Method and system for creating tamper-resistant operation datasets
By introducing cryptographic components into the display device to compile and encrypt the operation dataset, the problems of error-prone information presentation and insufficient security in the graphical user interface are solved. The operation dataset with anti-tamper protection and high security standards is achieved and is suitable for functionally safe HMI systems.
Patent Information
- Application Number
- CN202380097162.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-14
- Publication Date
- 2025-11-11
AI Technical Summary
Existing technologies have problems with information presentation errors in graphical user interfaces, especially in terms of insufficient security due to defects or software errors in hardware and software, making it difficult to achieve tamper-proof archiving and secure export of operation datasets.
By introducing cryptographic components into the display device, input data, output data, and comparison data are compiled into an operational dataset, and tamper-proof protection is provided through cryptographic components, including cryptographic signatures and hash algorithms, to ensure the integrity and security of the dataset.
It achieves tamper-proof protection for data operation in the graphical user interface, improves security, reduces operator burden, ensures long-term data accessibility and high security standards, and is suitable for functionally safe HMI systems.
Smart Images

Figure CN120937009A_ABST
Abstract
Description
Technical Field
[0001] In summary, the present invention relates to graphical user interfaces (GUIs) in applications where safety is critical in the sense of hazard-related, operational safety, or functional safety. Background Technology
[0002] Specifically, the present invention relates to a monitoring unit for securely presenting image data via a presentation computing unit (particularly an image computing unit) that will be classified as unsafe. The presentation of information in computer graphics form is prone to errors. For example, errors can occur in each individual component of the graphics generation computing unit, particularly the image computing unit, due to faulty microprocessors, graphics processors, individual storage modules, power supplies, but especially due to software errors in the operating system, libraries used in the software production process, particularly in application software or other software components that generate GUIs. Based on the principles of the applicant's WO 2011 / 003872 A1 or patent EP 2353089 B1 or patent EP3712770 B1 or first application EP 2273369 A1 or EP 2551787 B1, the technology for presenting security-related information under the trademarks IconTrust® or SelectTrust® offers significant improvements. This technology allows for more secure presentation or input and is applicable, for example, to security levels SIL-2 or higher. A key advantage is that by equipping the hardware with a separate, security-certified monitoring module, virtually any type and complexity of hardware and software that would be classified as insecure (hereinafter referred to as insecure) in a security technology context can be used in a provably secure manner.
[0003] The first problem addressed by this invention is the provision of a further developed method based on the principles of WO 2011 / 003872 A1 or patent EP 2353089B1, specifically, the method allows for the secure and relevant export of manipulated datasets and allows for tamper-proof archiving and / or storage of manipulated datasets. Summary of the Invention
[0004] According to a first independent aspect, the present invention begins with a method for creating a tamper-proof operational dataset during operation of a display device, the method comprising: Input data is transmitted to the computing unit to generate presentable output data. The output data is transmitted to the inspection unit. The input data is transmitted to the inspection unit. The inspection unit generates comparison data by comparing the input data with the output data.
[0005] According to a first independent aspect of the invention, a method is proposed comprising: compiling data by cryptographic components to form an operational dataset, the operational dataset comprising at least two of three types of data, specifically input data, output data, and / or comparison data; and preventing tampering with the operational dataset by cryptographic components to provide a tamper-proof operational dataset.
[0006] The display device preferably includes at least one display unit, particularly at least one monitor and / or at least one touchscreen display. The display device preferably includes at least one computing unit, particularly an image computing unit. The display device preferably includes at least one additional computing unit, particularly a checking unit. The display device preferably includes at least one supplementary computing unit, particularly a dataset generator. The supplementary computing unit, particularly the dataset generator, preferably includes cryptographic components. The display device may include at least one auxiliary computing unit (particularly a secure computing unit), preferably a secure programmable controller (SPC). The auxiliary computing unit may be formed externally relative to the display device, particularly separately. The computing unit, the additional computing unit, and / or the supplementary computing unit may be at least partially formed as a single component, particularly on a common board, particularly on a circuit board. For example, the additional computing unit (particularly a checking unit) and the supplementary computing unit (particularly a dataset generator) may be formed as a single computing unit, particularly as a security system, preferably on a common board or circuit board, which is separately formed and / or arranged relative to the computing unit (particularly the image computing unit) and / or relative to the auxiliary computing unit as a separate component.
