control program of an engine of the same vehicle, different power levels can be parameterized. Similarly, for the same vehicle, different functions can be implemented by different computer programs. For example, depending on whether the corresponding computer program has been installed / enabled, an autonomous driving function such as automatic parking can be implemented or not while other aspects of the vehicle remain unchanged. These differences in the provided functions may also depend on the respective users of the vehicle. Summary of the Invention

[0003] According to the present invention, there are provided a method for providing computer-implemented functions in a computing system and a method executed in a computing system, a computing unit for executing the method, and a computer program having the features of the independent claims. Advantageous designs are the subject matter of the dependent claims and the following description.

[0004] The present invention takes the following measures. In a method for providing computer-implemented functions in a computing system having at least one computing unit and a security module, the security module uses an authorization key stored by the security module to sign a request for providing the requested function and sends it to the access management. After successfully checking the authenticity of the signed request for providing, the access management sends an access key for the requested function to the computing system. In addition, a container request for the requested function is sent to a repository storing a function container with the requested function, and when the validity of the access key is confirmed or upon confirmation of the validity of the access key, the function is implemented in the computing system using the function container.

[0005] With the present invention, it is possible to access a large number of different functions that require authorization, where only a single authorization key or a relatively small number of authorization keys (e.g., specific to a particular user of a vehicle) are stored by the security module. It is not necessary to store a large number of keys according to the number of different functions.

[0006] The method is executed in a system having a computing system, an access management, and a repository.

[0007] The term "cryptographic key" or simply "key" shall refer to a string used in a cryptographic method. These strings shall be random enough so that they can only be determined by guessing or brute-force attack (in an unknown situation).

[0008] According to a design, the container request contains an access key, and the method includes: to confirm the validity of the access key, checking the validity of the access key through a repository; and if the check of validity is successful, the repository transfers the functional container to the computing system. This is appropriate because the access key is confirmed by a system independent of the computing system.

[0009] According to a design in which the functional container is cryptographically protected, especially encrypted, in the repository so that the function cannot be realized without knowing the access key, the method includes: to confirm the validity of the access key, transferring the protected functional container to the computing system by the repository in response to the container request, and decrypting, especially decrypting, the functional container by the computing system using the access key. In this design, the container request and the transfer of the functional container can be carried out before providing the request (i.e., before signing and / or sending the providing request).

[0010] According to a design, the access key is sent to the computing system as an encrypted access key through access management. This encryption of the access key can exist in addition to the encryption of the message sending the access key to the computing system. This especially realizes a design in which the (unencrypted) access key is only known in the security module.

[0011] According to a design, the encrypted access key is decrypted by the security module and staged by the security module when necessary, without being transferred to the computing unit or other modules of the computing system, and the access key is inserted into the container request by the security module, where the container request is encrypted by the security module after insertion. According to this design, a container request can be generated without the requested and possibly stolen computing unit obtaining access to the access key.

[0012] According to a design, the encrypted access key is decrypted by the security module and staged by the security module when necessary, without being transferred to the computing unit or other modules of the computing system, where the cryptographic protection of the functional container is lifted by the security module. Here, leakage of the (unencrypted) access key outside the security module in the computing system can also be avoided.

[0013] According to a design, the computing system has a communication module through which it communicates with an access management and a repository. The communication with the access management and the repository includes: sending a signed provision request, receiving an access key during the sending of the access key to the computing system, sending a container request to the repository, and receiving a functional container from the repository if necessary. The communication module is the central unit in the computing system through which messages are exchanged with external systems. The communication module can be configured to exchange data only with at least one computing unit within the computing system. This enables the use of a security module that meets very high security requirements, such as a hardware security module. Alternatively, it can also be provided that the communication module is configured to exchange data with at least one computing unit and with a security module within the computing system. This simplifies the data exchange in the computing system, such that in particular less computing power and / or less data bandwidth of the bus for data exchange is required.

