Method for encrypting source text, method for decrypting source text and development system

By encrypting and texting the source text used in the version control system, the problem of unauthorized access and disclosure of trade secrets is solved, and the functions of secure management and differential viewing in the version control system are realized.

CN120202469APending Publication Date: 2025-06-24BECKHOFF AUTOMATION GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380078815.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-25
Filing Date
2023-11-22
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In version control systems, the development and management of source texts are at risk of unauthorized personnel peeping and leaking trade secrets.

Method used

By encrypting the source text and texting the encrypted source text, it is possible to manage and register changes between different versions in the version control system.

Benefits of technology

It implements secure management of source text in a version control system to prevent unauthorized access and leakage of trade secrets, while allowing viewing and managing differences in different versions in encrypted source text.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120202469A_ABST
    Figure CN120202469A_ABST
Patent Text Reader

Abstract

The invention relates to a method (100) for encrypting source text (301) for use (315) in a version control system, comprising: providing the source text (301) in unencrypted and textual form in a providing step (101); performing encryption of the source text (301) and generating an encrypted source text version (303) in an encryption step (103); and performing textualization of the encrypted source text version (303) and generating a textualized representation (305) of the encrypted source text version (303) in a textualization step (105). The invention also relates to a method (200) for decrypting an encrypted source text version (303) and a development system (300) for performing the method (100, 200).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for encrypting source text used in a version control system, a method for decrypting the corresponding encrypted source text, and a development system configured to execute these two methods. Background Art

[0002] Programmable logic controllers (PLCs) are mainly used for controlling and regulating machines and equipment, especially in the field of automation. In this case, the control or regulation actions are represented by control programs that are appropriately set and executable on the corresponding PLCs. Such control programs are usually developed individually by developers for the corresponding machine or equipment type.

[0003] Version control systems for developing source text are known from the prior art. Such version control systems allow storing and managing different versions of the source text to be developed, so as to build a development process of the source text on this basis, and allow developers to access old versions of the source text during the development process.

[0004] In addition to managing the versions of the source text created during the development operations of the source text, the version control systems known from the prior art also allow marking the changes created between different versions of the source text.

[0005] For this purpose, various versions of the source text are stored in the storage area of the version control system and must exist in text representation so that the changes made by the version control system can be detected and identified.

[0006] However, if the source text is developed by multiple developers, or the version control system is generally viewable by multiple people because the version control system operates, for example, on a public or at least partially publicly accessible server system, there is a risk that unauthorized persons will gain insight into the developed source text, thereby inadvertently disclosing trade secrets. Especially in the field of automation, the source text of the control program used to control the automation system must be protected from third-party access. Summary of the Invention

[0007] Therefore, an object of the present invention is to provide an improved method for encrypting source text used in a version control system, an improved method for decrypting encrypted source text, and a development system for executing these methods.

[0008] This object is achieved by the method for encrypting source text, the method for decrypting encrypted source text, and the development system according to the independent claims. Preferred embodiments are given in the dependent claims.

[0009] According to one aspect of the present invention, there is provided a method for encrypting source text used in a version control system, comprising:

[0010] Provide the source text in unencrypted and text form in the providing step;

[0011] Perform encryption of the source text and generate an encrypted source text version in the encryption step; and

[0012] Perform textification of the encrypted source text version and generate a textified representation of the encrypted source text version in the textification step.

[0013] This can achieve technical advantages, namely, an improved method for encrypting source text used in a version control system can be provided.

[0014] To this end, first encrypt the developed source text and generate an encrypted source text version. Here, the encrypted source text version can be encrypted by an encryption method known in the prior art.

[0015] Subsequently, generate a textified representation of the encrypted source text version. To this end, perform textification of the encrypted source text version. This can be achieved, for example, by a textification method known in the prior art.

[0016] Through the textified representation of the encrypted source text version, the encrypted source text version can be managed in the form of a textified representation in the version control system.

[0017] Version control systems known in the prior art are used to manage the development process when developing source text. In this case, version control systems known in the prior art are aligned in such a way that, in addition to management, the version control system can register and optionally display changes made between different versions of the developed source text. However, the source text uploaded to the version control system must exist in textified representation form. Version control systems known in the prior art can only work on textified files and, due to the textified form of the current source text file, register and possibly display changes made between different versions of the uploaded source text.

[0018] By textifying the encrypted source text version, the encrypted source text version can be managed by a version control system known in the prior art. Due to the text representation, the version control system can register and display changes to different versions of the developed source text.

[0019] By encrypting the source text performed previously, unauthorized persons can be prevented from peeping at the developed source text when managing the developed source code version, thereby possibly leaking trade secrets. According to the present invention, the encryption of the source text is configured in such a way that different versions of the developed source text result in different encrypted source text versions.

[0020] Thus, differences between different source text versions can be viewed in different encrypted source text versions. Thus, through textification, a version control system can register different encrypted source text versions and, if needed, also register the corresponding differences within the encrypted source text versions without exposing the actually generated source text.

[0021] Thus, the version control system can register different encrypted source text versions only in different encrypted forms and, if needed, display different locations within the source text. However, due to the encryption, the actual source text is never opened in the version control system at any time.

[0022] This improves data security and prevents accidental leakage of the generated source text. At the same time, the textified representation of the encrypted source text versions ensures the management of various source text versions in a control system provided for this purpose during the development process and known from the prior art. This can simplify and accelerate the development process.

[0023] In the context of automated applications, it may be necessary to protect programming source code, especially control programs for automated systems, against unauthorized access.

[0024] For example, this may be related to the following potential use cases. Source code, such as a control program for an automated system, is developed by developers of a company, for example using a version control system, and stored on the control system of another company so that the developers can access the programmed source code at a later time, for example for troubleshooting.

[0025] In this case, the company that owns the source code may have the motivation to protect the source code (which may include trade secrets) from unauthorized access, for example by employees of another company that is a competitor of the first company.

[0026] The method according to the invention allows the owner company to protect the generated source code and the trade secrets contained therein by encrypting the source text. Encryption is performed here such that the encrypted source text can be managed in a version control system known from the prior art or a debugging process can be performed based on the encrypted source text in order to be able to check the functionality of the source code.