[0007] Preferably, in at least one method step, input data (particularly secure input data) is transmitted to a computing unit (particularly an image computing unit) to generate presentable output data. The input data is preferably configured in the form of process values. The input data is preferably generated by a secure computing unit (particularly a secure programmable controller (SPC), particularly an auxiliary computing unit). Preferably, in at least one method step, the computing unit (particularly an image computing unit) generates presentable output data (particularly image data, preferably for pixel-based rendering) from the input data. The computing unit is preferably connected to at least one display unit (e.g., a monitor) of a display device, particularly for transmitting output data in the form of image data to the display unit. The computing unit particularly includes a processor and / or processor unit, a memory unit, and may include operating, control, and / or computing programs stored in memory. The computing unit (particularly an image computing unit) preferably includes at least one GPU as a processor. The display device preferably includes at least one recovery unit, which is preferably configured as a computing unit and designed to determine process values via fingerprint data based on the output data (particularly image data) generated by the image computing unit. For example, the recovery unit may be formed as part of another computing unit (particularly a checking unit). For example, the recovery unit can be formed as part of a computing unit (particularly an image computing unit). The recovery unit is preferably designed to convert output data in the form of image data (particularly video data) into fingerprint data and / or at least one process value. The fingerprint data can, for example, be configured as hash data. For example, the recovery unit can be formed as a component separate from or distinct from the inspection unit and / or the image computing unit and / or the dataset generator (particularly non-destructively spatially separated).
[0008] Preferably, in at least one method step, output data is transmitted from the computing unit (preferably from the image computing unit) to the inspection unit, for example, in the form of process values recovered from the output data (preferably in the form of image data). Preferably, in at least one method step, output data is transmitted from the image computing unit or the recovery unit to the dataset generator, for example, in the form of process values recovered from the output data, or in the form of fingerprint data recovered from the output data, or, for example, in the form of image data.
[0009] Preferably, in at least one method step, input data (especially security input data) is directly transmitted from the auxiliary computing unit (preferably a security computing unit, especially a security programmable controller (SPC)) to the inspection unit.
[0010] The checking unit preferably includes a comparison component for comparing input data with output data. Preferably, in at least one method step, the checking unit generates comparison data from the comparison of input data and output data, particularly for the purpose of initiating a safety-oriented response. The additional computing unit (particularly the checking unit) is preferably designed such that, in the presence of at least some irregularity in the comparison data, the checking unit initiates a safety-oriented response, such as a restart. Preferably, in at least one method step, the comparison data is transferred from the additional computing unit (particularly the checking unit) to an additional computing unit (particularly a dataset generator). Preferably, in at least one method step, the additional computing unit (particularly the dataset generator) compiles an operational dataset having operational data associated with the display device. Preferably, in at least one method step, the additional computing unit (particularly the dataset generator) preferably compiles multiple operational datasets associated with the display device at periodic time intervals relative to each other.
[0011] Each operational dataset preferably includes the same data input fields. Preferably, each operational dataset includes at least input data and output data, at least comparison data and output data, and / or input data and comparison data. Each operational dataset may include signature data specifically created from all data in a particular operational dataset (e.g., from input data, output data, and / or comparison data) using a hash algorithm.
[0012] Additional computing units (particularly dataset generators, such as cryptographic components) preferably have a data backup interface designed to output at least one operational dataset. The data backup interface can be configured as a wireless interface, particularly for wireless data transmission.
[0013] Each computing unit may be or include one or more configurable logic units or one or more programmable computer components, such as FPGAs, ASICs, and / or microcontrollers. Implementations of logically separated computing components via common hardware, particularly within an integrated circuit, also fall within the scope of this invention.
[0014] The dataset generator can be connected to the secure computing unit via a connection located outside the image computing unit for the transmission of input data.
[0015] Preferably, in at least one method step, tamper-proof protection (e.g., cryptographic signature) is applied to at least one operational dataset. Specifically, tamper-proof protection will be understood to mean relative tamper-proof protection that can be used to enable the dataset to be inspected for tampering, wherein, in particular, tamper-proof protection does not preclude tampering with the data.
[0016] In at least one method step, at least one operational dataset may be at least partially encrypted to provide tamper-proof protection for the operational dataset. In at least one method step, signature data (e.g., hash data) may be formed from other data in at least one operational dataset. In at least one method step, signature data may be encrypted to provide tamper-proof protection for the operational dataset. In at least one method step, signature data (e.g., hash data) may be formed using a hash algorithm. Preferably, for example, in at least one method step, a digital signature (preferably an encrypted signature) is created for at least one operational dataset and appended to a corresponding at least one unencrypted operational dataset to provide tamper-proof protection for the operational dataset.