[0014] According to a design, the sending of the provision request and / or the sending of the access key and / or the sending of the container request and / or the transfer of the functional container if necessary is carried out in a password-protected form, where the respective messages are encrypted and / or signed. This can in particular confirm the authenticity and integrity of the messages and prevent an attacker from gaining access to the transmitted data, such as learning the access key or finding out about the requested function.

[0015] According to a design, the encryption and / or signing and / or decryption and / or signature check of the messages is carried out by a security module in the computing system, where the cryptographic keys used in this process are stored by the security module. The use of a security module is appropriate because it is typically especially protected against attacks. The security module can store the keys, for example, in an internal memory and / or a security-module-specific memory and / or in a separate storage area of an external memory that is only accessible by an access module.

[0016] According to a design, the provision request and / or the container request is generated by at least one computing unit of the computing system, in particular by the computing unit that is to implement the requested function. Thus, the process is controlled by this computing unit.

[0017] According to a design, the functional container contains program modules and / or program parameters. The program modules (or computer program modules) can be executed by a computing unit to implement the function. The program parameters can be used to change the function of the installed program modules.

[0018] The method according to the invention, which is executed in a computing system having at least one computing unit and a security module, comprises: signing, by the security module, a provision request specifying the requested function using an authorization key stored by the security module; sending the signed provision request to access management; receiving, from the access management, an access key for the requested function; sending a container request for the requested function to a repository that stores function containers having the requested function. Here, the container request contains the access key, and the method comprises: receiving the function container from the repository and implementing the function by the at least one computing unit using the function container; or receiving the function container as a password-protected function container from the repository, and the method comprises: decrypting the password protection of the function container using the access key and implementing the function by the at least one computing unit using the function container.

[0019] The method executed in a computing system having at least one computing unit and a security module may further comprise the method steps mentioned in this application with respect to a system comprising a computing system, access management, and a repository, provided that these method steps are executed by the computing system.

[0020] A computing unit according to the invention, such as a control device of a motor vehicle, is in particular configured in programming technology to execute the method according to the invention.

[0021] It is also advantageous to implement the method according to the invention in the form of a computer program or a computer program product having program code for executing all the method steps, since this results in particularly low costs, especially if the control device used for execution is also used for other tasks and thus exists anyway. Finally, a machine-readable storage medium is provided, having stored thereon the computer program as described above. Storage media or data carriers suitable for providing the computer program are in particular magnetic, optical, and electrical memories, such as hard disks, flash memories, EEPROMs, DVDs, etc. The program can also be downloaded via a computer network (Internet, intranet, etc.). Such a download can be carried out here either wired or wirelessly (e.g., via a WLAN network, 3G connection, 4G connection, 5G connection, or 6G connection, etc.). Description of the Drawings

[0022] Further advantages and refinements of the invention result from the description and the drawings.

[0023] The invention is schematically illustrated in the embodiments in the drawings and is described below with reference to the drawings.

[0024] Figure 1 The structure of a system in which the method according to the invention can be implemented is shown by way of example.

[0025] Figure 2A flowchart of a method according to an embodiment of the present invention is shown.

[0026] Figure 3 A flowchart according to a general embodiment of the present invention is shown. Detailed implementation manners

[0027] Figure 1 Exemplarily, the structure of a system that can implement the method according to the present invention is shown.

[0028] Computing system 2 is shown herein, especially in vehicle 3. The computing system includes a plurality of computing units or computing modules. Computing unit 4 (or control device) is specifically shown. The computing unit implements specific functions of vehicle 3 by executing a computer program, and the computer program exists in the form of, for example, a computer program module or a computer program container. Three computing units are shown exemplarily. Generally, any number of computing units can be provided. In this application, the terms "program module" and "program container" are also used for the terms "computer program module" or "computer program container".