[0027] In another use case of the method according to the invention, developers of a company store source code created, for example, using a version control system, on the company's system (such as a server).

[0028] By the method according to the invention, access to the developed source code by another developer from another company can be prevented. On the other hand, another developer from another company should be able to access at least one specific part of the source code but may not be able to access other parts of the source code because, for example, trade secrets are disclosed in that part.

[0029] By the method according to the present invention, various parts of the source code can be encrypted such that an individual can be partially granted access to the source code while other parts of the source code can remain inaccessible.

[0030] According to one embodiment, the encryption and / or texturization is performed line by line, wherein the line order of the unencrypted source text is retained in the encrypted source text version and / or the texturized representation of the encrypted source text version.

[0031] Thus, a technical advantage can be achieved that the line structure of the original source text is retained by encrypting line by line and texturizing the encrypted lines of the encrypted source text version line by line. By retaining the line structure, a version control system can display the individual lines changed between different source text versions based on the texturized representation of the encrypted source text version. Thus, the development process can be further improved because the changes made between different source text versions can be directly visible by registering or displaying line by line the changes made between different source text versions.

[0032] The line order here describes the arrangement of the individual lines within the source text, within the encrypted source text version, or within the texturized representation of the encrypted source text version.

[0033] This means that the nth line within the unencrypted source text results in the nth encrypted line within the encrypted source text version and the nth texturized line representation of the nth encrypted line within the texturized representation. Thus, the encrypted line within the encrypted source text version with a specific line number corresponds to the encryption of the line within the unencrypted source text with the same line number. This also applies to the corresponding lines within the texturized representation, for the same line number, the texturized representation is also based on the corresponding encrypted line of the encrypted source text version.

[0034] According to one embodiment, the method further comprises:

[0035] performing line separation of the source text and generating separated lines of the source text in the line separation step;

[0036] wherein the encryption step is performed on the separated lines of the source text and, for each separated line, comprises:

[0037] performing encryption of the separated line and generating an encrypted line of the encrypted source text version in the line encryption step.

[0038] In this way, the technical advantage of unique line-by-line encryption of each line of the unencrypted source text can be achieved. By separating each line of the unencrypted source text and generating multiple separated lines accordingly, applying encryption line by line to each separated line of the unencrypted source text and generating the corresponding encrypted lines of the encrypted source text version line by line enables the creation of multiple independent individual encrypted lines. In this case, the encrypted source text version describes most of the encrypted lines generated in this way.

[0039] By separating each line of the unencrypted source text, the line order of the unencrypted source text can be maintained. Thus, for example, a corresponding line number can be assigned to a single separated line, which reproduces the corresponding line number within the unencrypted source text.

[0040] Optionally, the corresponding separated lines can be arranged in an arrangement corresponding to the line order of the unencrypted source text so as to be able to maintain the line order during the encryption operation. In this case, the encrypted lines can similarly be provided with corresponding line numbers, or after encryption, can be arranged in the corresponding arrangement of the separated lines of the unencrypted source text. In this way, the line order within the multiple encrypted lines can be maintained again.

[0041] According to one embodiment, the texturizing step is performed on the encrypted lines of the encrypted source text version and for each encrypted line includes:

[0042] Performing texturizing of the encrypted lines of the encrypted source text version and generating a texturized line representation of the encrypted lines of the encrypted source text version in the line texturizing step.

[0043] This can achieve the technical advantage that unique line-by-line texturizing of multiple encrypted lines of the encrypted source text version is possible. In this case, texturizing is applied separately to the multiple encrypted lines of the encrypted source text version in each case. By performing texturizing line by line on the various encrypted lines, the line numbers of the individual encrypted lines or the corresponding line order of the corresponding arrangement form of the multiple encrypted lines can also be maintained.

[0044] The corresponding texturized line representations, which are in each case the texturized representations of a single encrypted line, can also be provided with corresponding line numbers, or can be arranged according to the corresponding arrangement of the encrypted lines.

[0045] According to one embodiment, the texturizing step further includes:

[0046] Merging the multiple texturized line representations of the encrypted lines of the encrypted source text version and generating a texturized representation of the encrypted source text version as an entirety of the texturized line representations in the line merging step.

[0047] Accordingly, technical advantages can be achieved that can provide a coherent textual representation of an encrypted source text version. To this end, a plurality of updated line representations previously generated by textually representing multiple encrypted lines line by line are combined into a corresponding textual representation of the encrypted source text version.

[0048] The textual representation of the encrypted source text version describes the corresponding combination of multiple textual line representations, wherein, in the combination of the multiple textual line representations, the corresponding line order of the original unencrypted source text is retained.

[0049] To this end, the nth textual line representation based on the nth encrypted line and thus based on the nth line of the unencrypted source text is arranged at the nth position within the textual representation of the encrypted source text version. Accordingly, the textual representation of the encrypted source text version generated in this way corresponds to the textual representation of the original source text, wherein the corresponding line structure or line order of the original source text is retained, and wherein each textual line representation is a textual representation of the encrypted line based on the corresponding original line of the unencrypted source text.

[0050] Accordingly, to a version control system, the textual representation of the encrypted source text version appears like a normal source text consisting of n lines, where each line represents a text element. However, despite the textual representation, the content of the source text is encrypted and thus cannot be read by unauthorized persons without performing the corresponding key.

[0051] According to one embodiment, the encryption is configured to be decryptable encryption, wherein, by applying an appropriate key to the encrypted source text version, the encrypted source text version can be uniquely traced back to the unencrypted source text.

[0052] Accordingly, technical advantages can be achieved such that the encrypted source text version can be returned to the original source text by performing appropriate decryption, such that, for example, when downloading the textual representation of the encrypted source text version from a version control system, the original source text can be restored by appropriate decryption, such that the corresponding user or developer can continue development operations based on the corresponding source text.

[0053] Accordingly, the encryption of the original source text is mainly used to protect the source text from unauthorized access when managed within a version control system. However, through appropriate decryption, the source text can be restored by authorized personnel having the corresponding key, thereby allowing further processing of the original source text.