[0017] The cryptographic component is preferably configured as a secure element IC or a secure coprocessor IC, where IC specifically represents an integrated circuit.
[0018] By means of embodiments of the method according to the invention, advantageous data provision can be achieved, which is particularly suitable for making operational data accessible for extended periods. High security standards can be advantageously achieved. Advantageous tamper-proof protection of operational datasets can be achieved. In particular, advantageous authentication documentation of processes during operation of the display device can be achieved. In particular, the method can lead to a more secure HMI and can advantageously reduce the operator's burden regarding communication and documentation. In particular, further advantages are possible at the system level through the resulting risk reduction and / or authenticated documentation.
[0019] It also proposes that image data include video data. It is possible to achieve favorable multi-compatible file formats for archiving.
[0020] It is also proposed to transmit output data to the cryptographic component in the form of image data. The computing unit (especially the image computing unit) is preferably directly connected to the dataset generator (especially the cryptographic component) for data transmission. Preferably, in at least one method step, image data is transmitted from the computing unit (especially the image computing unit) to the dataset generator. Preferably, in at least one method step, image data is incorporated as output data into the operational dataset. Therefore, advantageous and uncomplicated reconstruction of the operation of the display device can be achieved using the output data in the operational dataset. It is advantageously possible to avoid checking the table used to convert fingerprint data into process values.
[0021] It is also proposed that output data be transmitted to the cryptographic component in the form of fingerprint data generated from image data by a computing unit (particularly the aforementioned computing unit) and / or another computing unit (particularly the aforementioned other computing unit, preferably the recovery unit). The computing unit (particularly the image computing unit) and / or another computing unit (particularly the inspection unit) and / or preferably the recovery unit are preferably directly connected to the dataset generator (particularly the cryptographic component) for data transmission. Preferably, in at least one method step, output data in the form of fingerprint data is sent from the computing unit (particularly the image computing unit) and / or another computing unit (particularly the inspection unit) and / or preferably the recovery unit to the dataset generator (particularly the cryptographic component). Preferably, in at least one method step, output data in the form of image data is converted into fingerprint data, preferably by the computing unit (particularly the image computing unit) and / or another computing unit (particularly the inspection unit), preferably by the recovery unit. Preferably, in at least one method step, fingerprint data is incorporated as output data into the operational dataset. This allows for an advantageous reduction in the amount of output data in the operational dataset. It also advantageously avoids checking the table used to convert fingerprint data into process values.
[0022] It is also proposed that the output data be transmitted to the cryptographic component in the form of process values generated from the image data by a computing unit (in particular the aforementioned computing unit) and / or another computing unit (in particular the aforementioned other computing unit) (particularly preferably via a recovery unit). Preferably, in at least one method step, the output data is sent from another computing unit (in particular a checking unit, preferably a recovery unit, particularly as part of the checking unit) to a dataset generator (in particular the cryptographic component).
[0023] Preferably, in at least one method step, the output data in the form of image data is converted into fingerprint data and / or process values by a computing unit and / or another computing unit (particularly preferably by a recovery unit). Preferably, in at least one method step, at least one process value is incorporated as output data into the operational dataset. This allows for an advantageous reduction in the amount of output data in the operational dataset.
[0024] It is also proposed that, during the compilation of the operational dataset, all three data sets (specifically, comparison data, output data, and input data) are incorporated into the operational dataset. Each operational dataset particularly preferably includes input data, output data, and comparison data. More preferably, in at least one method step, at least the input data, output data, and comparison data are combined to form the operational dataset. Advantageous comprehensive operational datasets can be created.
[0025] The second problem addressed by this invention is a method further developed based on the principles of patent EP 2551787 B1, which in particular allows for the secure-related export of the input dataset and the tamper-proof archiving and / or storage of the input dataset.
[0026] According to a second independent aspect, the present invention begins with a method for creating a tamper-proof operational input dataset during operation of a display device having a display unit and input units arranged on the display unit, the method comprising: Input data is transmitted to the computing unit (especially the image computing unit) in order to generate presentable output data. The presentable output data is transmitted to the inspection unit. Input data is captured by reading the input unit and using the input data at the input unit (e.g., touch input). The input data is transmitted to the inspection unit. Input validation data is generated by merging at least the input data and the output data through the inspection unit.
[0027] According to a second independent aspect of the present invention, a method comprising: Data is merged using cryptographic components to form an operational input dataset from input validation data and input data, and By using cryptographic components to prevent tampering with the operational input dataset, a tamper-proof operational input dataset can be provided.