[0029] In addition, a security module is shown. Among them, hardware security module 6 and a protected area 8 (English: "secure enclave") in the computing unit are shown exemplarily, such as based on TPM (Trusted Platform Module, trusted platform module), etc. The security module provides security-related functions in the computer system and is used herein as a trust anchor, that is, the cryptographic functions provided by the security module and / or the (cryptographic) keys stored by the security module, etc. are regarded as trustworthy or protected against tampering. For the method according to the present invention, at least one security module is provided. In addition to the function as a trust anchor, the security module can also be configured to execute the provided cryptographic functions at high speed, for example, in such a way that the security module is implemented by a hardware circuit.

[0030] A (central) communication module 10 is also provided, which is configured to implement data communication between vehicle 3 or computing system 2 and a computer or system outside the (vehicle), for example, by means of a radio connection or a mobile radio connection (such as by means of WiFi or by means of a 3G connection, 4G connection, 5G connection or 6G connection).

[0031] A load distribution module 12 can be provided, which is configured to distribute the computing load (especially execute specific program modules) among the computing units 4 according to the load of each computing unit.

[0032] The computing units 4, security modules 6, 8, communication module 10 and, if necessary, load distribution module 12 are in Figure 1is exemplarily shown as a separate unit or module. Generally speaking, the computing unit and / or computing module or the functions provided by them can be at least partially jointly provided in one computing unit. In particular, the security module (hardware security module 6, protected area 8) can be provided or implemented in one of the computing units 4. Similarly (and independently of the security module), the communication module 10 can be provided or implemented in one of the computing units 4. If necessary, the load distribution module 12 can be provided or implemented in one of the computing units 4 (independently of the security module and the communication module).

[0033] Figure 1 The system also has access management 14 (or rights management) and a repository 16 for the function containers 18. Both are remote from the vehicle and its computing system or are provided outside the vehicle and its computing system. The access management 14 is provided in a computer and / or computer system, such as a server and / or server system. Similarly, the repository 16 (independently of the access management) is provided in a computer and / or computer system, such as a server and / or server system. These computers and / or computer systems are connected to a data communication system (such as the Internet) and are configured to exchange data with the vehicle or the communication module 12 via the data communication system. Therefore, data communication is possible both between the vehicle or the communication module 12 and the access management 14 and between the vehicle or the communication module 12 and the repository 16.

[0034] The access management 14 stores authorization information. Based on the authorization information, it can be determined which functions can or are allowed to be provided by the computing system. The authorization information includes one or more cryptographic keys (or key information) for this purpose, which are called confirmation keys. Each of the said confirmation keys can be used to check the authenticity of the provision request during the process of the cryptographic method. The provision request is sent by the computing system (such as as shown in the figure) to the access management and received by the access management. Each provision request particularly contains a description of at least one requested function that should be provided in the corresponding computing system. In the authorization information, each confirmation key is associated with one or more functions, where if the authenticity of the provision request is confirmed during the check using the confirmation key, the sender of the provision request (i.e., the computing system that sends the provision request to the access management) has the right to use or implement one or more functions. As a cryptographic method for checking the authenticity of the provision request, an asymmetric cryptographic method can be used, where the provision request is signed with a cryptographic key called the authorization key (by the sender of the provision request) and checked using the confirmation key (by the access management), where the cryptographic key and the confirmation key form a key pair.

[0035] If the authenticity of the provision request is confirmed when checking with the confirmation key, and at least one of the requested functions included in the provision request is included in one or more functions associated with the confirmation key, access management 14 determines that the sender is authorized to implement at least one of the requested functions. In this case, access management 14 sends a message with an access key (access code or token) to the sender (computing system) of the provision request. Sending the access key is especially in encrypted form. The access key can be specific to the sender of the provision request, for example derived from a general access key that contains information included in the provision request.

[0036] If at least one of the requested functions included in the provision request is not included in one or more functions, and / or if the authenticity of the provision request is not confirmed when checking with the confirmation key, access management 14 may determine that the sender is not authorized to implement at least one of the requested functions. In this case, access management 14 may be configured not to send a message to the sender (computing system) of the provision request, or to send a message with an explanation that the provision request has failed.