[0054] According to one embodiment, the encryption is configured to be symmetric encryption.

[0055] Accordingly, technical advantages can be achieved that symmetric encryption can provide encryption that is as simple as possible.

[0056] According to one embodiment, the encryption is configured to be asymmetric encryption.

[0057] In this way, technical advantages can be achieved, namely, through asymmetric encryption, as secure an encryption as possible of the source text can be provided.

[0058] According to one embodiment, the texturization is configured to be a uniquely reversible texturization, wherein, by reversing the texturization in the de-texturized form, the texturized representation of the encrypted source text version can be uniquely converted into the encrypted source text version.

[0059] Therefore, technical advantages can be achieved, namely, the texturization of the texturized representation of the encrypted source text version can be reversed by reversible texturization, and the encrypted source text version can be recovered from the texturized representation of the encrypted source text version.

[0060] This further allows the encrypted source text version to be decrypted by executing the corresponding key. Therefore, in order to recover the original source text from the texturized representation of the encrypted source text version, first the texturization of the texturized representation of the encrypted source text version is revoked, and the encrypted source text version is recovered from the texturized representation of the encrypted source text version.

[0061] Subsequently, the corresponding key is executed on the encrypted source text version, and the original source text is generated by decrypting the encrypted source text version. Since both the texturization and the encryption are uniquely reversible, the described decryption method can uniquely recover the original source text.

[0062] On the one hand, this makes it possible to securely manage the source text within a version control system. On the other hand, the original source text managed in the version control system in the form of the texturized representation of the encrypted source text version can be recovered so that it can be further processed if appropriate.

[0063] According to one embodiment, the encryption is a unique encryption, which results in the same encrypted lines in the case of lines of source text with the same content, and different encrypted lines in the case of lines of source text with different content, and / or, wherein, the texturization is a unique texturization, which results in the same texturized line representation in the case of encrypted lines with the same encryption, and different texturized line representations of the encrypted lines in the case of encrypted lines with different encryption.

[0064] Therefore, technical advantages can be achieved, namely, through unique encryption or unique texturization, unique decryption of the texturized representation of the encrypted source code version and unique recovery of the original source text can be achieved, wherein different lines of the original source text with the same content result in the same encrypted lines or the same texturized line representation of the encrypted source text version, while lines of the original source text with different content result in different encrypted lines and different texturized line representations. This makes it possible to manage various source texts in the form of the texturized representation of the encrypted source text version in a version control system without any problems.

[0065] According to one embodiment, the encryption is binary encryption.

[0066] Therefore, the technical advantages of providing technically simple and secure encryption can be achieved.

[0067] According to one embodiment, the texturization of the source text version for encryption is implemented by a base64 texturization algorithm.

[0068] Therefore, the technical advantages of achieving a unique and precise texturization of the source text version for encryption can be achieved.

[0069] According to one embodiment, the source text defines a control program for an automated system.

[0070] Therefore, the technical advantages can be achieved that, by the method according to the invention, the control program in the version control system can be securely managed, wherein unauthorized persons can be prevented from viewing the source text of the control program, and any operational secrets contained in the control program can be prevented from being inadvertently disclosed.

[0071] According to another aspect of the invention, there is provided a method for decrypting a source text encrypted by the method for encrypting a source text according to any one of the foregoing embodiments, comprising:

[0072] Performing line separation of the textual representation of the encrypted source text version and generating a separated textual representation of the encrypted lines of the encrypted source text version in another line separation step;

[0073] Performing detexturization on each textual representation of the encrypted lines of the encrypted source text version in a detexturization step;

[0074] Decrypting the encrypted lines of the encrypted source text version and generating unencrypted lines of the source text in a decryption step; and

[0075] Merging the unencrypted lines of the source text and generating a visible representation of the source text in another line merging step.

[0076] In this way, the technical advantages can be achieved that an improved method for decrypting a source text that has been encrypted by the method for encrypting a source text according to any one of the foregoing embodiments can be provided. Decryption allows further processing of the encrypted source text, for example, further development of the source text by a developer. Due to the uniqueness of the encryption / decryption, the original unencrypted source text can be restored.

[0077] According to another aspect of the invention, there is provided a development system for developing and / or processing a source text, wherein the development system is arranged to execute the method for encrypting a source text used in a version control system and / or the method for decrypting a source text according to any one of the foregoing embodiments.

[0078] In this way, technical advantages can be achieved, namely, an improved development system can be provided, which is configured to execute the method for encrypting and / or decrypting a source text according to the present invention and has the above-mentioned technical advantages. Description of the Drawings

[0079] The present invention will be explained in more detail with reference to the accompanying drawings. In the drawings:

[0080] Figure 1 A graphical representation of a method for encrypting a source text used in a version control system according to an embodiment is shown;

[0081] Figure 2 A graphical representation of a method for decrypting a source text according to an embodiment is shown;

[0082] Figure 3 A flowchart of a method for encrypting a source text used in a version control system according to an embodiment is shown;

[0083] Figure 4 Another flowchart of a method for encrypting a source text used in a version control system according to another embodiment is shown; and

[0084] Figure 5 A flowchart of a method for decrypting a source text according to an embodiment is shown. Detailed Description of the Embodiments

[0085] Figure 1 A graphical representation of a method 100 for encrypting a source text 301 used in a version control system 315 according to an embodiment is shown.

[0086] In Figure 1 the graphical representation, each step of the method according to the present invention for encrypting the source text 301 in the version control system 315 described in conjunction with Figure 3 is described.

[0087] Figure 1 A development system 300 for developing the source text 301 and a version control system 315 for storing and managing different versions of the developed source text 301 are shown. The development system 300 and the version control system 315 can be configured as the development system 300 or the version control system 315 known in the prior art.

[0088] In particular, the development system and the version control system can also be the same and located on the same computing unit.

[0089] In the context of the present application, the development system 300 is a development environment for developing source text. Such a development system 300 can be provided, for example, by an IDE (Intelligent Development Engine).

[0090] The development system 300, which is used, for example, in automation technology, provides various functions for programmers of automation software to program such software. For text-based programming languages in DIN 61131, this includes, for example, the automatic completion of frequently used programming expressions, etc. For graphical programming languages from DIN 61131, the development system provides a graphical representation of the programming.

[0091] Thus, developers of software products can use the development system to develop control programs for machines or automation systems and other technical devices.

[0092] For this purpose, developers can use different programming languages. In the field of automation, the programming languages in DIN 61131 are mainly used. These can also include graphical programming languages.

[0093] Developers can also use the development system to observe and understand the behavior of the programmed control program during execution, such as analyzing error behavior or optimizing behavior. This is achieved during the debugging process.

[0094] Technicians can also use the development system to debug devices, such as automation systems. This can include transferring the control program to a suitable controller, such as a PLC (Programmable Logic Controller) memory, and setting device parameters or observing the device behavior as described above, respectively, in order to be able to eliminate or detect installation errors.

[0095] Operators of technical devices (such as automation systems) can also use the development system to control, manually operate the device, bridge behavior, or set simple parameters.

[0096] Generally, in the field of automation, control programs are written in one or more languages of the IEC 61131-3 standard.

[0097] This standard includes five languages: "Structured Text", "Instruction List", "Process Language", "Link Plan", and "Function Block Language". "Structured Text" and "Instruction List" are text languages. "Link Plan" and "Function Block Language" are graphical languages. "Link Plan" includes both text and graphics aspects.

[0098] The input of source text during programming can be supported by an automatic completion mechanism within the development system used. For example, automatic completion can complete, correct the input of keywords, and / or insert another associated keyword.

[0099] Input can also be simplified by displaying information. For example, the expected parameters of a function call can be displayed.

[0100] If the program code is recognized as an error during input, the corresponding location can be marked in the source code, and an explanation can be optionally displayed, which can facilitate immediate error correction.

[0101] The version control system 315 can be configured as a public version control system, such as the commercially available GitHub Dients that uses the open-source version control system software GIT.

[0102] Alternatively, the version control system 315 can be configured as a private version control system operating on a corporate internal server architecture.

[0103] The version control system provides a management tool for the development process of software products. During the development process of a software product (such as a control program for an automation system), newly created versions of the written source code can be stored in and managed by the version control system. Thus, during the development process of continuously creating new versions of the source code, users can track the development process, especially the progress, by managing the source code versions stored in the version control system. For this purpose, the version control system provides many different functions for users. Thus, for example, a line-by-line structured change log can be provided to the user, which shows the changes made between different versions of the source code line by line. This allows for comparison of different versions of the source code created at different times or by different developers.

[0104] For this purpose, the change log can include, for example, indications of which lines have been changed in what way between different versions. For example, it can point to newly added lines, deleted lines, and changed lines.

[0105] Generally, users of a version control system can store versions of the source code as a set of files in the directory structure of the version control system, and these files are typically designed as text files and contain program code.

[0106] Then, the version control system enables users to access not only one state of these data, but also multiple such states. The version control system associates additional information with the states, and this additional information can include, for example, the creation date, the creator, an informal description, a unique number, and a reference to a previous state.

[0107] In this case, the version control system is usually set up in such a way that it does not store the complete state, but only stores the current changes of the current version relative to the source code version that describes the previous state of the source code. This makes it possible to save resources because versions that are consecutive in time build on each other and are usually only slightly different.

[0108] Based on this information, a version control system can provide the user with data of any source code version (check out). Thus, the user can consider any old version and, if necessary, incorporate it back into the development process.

[0109] The version control system can also show the user which files are different between two versions or exist only in one version.

[0110] If these are text files, the version control system can also show which lines are different or available only in one version (diff).

[0111] For each line of a text file, the version control system can also show the user into which (previous) version the line was most recently modified or inserted. For example, the date, author, and part of the description can be shown next to each line (blame).

[0112] The version control system can also merge independently generated versions developed by different developers, for example (merge).

[0113] The version control system can also undo changes between two consecutive versions, perhaps only partially (revert).

[0114] The version control system can further restructure and modify the version sequence into a change sequence (re-base).

[0115] The version control system can also apply the changes that are the difference between two source code versions to another source code version (cherry-pick).

[0116] To perform the encryption of the source text 301, the development system 300 first provides the source text 301 having multiple lines 313 in the providing operation 302. In this case, the providing can be achieved by a development operation in which a developer creates the source text 301 within the development system 300 by performing appropriate programming operations.

[0117] Alternatively or additionally, the providing operation 302 can include the development system 300 reading in the already created source text 301.

[0118] In the line separation operation 304, the development system 300 generates a plurality of separated lines 307 from the provided source text 301. Each separated line 307 corresponds in content to a respective line 313 of the provided source text 301. Thus, the separated lines 307 differ from the lines 313 of the original source text 301 in that they are provided as separate lines or separate objects respectively, rather than being combined in the entire document in the form of the original source text 301.

[0119] The separated lines 307 can be stored as separate files.

[0120] The line separation operation 304 preferably preserves the line order of the lines 313 of the original source text 301. Thus, the n-th line 313 becomes the n-th separated line 307. Accordingly, the n-th separated line 307 is arranged in the n-th position within the total number of the plurality of n separated lines 307. To this end, a corresponding line number can be assigned to each separated line 307, which corresponds to the line number of the corresponding line 313 within the original source text 301.

[0121] The character combinations within the separated lines 307 are intended to represent the source code programmed within the line in each case.

[0122] Alternatively or additionally, the corresponding separated lines 307 can be arranged in the corresponding n-th position within the plurality of separated lines 307, wherein the corresponding arrangement position of the corresponding separated line 307 reflects the line number of the corresponding line 313 of the original source text 301 that gave rise to the separated line 307.

[0123] In the encryption operation 306, each separated line 307 is subsequently encrypted line by line, and a corresponding encrypted line 309 is generated. In this case, the separated line 307 is considered as a separate encryption object in each case, and the corresponding encryption is applied line by line to the individual separated lines 307.

[0124] The encryption operation 306 uses the first key 323 to encrypt the separated lines 307.

[0125] Accordingly, two separated lines 307 with the same content result in encrypted lines 309 with the same content.