[0037] The repository 16 stores functional data or functional containers 18 of multiple computer-implemented functions. Functional containers generally contain data that enables a computing system or its computing unit to provide (at least one) function. The functional container 18 can exist, for example, in the form of an executable program module and / or in the form of program parameters. The program module can be installed and executed in a computing unit, for example, to provide the corresponding function. The installed program module can be parameterized using program parameters and, for example, affect its execution, such that in principle different functions are provided according to different parameterizations. The functional containers 18 are each associated with an access key.

[0038] The repository 16 is configured to receive messages, each containing at least one access key and optionally specifying at least one requested functional container, which are called container requests, and to transmit at least one functional container 18 associated with at least one access key or, after checking whether at least one access key is valid for at least one requested functional container (for example, associated with this functional container), transmit at least one functional container 18 to the sender of the container request. The container requests are especially encrypted.

[0039] According to an alternative or additional design, it can be stipulated that the repository 16 is configured to respond to a message (also referred to as a container request) in which at least one functional container 18 is requested, and transmit at least one requested functional container 18 to the sender of the container request, where the container request does not contain an access key and / or the access key is not checked. In this design, the functional container 18 is protected cryptographically, that is, the recipient of the functional container does not initially implement the functions provided in the functional container. Only by knowing the access key corresponding to the functional container can the functions provided by the functional container be implemented. For example, the functional container can be encrypted, and the access key can be used for decryption.

[0040] These two methods can be regarded as steps for confirming the validity of the access key. In any case, the functions can only be used or implemented when the validity of the access key is confirmed. In the first method of the above-mentioned methods, the confirmation is directly carried out by the repository. In the second method, the confirmation is carried out indirectly on the side of the recipient (computing system or computing unit) of the (cryptographically protected) functional container.

[0041] Figure 2 A flowchart of a method according to an embodiment of the present invention is shown. This embodiment is a design of the first method among the above-mentioned methods. It is a system corresponding to the system shown in Figure 1 in which the computing unit 4, a security module in the form of a hardware security module 6, a communication module 10, an access management 14, and a repository 16 are shown in columns. As described in connection with Figure 1 the computing unit 4, the hardware security module 6, and the communication module 10 are included in the computing system 2 (especially the computing system of a vehicle). Instead of the hardware security module 6, other security modules can also be used, such as a protected area 8. The steps of the method are indicated by arrows.

[0042] The method shown should provide the desired computer-implemented functions through the computing unit 4 in the computing system 2 or the vehicle.

[0043] In step 110, the computing unit 4 first creates a request for providing the desired function and sends a request to sign the providing request to the hardware security module 6. The hardware security module 6 signs the providing request with the authorization key stored by the hardware security module 6 and transmits the signed providing request to the computing unit 4 in step 120 (or informs the computing unit where the signed providing request is stored, or that the signature exists, for example, if a corresponding predetermined storage area is set).

[0044] The computing unit 2 transmits the signed provision request to the access management 14. Herein, in step 130, the computing unit 2 first transmits the signed provision request to the communication module 10, or the computing unit 2 informs the communication module 10 via the description storage area that the signed provision request should be transmitted to the access management 14. The communication module 10 transmits the signed provision request to the access management 14 in step 140.

[0045] In step 150, the access management 14 checks the authenticity of the received (signed) provision request, wherein, as described in connection with Figure 1 a confirmation key is used. If the authenticity is confirmed during the check (and thereby it is confirmed that the computing system is authorized to implement the function) (valid signature), the access management 14 transmits the corresponding access key in an encrypted and especially signed form to the communication module 10 of the computing system 2 in step 160.

[0046] In step 170, the encrypted and optionally signed access key is transmitted by the communication module 10 to the computing unit 4, and the computing unit transmits the access key to the hardware security module 6 in step 180. In step 190, the hardware security module 6 decrypts the encrypted access key, wherein the signature of the access key is optionally checked.