[0126] Through the line-by-line encryption in the encryption operation 306 and the corresponding line-by-line generation of the encrypted lines 309, the line order of the separated lines 307 that reflects the line order of the original lines 313 of the unencrypted source text 301 is retained. To this end, a line number corresponding to the line number of the corresponding line 313 within the source text 301 can be added to the encrypted lines 309.

[0127] Alternatively, the corresponding encrypted lines 309 can be arranged according to the line order of the lines 313 of the original source text 301, such that the n-th encrypted line 309 representing the n-th line 313 of the original source text 301 is arranged in the n-th position within the plurality of encrypted lines 309. Here, the plurality of encrypted lines 309 defines the encrypted source text version 303, which represents the complete encryption of the original source text 301.

[0128] In this case, the encrypted lines 309 can be cached individually as separate objects.

[0129] Alternatively or additionally, the encrypted lines 309 can be cached as partial objects within the encrypted source text version 303 as a whole object.

[0130] Encryption can be in the form of, for example, binary encryption. In the representation shown, the corresponding encrypted line 309 is represented as binary elements, which is intended to illustrate the corresponding binary encryption.

[0131] Examples of binary encryption are RSA (Rivest-Shamir-Adleman) encryption or AES (Advanced Encrypted Standard) encryption. Both of these encryptions use a key to convert data into a form that allows the original data to be inferred only if the key is known. Symmetric encryption uses the same key for encryption and decryption. In asymmetric encryption, separate and different keys are used for encryption and decryption.

[0132] Both of these methods take a byte sequence as input and return an (encrypted / decrypted) byte sequence, where a byte contains an integer in the range [0..255].

[0133] Each text is interpreted as a byte sequence and can thus be encrypted immediately. However, the result is a byte sequence that usually does not correspond to any valid text line.

[0134] However, optionally, any other encryption can also be used.

[0135] Preferably, the encryption is provided as a unique or injective encryption, where separate lines 307 with the same content result in encrypted lines 309 with the same encrypted representation, and separate lines 307 with different content result in encrypted lines 309 with different encrypted representations. In the shown Figure 1 the encrypted representation is represented by the corresponding binary digit sequence.

[0136] In the texturization operation 308, texturization is subsequently performed line by line based on the encrypted line 309, and the corresponding texturized line representation 311 of the encrypted line 309 is generated.

[0137] The texturization is preferably a unique or injective texturization, where encrypted lines 309 with different encrypted representations result in different texturized line representations 311, while encrypted lines 309 with the same encrypted representation result in the same texturized line representation 311.

[0138] This is illustrated by the letter combinations of the shown texturized line representations 311. For encrypted lines 309 that describe the same part of the source code, the texturized line representations 311 have the same letter combinations.

[0139] Separate lines 307 with the same content result in the same encrypted lines 309 after encryption.

[0140] On the other hand, for the encrypted line 309 with different encrypted representations, the textual line representation 311 has different combinations of letters. The combination of letters of the textual line representation 311 is only used to illustrate the textual form of the textual line representation 311. However, the shown combination of letters does not describe the actual textual line representation 311 and can only be understood symbolically.

[0141] By performing the texturing operation 308, the line order of the encrypted line 309 is maintained, which corresponds to the line order of the separated line 307, and the separated line 307 in turn corresponds to the line order of the line 313 of the original source text 301. To this end, the textual line representation 311 can be identified by the corresponding line numbers corresponding to the line numbers of the original line 313 of the source text 301. Optionally, the textual line representations 311 can be arranged or stored in the corresponding order corresponding to the line order of the original source text 301. To this end, the textual line representations 311 can be cached as independent objects or files.

[0142] The texturing operation 308 can be implemented, for example, by performing the base64 algorithm.

[0143] The base64 algorithm is a method of encoding 8-bit binary data (such as an executable program, a ZIP file, or an image) into a string consisting only of readable, code-page-independent ASCII characters. In the base64 algorithm, 24 bits of three consecutive bytes are divided into four parts, each part being six bits. Each 6-bit part can represent 64 different values, which can be represented by 64 common text characters (a-z, A-Z, 0-9, +, and / ).

[0144] In the line merging operation 310, the development system 300 then combines the textual line representations 311 according to the corresponding line order in the textual representation 305 of the encrypted source text version 303. In this case, the textual representation 305 of the encrypted source text version 303 describes the relevant document in text format, where the textual line representations 311 are combined into a single line arranged according to the corresponding order.

[0145] Therefore, the textual representation 305 describes the encrypted representation of the original source text 301 in text format, where the corresponding content of the original source text 301 exists in the textual representation 305 in encrypted form. Therefore, each line of the textual representation 305 represents each line 313 of the original source text 301, where the corresponding content of the line 313 is encrypted within the textual representation 305 but still exists in text form.

[0146] The content of the nth line of the source code 301 is only reflected in the corresponding nth line of the textual representation 305. Therefore, a change in the nth line of the source code only results in a change in the nth line of the textual representation 305. This is a necessary condition for using encryption in a version control system.

[0147] In the storage operation 312, the textual representation 305 of the encrypted source text version 303 is stored in the aforementioned version control system 315. Thus, the version control system 315 can manage the textual representation 305, read in the textual representation 305 in text form, compare it with other textual representations 305 of other source text versions, and register and optionally display the corresponding matches or changes. Due to the encryption, although in text form of the textual representation 305, the actual content of the source text 301 cannot be viewed without performing the corresponding decryption.

[0148] Alternatively, the text representation can of course also be stored on a hard disk or another storage medium.

[0149] In addition to the entire source text 301, the above operations can also be performed only on individual parts of the source text 301, including the line separation operation 304, the encryption operation 306, the textification operation 308, the line merging operation 310, and the storage operation 312.

[0150] In particular, the operations can be performed only on the lines of the source text 301 that are newly created or modified during the programming operation. In the extreme case, the operation can be performed only on a newly created line.

[0151] As a result, it is possible to achieve that only the newly created lines of the source text 301 are encrypted and, for example, loaded into the version control system. Thus, the entire source code 301 does not have to be fully encrypted again every time there is a change.