[0047] In step 200, the HSM 6 encrypts the (decrypted) access key and optionally signs the encrypted access key. This encryption is performed, for example, using a symmetric encryption method, using a key known especially only to the HSM 6 and the computing unit of the computing system, so that an attacker who eavesdrops on the data stream in the computing system cannot obtain the key. Further, a key known only to the requested computing unit 4 (and the HSM) can be used, so that other computing units in the computing system cannot obtain the key.

[0048] The access key encrypted and optionally signed by the HSM 6 is transmitted to the computing unit 4 in step 210. Similarly, the HSM 6 stores the (decrypted) access key (for further use in step 240). The computing unit 4 verifies the encrypted and optionally signed access key, wherein especially the digital signature of the key is verified (the digital signature is optionally generated by the HSM).

[0049] In the case of successful verification, the computing unit 4 transmits a message to the HSM 6 in step 230, with a description (or path description) of the storage location of the requested function container and the specification of the requested function container, which function container contains the computer-implemented function to be provided by the vehicle or the computing unit 4 in the computing system. This description is especially a uniform resource locator (URL). This transmission can be password-protected, i.e., the message with the description can be signed and optionally encrypted by the computing unit.

[0050] The HSM 6 can verify a message with the storage location and the specified description of the requested function container (i.e., check its signature) and decrypt it if necessary. In step 240, the HSM 6 supplements the message with the storage location and the specified description of the requested function container with an encrypted version of the access key (the access key was staged in the HSM in step 210) to obtain a container request. The encryption to obtain the encrypted version of the access key is performed in such a way that only the repository 16 can decrypt this version. For example, it is performed by means of an asymmetric encryption method, where the public key is used for encryption.

[0051] In step 250, the HSM 6 transmits the message supplemented with the encrypted version of the access key (container request) to the computing unit 4, which transmits this message to the communication module 10 in step 260. These transmissions can again be protected by means of signatures. The communication module transmits the message, or at least the specification of the requested function container and the encrypted version of the access key, if necessary after (successfully) verifying the signature, as a container request to the storage location specified in the message, i.e., the repository 16.

[0052] The repository 16 decrypts the encrypted version of the access key, for example, using the private key of the asymmetric encryption method mentioned in step 240, checks whether the access key is valid for the requested function container (i.e., is associated with this function container), and, after a successful check, transmits the function container to the computing system 2, i.e., its communication module 10, in step 280. This transmission is performed in a signed manner and optionally in an encrypted manner.

[0053] The communication module 10 transmits the signed and, if necessary, encrypted function container to the computing unit 2 in step 290, which in turn transmits this function container to the HSM 6 in step 300. The HSM 6 checks the signature of the function container and decrypts it if necessary. In the case of a successful check, the function container is transmitted by the HSM 6 to the computing unit 4 in step 310 (optionally again protected by signature and / or encryption).

[0054] In step 320 (if necessary after checking the signature and / or decryption), the computing unit 4 implements the function provided in the function container. Thus, if the function container contains a program module, the program module is stored in an appropriate memory and the computing unit starts executing the program module. If the function container contains program parameters, at least one program module already present in the computing unit is modified with these program parameters and executed with these program parameters.

[0055] At Figure 2In the design solution, based on the hardware security module 6, its functions are basically limited to providing predetermined cryptographic functions (such as decryption, encryption, signature, signature verification) for the computing unit 4. For example, these functions are provided in such a way that the computing unit in need of the function transfers the data to which the function should be applied to the hardware security module 6 and calls the hardware security module 6 to apply the function to the data. Transferring the data to the hardware security module 6 can be carried out, for example, by the computing unit writing the data to which the function should be applied into a pre-given storage area of the hardware security module 6, or writing the storage address indicating where the data to which the function should be applied is stored into a pre-given address register (or the like) of the hardware security module 6. The cryptographic key (or the like) used by the cryptographic function is stored by the hardware security module 6 and is especially unknown to the computing unit. If multiple keys are stored by the hardware security module, the call by the computing unit to the hardware security module to apply the function can include an indication of which key to use. For this purpose, the keys are named in an appropriate way, such as numbered.