[0152] Since according to the present invention, the encrypted lines 309 of the encrypted source text version 303 precisely correspond to the unencrypted lines of the unencrypted source text 301, typical statements of the version control system, such as the modification range or even determining the line origin of the encrypted lines 309 of the encrypted source text version 303, still remain valid. The version control system also provides support for merging different states (merge / rebase).

[0153] Figure 2 A graphical representation of a method 200 for decrypting an encrypted source text 305 according to an embodiment is shown.

[0154] Figure 2 Is shown graphically in combination with Figure 5 The individual steps of the method for decrypting an encrypted source code described. Figure 2 The development system 300 and the version control system 315 are shown again. These can be constructed accordingly according to Figure 1 The embodiments.

[0155] In Figure 2 The textual representation 305 is associated with Figure 1is the same as the textual representation 305. Accordingly, the textual line representation 311 is the same as the textual line representation 311 in Figure 1 This is merely exemplary and should not limit the method according to the present invention.

[0156] According to Figure 1 The textual representation 305 of the encrypted source text version 303 of the corresponding source text 301 generated according to the described steps is stored in the version control system 315.

[0157] In the loading operation 314, the textual representation 305 of the encrypted source text version 303 stored and managed in the version control system 315 is loaded into the development system 300.

[0158] In another line separation operation 316, the individual lines of the textual representation 305 of the encrypted source text version 303 are separated, and corresponding textual line representations 311 are generated based on Figure 1 the description.

[0159] As already combined with Figure 1 described, the line separation maintains the line order of the individual lines within the textual representation 305 within the textual line representation 311. To this end, the textual line representation 311 may include corresponding line numbers describing the corresponding arrangement of the corresponding lines within the textual representation 305. Alternatively or additionally, the textual line representation 311 may be arranged in a corresponding order describing the line order of the textual representation 305.

[0160] In the detextualization operation 318, each textual line representation 311 is detextualized line by line, and corresponding encrypted lines 309 are generated. In this case, the encrypted lines 309 correspond to the encrypted lines 309 that were initially used to generate the textual line representation 311 through textuallization.

[0161] Therefore, the detextualization in the detextualization operation 318 describes a function opposite to the textuallization function, which was initially used to generate the textual line representation 311 based on the encrypted lines 309 of the encrypted source text version 303.

[0162] Therefore, the textuallization is preferably configured as a unique injective textuallization function that converts the encrypted lines 309 into corresponding textual line representations 311 in a unique way, where the same textual line representation 311 is generated for encrypted lines 309 with the same encrypted representation, and different textual line representations 311 are generated for encrypted lines 309 with different encrypted representations, and where the detextualization generates a uniquely corresponding encrypted line 309 from the textual line representation 311 in a unique way, where encrypted lines 309 with the same textual content are generated for textual line representations 311 with the same textual content, and different encrypted lines 309 are generated for textual line representations 311 with different textual content.

[0163] The encrypted representation here describes an encrypted form of the content of the corresponding encrypted line. In the illustrated embodiment, the encrypted representation of encrypted line 309 is given by a binary representation represented separately. The binary representation here describes the binary encrypted content of the corresponding line 313.

[0164] Through the detextualization operation in 318, the original line order of the lines within the textual representation 305 is retained. To this end, the correspondingly generated or restored encrypted line 309 can have a corresponding line number.

[0165] Alternatively, the arrangement of the individual encrypted lines 309 can be performed according to the line order of the lines within the textual representation 305. The encrypted lines 309 can be stored as separate objects or files or caches.

[0166] Alternatively or additionally, a file of the encrypted source text version 303, which includes the entirety of the individual encrypted lines 309, can be stored or cached.

[0167] In the decryption operation 320, the individual encrypted lines 309 are decrypted, and the corresponding separated lines 307 are generated. Thus, the encryption is preferably a unique injective encryption, which allows for the unique decryption of the encrypted lines 309. Through the line-by-line decryption in the decryption operation 320, the line order of the encrypted lines 309 is maintained, and the separated lines 307 can be arranged according to the maintained line order.

[0168] The decryption operation 320 is performed considering a second key 325 for decrypting the encrypted line 309.

[0169] The first key 323 for encryption and the second key 325 for decryption can be configured as different keys, such as a private key and a public key. Optionally, the same key can be used for the first and second keys 323, 325.

[0170] To this end, the individual separated lines 307 can be set with corresponding line numbers, or can be arranged according to the line order. In this case, the decrypted separated lines 307 represent the corresponding lines 313 of the original source text 301 in a separated form. To this end, the separated lines 307 can be cached as independent objects or files.

[0171] In another line merging operation 322, the individual separated lines 307 are merged into the original source text 301. In this case, the line order is maintained in such a way that the separated lines 307 are merged according to their line order in the source text 301.

[0172] The source text 301 restored in this way can be further processed in the development system 300, just like the original source text 301 that already existed before encryption or decryption.

[0173] Figure 1 The encryption method shown and Figure 2 the decryption method shown can be executed or continued as frequently as desired during the development operation of the source text 301, for example, for a control program that describes an automated system. Each time a new version of the source text 301 is generated, for example, after completion of a partial development operation, a corresponding textual representation 305 can be generated according to the above encryption method, loaded into the corresponding version control system 315, and managed there.

[0174] To further continue the development operation, a previous version of the source text 301 managed in the version control system 315 or a textual representation 305 of any old version of the source text 301 can be decrypted by means of Figure 2 the decryption method described, and the underlying source text 301 can be restored according to the textual representation 305.

[0175] As described above, according to the method described in conjunction with Figure 1 it is also possible to encrypt only individual parts of the generated source text 301, such as individual sections or individual lines, and corresponding textual representations 305 can be generated and managed in the version control system 315. Similarly, individual sections or individual lines can also be decrypted by means of Figure 2 the decryption method described and restored in the form of the original source text.

[0176] Thus, the version control system used does not have to manage the complete source code at every change, but it is sufficient to mainly manage the newly changed parts of the source code. In particular, developers can only retrieve the parts of the encrypted source text that they are interested in from the version control system for further processing.

[0177] Line-by-line encryption of the source text 301 enables the source text 301 or the encrypted source text version 303 to be divided into arbitrarily small parts, down to individual lines, thus enabling simpler processing.

[0178] Figure 2 It is also shown how the source text 301 restored by decryption is further developed and completed in the development system 300.

[0179] It is also shown how, in an installation operation 324, the completed source text 301, which represents, for example, a control program of an automated system 317, is installed on the control unit 319 of the automated system 317. For this purpose Figure 2 a corresponding automated system 317 with a control unit 319 and a plurality of sensor / actuator units 321 is shown.

[0180] In addition to the control program for the automated system 317 Figure 1 and Figure 2The method for encrypting or decrypting the source text 301 described can be used for any desired source text. The described encryption and decryption methods are equally applicable to any programming language.

[0181] The method according to the invention is preferably applied to the programming languages of the standard DIN 61131.

[0182] The method according to the invention can in particular be applied to the source code 301 written in a graphical programming language. For this purpose, the graphical source code of the graphical programming language is stored in a text representation. According to the above in connection with Figure 1 and Figure 2 the described encryption method and decryption method of the operations can be applied to this text representation.

[0183] Figure 3 The flowchart of a method 100 for encrypting the source text 301 used in a version control system 315 according to an embodiment is shown.

[0184] In the shown embodiment, in order to encrypt the source text 301 used in the version control system 315, in the providing step 101, the source text 301 in unencrypted and text form is first provided. This can be achieved, for example, by a development or programming operation or by installing or loading the already programmed source text 301 into the corresponding development system 300.

[0185] In the encryption step 103, the encryption of the source text 301 is performed and an encrypted source text version 303 is generated. The encryption can be, for example, binary encryption, and the encrypted source text version 303 represents the unencrypted source text 301 in a binary encrypted representation. In this case, the encryption can be symmetric or asymmetric.

[0186] In the case of an asymmetric method, a key pair can be formed according to the encryption method, where, in each case, one key can reverse the transformation of the other key. Thus, encryption can be performed according to one key, while in each case, the other key is used for decryption.

[0187] The keys here are constructed in such a way that one key cannot be derived from the other key.

[0188] Generally, these two keys are referred to as the "public key" and the "private key". The public key is available to any communication partner who wants to create an encrypted message. On the other hand, the private key is private and is used to decrypt the encrypted message.

[0189] In particular, the encryption can be implemented in a unique and injective form, where the lines 313 of the source text 301 with the same content are encrypted into the same encrypted lines 309, while the lines 313 of the source text 301 with different content are encrypted into different encrypted lines 309.

[0190] According to one embodiment, encryption is performed line by line, where each line 313 of the source text 301 is encrypted as an independent object, and correspondingly, independent encrypted lines 309 of the encrypted source text version 303 are generated. In this case, the encrypted source text version 303 describes the entirety of the individual encrypted lines 309.

[0191] In the texturization step 105, texturization of the encrypted source text version 303 is performed, and a texturized representation 305 of the encrypted source text version 303 is generated. The texturized representation 305 describes the encrypted source text version 303 in text form. In this case, the content of the texturized representation 305 remains the encrypted content of the encrypted source text version 303.

[0192] According to one embodiment, texturization is performed line by line similar to encryption, and each encrypted line 309 is individually converted into a texturized line representation 311 by the performed texturization.

[0193] According to one embodiment, texturization is implemented as a unique and injective function that generates the same texturized line representation 311 for encrypted lines 309 having the same encrypted representation, and different texturized line representations 311 for encrypted lines 309 having different encrypted representations.

[0194] According to one embodiment, texturization can be implemented, for example, by the base64 algorithm.

[0195] The line order of the original source text 301 is maintained through encryption and texturization in the texturized representation 305. Thus, the texturized line representations 311 of the texturized representation 305 of the encrypted source text version 303 are arranged in the same arrangement or order as the original lines 313 of the original unencrypted source text 301.

[0196] Thus, the nth line 313 of the source text 301 results in a texturized line representation 311 of the texturized representation 305 of the encrypted source text version 303, which is in the nth position in the texturized representation 305. Thus, the texturized representation 305 describes the entirety of the texturized line representations 311.

[0197] Figure 4 Another flowchart of a method 100 for encrypting the source text 301 used in a version control system 315 according to another embodiment is shown.

[0198] Figure 4 The embodiment in... is based on Figure 3 the embodiment in... and includes all the method steps described therein.

[0199] Alternatively, in the illustrated embodiment, in the line separation step 107, the individual lines 313 of the original source text 301 are split. This results in separated lines 307 corresponding to the respective lines 313 of the original source text 301 and are treated as separate objects.

[0200] In the illustrated embodiment, encryption is performed line by line in the encryption step 103.

[0201] To this end, encryption of each separated line 307 is implemented in the line encryption step 109, and a corresponding encrypted line 309 is generated for each separated line 307. The encrypted lines 309 are again treated as independent objects.

[0202] In the illustrated embodiment, the texturization step 105 is also performed line by line.

[0203] To this end, texturization of each encrypted line 309 is performed in the line texturization step 111, and a corresponding texturized line representation 311 is generated for each encrypted line 309.

[0204] In the line merging step 113, the individual texturized line representations 311 are merged and combined in the texturized representation 305 of the encrypted source text version 303.

[0205] As described above, the line order of the original source text 301 is preserved such that the texturized representation 305 represents the encryption of the original source text 301 in text form, wherein the original structure of the original source text 301 is retained.

[0206] Figure 5 A flowchart of a method 200 for decrypting the source text 301 according to an embodiment is shown.

[0207] To decrypt the source text encrypted according to the method 100 for encrypting the source text 301, first, separation of the texturized line representations 311 of the texturized representation 305 of the encrypted source text version 303 is performed in another line separation step 201.

[0208] In the detexturization step 203, the individual separated texturized line representations 311 are detexturized separately, and on this basis, the corresponding encrypted lines 309 that initially generated the texturized line representations 311 are restored by line-by-line texturization.

[0209] In the decryption step 205, each encrypted line 309 is decrypted line by line, and the original separated lines 307 on which the encrypted lines 309 were generated by performing line-by-line encryption are restored.