[0056] Since the functions of such a hardware security module 6 are limited to providing cryptographic functions, this hardware security module cannot communicate with the communication module 10 in particular, or the communication module cannot access the hardware security module. Therefore, the data to be transferred to other systems or received from other systems cannot be directly transferred to or obtained from the communication module. Thus, the shown structure is obtained, in which the HSM 6 applies its cryptographic function and the data to be transferred to an external system is not directly transferred from the HSM to the communication module 10, but is first transferred back to the computing unit and then transferred by this computing unit to the communication module, which communicates with the external system (such as steps 120 and 130 or steps 250 and 260). Similarly, the data received from an external system through the communication module and for which the HSM should apply an encryption function is not directly transferred to the HSM, but is first transferred to the computing unit and then transferred by this computing unit to the HSM (such as steps 170 and 180 or steps 290 and 300).

[0057] In other design solutions, the security module can have a wider range of functions, where the security module can transfer data to or receive data from the communication module. In other words, the communication or access between the communication module and the security module can be carried out in the same or at least a similar manner as between the computing unit and the security module (e.g., limited to a subset). In such a design solution, the intermediate step of communicating data between the security module and the computing module via the computing unit can be omitted (e.g., after step 110, the data, i.e., the signed provision request, is transferred from the security module to the communication module, replacing steps 120 and 130). In this case, it is also conceivable that the computing unit, the communication module, and the security module work together, where, for example, the communication module transfers data to the security module, and the computing unit prompts the application of cryptographic functions.

[0058] Figure 3 A flowchart according to an embodiment of the present invention is shown, where most mentions of the individual elements of the computing system performing specific steps are omitted. The method involves providing a computer-implemented requested function in a vehicle having a computing system with at least one computing unit and a security module.

[0059] In step 410, the security module signs a provision request specifying the requested function using an authorization key stored by the security module.

[0060] In step 420, the signed provision request is sent from the computing system to the access management.

[0061] In step 430, the access management checks the authenticity of the signed provision request.

[0062] In step 440, if the check is successful, the access management sends an access key for the requested function to the computing system. If the check is unsuccessful, the access key is not sent to the computing system, where optionally an error message, etc., is sent.

[0063] In step 450, a container request for the requested function is sent to a repository storing a function container having the requested function.

[0064] Depending on how the validity of the access key should be confirmed (see the description of Figure 1 , especially the description of the repository), different ways can be taken. The first way includes steps 460 and 465. The second way includes steps 470 and 475.

[0065] According to the first approach, the container request includes an access key. In step 460, the repository checks the validity of the access key. In step 465, if the validity check is successful, the functional container is transmitted by the repository to the computing system. In the case where the check is unsuccessful, the functional container is not transmitted, and optionally an error message etc. is sent to the computing system.

[0066] According to the second approach, the functional container is password protected in the repository such that the requested function cannot be realized without knowing the access key. The password protection can especially include encryption. In step 470, in response to the container request, the protected functional container is transmitted by the repository to the computing system. In step 475, the computing system uses the access key to decrypt the password protection of the functional container. Decrypting the password protection especially includes decryption. Steps 470 and 475 can especially have been executed before performing step 420 or step 410, i.e., before the request is provided.

[0067] In step 480, when or after the validity of the access key is confirmed, the computing unit uses the functional container in the computing system to realize the function.