[0210] Similar to the encrypted texturization in method 100, the line order of each representation or version is retained during detexturization and decryption, respectively.

[0211] In a further line merging step 207, the recovered separated lines 307 are merged and incorporated into the recovered original source text 301. In this way, the original source text 301 is recovered, on the basis of which a corresponding textualized representation 305 of the encrypted source text version 303 is generated by executing the encryption method 100 according to the invention.

[0212] Due to the uniqueness of encryption and textualization, the restored source text 301 corresponds to the original source text 301 without exception.

[0213] List of Reference Numerals

[0214] 100 Methods

[0215] 101 Provide Steps

[0216] 103 Encryption Steps

[0217] 105 Textualization Steps

[0218] 107 rows of separation steps

[0219] 109 lines of encryption steps

[0220] 111 lines of text steps

[0221] 113 rows merge step

[0222] 200 Methods

[0223] 201 Another line separation step

[0224] 203 De-textualization Steps

[0225] 205 Decryption Steps

[0226] 207 Another line merge step

[0227] 300 Development System

[0228] 301 Source Text

[0229] 302 Provide Operation

[0230] 303 Encrypted source text version

[0231] 304 Line separation operation

[0232] 305 Textual Representation

[0233] 306 Cryptographic Operations

[0234] 307 Separation Line

[0235] 308 Text Operation

[0236] 309 Encryption Line

[0237] 310 line merge operation

[0238] 311 text line representation

[0239] 312 storage operation

[0240] 313 line

[0241] 314 loading operation

[0242] 315 version control system

[0243] 316 another line separation operation

[0244] 317 automation system

[0245] 318 detextualization operation

[0246] 319 control unit

[0247] 320 decryption operation

[0248] 321 sensor / actuator unit

[0249] 322 another line merge operation

[0250] 323 first key

[0251] 324 installation operation

[0252] 325 second key.

Claims

1. A method (100) for encrypting source text (301) used in a version control system (315), comprising: Providing the source text (301) in an unencrypted and text form in a providing step (101); Performing encryption of the source text (301) and generating an encrypted source text version (303) in an encryption step (103); and Performing texturization of the encrypted source text version (303) and generating a texturized representation (305) of the encrypted source text version (303) in a texturization step (105).

2. The method (100) according to claim 1, wherein The encryption and / or the texturization are performed line by line, and wherein the line order of the unencrypted source text (301) is retained in the encrypted source text version (303) and / or the texturized representation (305) of the encrypted source text version (303).

3. The method (100) according to claim 1 or 2, further comprising: Performing line separation of the source text (301) and generating separated lines (307) of the source text (301) in a line separation step (107); wherein the encryption step (103) is performed on the separated lines (307) of the source text (301), and for each separated line (307), comprises: Performing encryption of the separated line (307) and generating an encrypted line (309) of the encrypted source text version (303) in a line encryption step (109).

4. The method (100) according to claim 3, wherein, The texturization step (105) is performed on the encrypted lines (309) of the encrypted source text version (303), and for each encrypted line (309) comprises: Performing texturization of the encrypted line (309) of the encrypted source text version (303) and generating a texturized line representation (311) of the encrypted line (309) of the encrypted source text version (303) in a line texturization step (111).

5. The method (100) according to claim 4, wherein, The texturization step (105) further comprises: Merging multiple texturized line representations (311) of the encrypted lines (309) of the encrypted source text version (303) and generating the texturized representation (305) of the encrypted source text version (303) as a whole of the texturized line representations (311) in a line merging step (113).

6. The method (100) according to any one of the preceding claims, wherein, The encryption is configured to be decryptable encryption, and wherein the encrypted source text version (303) can be uniquely traced back to the unencrypted source text (301) by applying an appropriate key to the encrypted source text version (303).

7. The method (100) according to any one of the preceding claims, wherein, The encryption is configured to be symmetric encryption.

8. The method (100) according to any one of the preceding claims, wherein, The encryption is configured to be asymmetric encryption.

9. The method (100) according to any one of the preceding claims, wherein, The texturization is configured to be uniquely reversible texturization, and wherein the texturized representation (305) of the encrypted source text version (303) can be uniquely converted into the encrypted source text version (303) by reversing the texturization in a de-texturized form.

10. The method (100) according to any one of the preceding claims, wherein, The encryption is unique encryption, which results in the same encrypted line (309) in the case of lines (313) of the source text (301) having the same content, and results in different encrypted lines (309) in the case of lines (313) of the source text (301) having different content, and / or, wherein, the texturization is unique texturization, which results in the same texturized line representation (311) in the case of encrypted lines (309) having the same encryption, and results in different texturized line representations (311) of the encrypted lines (309) in the case of encrypted lines (309) having different encryption.

11. The method (100) according to any one of the preceding claims, wherein, The encryption is binary encryption.

12. The method (100) according to any one of the preceding claims, wherein, The texturization of the encrypted source text version (303) is implemented by a base64 texturization algorithm.

13. The method (100) according to any one of the preceding claims, wherein, The source text (301) defines a control program for an automated system.

14. A method (200) for decrypting a source text (301) encrypted by a method (100) for encrypting a source text (301) according to any one of the preceding claims 1 to 13, comprising: Performing line separation of the texturized representation (305) of the encrypted source text version (303), and generating a separated texturized line representation (311) of the encrypted lines (309) of the encrypted source text version (303) in another line separation step (201); Performing de-texturization on each texturized line representation (311) of the encrypted lines (309) of the encrypted source text version (303) in a de-texturization step (203); Performing decryption on the encrypted lines (309) of the encrypted source text version (303), and generating unencrypted lines (313) of the source text (301) in a decryption step (205); and Merging the unencrypted lines (313) of the source text (301), and generating a visible representation of the source text (301) in another line merging step (207).

15. A development system (300) for developing and / or processing a source text (301), wherein, The development system (300) is arranged to execute the method (100) for encrypting a source text (301) used (315) in a version control system according to any one of the preceding claims 1 to 13 and / or the method (200) for decrypting a source text (301) according to claim 14.