Claims

1. A method for providing a computer-implemented function in a computing system (2), the computing system having at least one computing unit (4) and a security module (6, 8), the method comprising: signing (210) by the security module (6, 8) a provision request specifying the requested functionality using an authorization key stored by the security module; sending (420) the signed provisioning request to the access management (14); The authenticity of the signed provision request is checked (430) by the access management (14); If the check is successful, the access key for the requested function is sent (440) by the access management to the computing system (2); sending (450) a container request for the requested functionality to a repository (16) storing a functionality container (18) having the requested functionality; as well as If the validity of the access key is confirmed, the at least one computing unit (4) implements (480) the function in the computing system (2) using the function container.

2. The method of claim 1 , wherein the container request includes the access key, and the method further comprises: To confirm the validity of the access key, checking (460) the validity of the access key by the repository (16); as well as If the validity check is successful, the capability container is transmitted (465) by the repository to the computing system (2).

3. The method according to claim 1, wherein the function container (18) is password-protected, in particular encrypted, in the repository (16), so that the requested function cannot be implemented without knowing the access key, the method further comprising: To confirm the validity of the access key, transmitting (470), by the repository (16) in response to the container request, a protected capability container to the computing system (2); and The computing system (2) uses the access key to release (475) the cryptographic protection of the function container, in particular to decrypt the function container.

4. The method according to any of the preceding claims, wherein the access key is sent by the access management (14) to the computing system (2) as an encrypted access key.

5. A method according to claim 4 with reference to claim 2, wherein an encrypted access key is decrypted by the security module (6, 8) and temporarily stored by the security module without being transmitted to the computing unit (4) or other modules of the computing system (2); wherein the access key is inserted into the container request by the security module (6, 8); and wherein the container request is encrypted by the security module after the insertion.

6. A method according to claim 4 while citing claim 3, wherein the encrypted access key is decrypted by the security module (6, 8) and temporarily stored by the security module without being transmitted to the computing unit (4) or other modules of the computing system; and wherein the cryptographic protection of the functional container is released by the security module (6, 8).

7. The method according to any one of the preceding claims, wherein the computing system (2) has a communication module (10); wherein communication with the access management (14) and the repository (16) is performed via the communication module; wherein the communication with the access management (14) and the repository (16) comprises: Sending a signed provision request, receiving the access key in the process of sending the access key to the computing system, sending the container request to the repository, and receiving the capability container from the repository if necessary.

8. The method according to any of the preceding claims, wherein sending the provision request and / or sending the access key and / or sending the container request and / or transmitting the functional container, if necessary, is performed in a cryptographically protected form, wherein the corresponding message is encrypted and / or signed.

9. The method according to claim 8, wherein encryption and / or signing and / or decryption and / or signature checking of messages are performed in the computing system by the security module (6, 8); wherein cryptographic keys used in this process are stored by the security module.

10. The method according to any of the preceding claims, wherein the provision request and / or the container request is generated by at least one computing unit (4) of the computing system (2), in particular by a computing unit that is to implement the requested function.

11. The method according to claim 1, wherein the function container (18) contains program modules and / or program parameters.

12. A method for execution in a computing system (2), the computing system having at least one computing unit (4) and a security module (6, 8), the method comprising: signing, by the security module (6, 8), a provision request specifying the requested functionality using an authorization key stored by the security module; Sending the signed provisioning request to access management (14); receiving an access key for the requested function from the access management (14); sending a container request for the requested functionality to a repository (16), the repository storing a functionality container (18) having the requested functionality; The container request includes the access key, and the method comprises: receiving the function container from the repository (16) and implementing the function by the at least one computing unit (4) using the function container (18); or the function container is received from the repository as a password-protected function container, and the method comprises: removing the password protection of the function container using the access key and implementing the function by the at least one computing unit (4) using the function container (18).

13. A computing system (2) configured to perform all the steps of the method according to claim 12.

14. A computer program which causes a computing unit (4) of a computing system (2) to execute all method steps of the method according to claim 12 or which causes them to be executed when the computer program is executed on a computing unit, in particular by a security module.

15. A machine-readable storage medium having stored thereon the computer program according to claim 14.