[0028] The display device preferably includes at least one touchscreen display. Preferably, the at least one touchscreen display is formed by a display unit and an input unit arranged on the display unit. Alternatively or additionally, the input unit may be or include a mouse, keyboard, console, etc. The display unit is preferably a monitor. The display device preferably includes at least one computing unit, particularly an image computing unit. The display device preferably includes at least one additional computing unit, particularly an inspection unit. The display device preferably includes at least one recovery unit, which is preferably configured as a computing unit and designed to determine process values via fingerprint data based on output data (particularly image data) generated by the image computing unit. For example, the recovery unit may be formed as part of another computing unit (particularly an inspection unit). For example, the recovery unit may be formed as part of a computing unit (particularly an image computing unit). The recovery unit is preferably designed to recover from the output data process values related to the verification of the displayed output data using input data, specifically relating to the inspection of work performed by the image computing unit. The recovery unit is preferably designed to convert output data in the form of image data (particularly video data) into fingerprint data and / or at least one process value. The fingerprint data may, for example, be configured as hash data. For example, the recovery unit can be configured as a component that is separate from or different (particularly spatially separated) from the inspection unit and / or image computing unit and / or dataset generator.
[0029] The display device preferably includes at least one additional computing unit, particularly a dataset generator. The additional computing unit (particularly the dataset generator) preferably includes cryptographic components.
[0030] The display device may include at least one auxiliary computing unit (particularly a security computing unit), preferably a security programmable controller (SPC). The computing unit, additional computing units, and / or supplementary computing units may be at least partially formed as a single component, particularly on a common board, especially on a circuit board. For example, additional computing units (particularly inspection units) and supplementary computing units (particularly dataset generators) may be formed as a single computing unit (particularly as a security system), preferably on a common board or circuit board, which is preferably formed and / or arranged as a separate component relative to the computing unit (particularly the image computing unit), wherein, in particular, the recovery unit is formed as part of the inspection unit.
[0031] Preferably, in at least one method step, input data (particularly secure input data) is transmitted to a computing unit (particularly an image computing unit) to generate presentable output data. The input data is preferably configured in the form of process values. The input data is preferably generated by a secure computing unit (particularly a secure programmable controller (SPC), particularly an auxiliary computing unit). Preferably, in at least one method step, the computing unit (particularly an image computing unit) generates presentable output data (particularly image data) from the input data, preferably for pixel-based rendering. The computing unit (particularly an image computing unit) is preferably connected to at least one display unit of a display device, particularly for transmitting the output data to the display unit.
[0032] Preferably, in at least one method step, output data is transmitted from a computing unit (preferably from an image computing unit) to an inspection unit, for example, in the form of image data. For example, in at least one method step, output data is transmitted from a recovery unit (preferably as part of an image computing unit) to an inspection unit, for example, in the form of image data and process values recovered from the output data. For example, in at least one method step, output data is transmitted from a recovery unit (preferably as part of an image computing unit) to an inspection unit, for example, in the form of image data and fingerprint data recovered from the output data.
[0033] In at least one method step, input data (particularly security input data) can be directly transferred from an auxiliary computing unit (preferably a security computing unit, particularly a security programmable controller (SPC)) to an inspection unit. Preferably, in at least one method step, the input data is captured by an input unit. Preferably, in at least one method step, the input data is transferred to an inspection unit. Preferably, in at least one method step, the input data is transferred to a dataset generator. The inspection unit preferably includes a comparison component for comparing the input data with the output data. Preferably, in at least one method step, the inspection unit generates comparison data from the comparison of the input data and the output data, particularly for the purpose of initiating a security-guided response. An additional computing unit (particularly the inspection unit) is preferably designed such that, in the event of at least some irregularity in the comparison data, the inspection unit initiates a security-guided response, such as restarting at least a portion of the display device. Preferably, in at least one method step, the comparison data is transferred from another computing unit (particularly the inspection unit) to an additional computing unit (particularly the dataset generator). In particular, the second aspect of the invention can supplement the first aspect of the invention.
[0034] Preferably, the checking unit includes the aforementioned comparison component for merging at least the input data and output data. Preferably, in at least one method step, the checking unit (in particular the comparison component) generates input verification data by merging at least the input data and output data. The input verification data can be understood, for example, as data about which icon on the presented display was clicked. Preferably, in at least one method step, the input verification data is preferably transferred in the form of a process value from another computing unit (in particular the checking unit) to an additional computing unit (in particular a dataset generator).
[0035] Preferably, in at least one method step, an additional computing unit (in particular a dataset generator) compiles an operational input dataset using operational input data (in particular additional operational data) associated with the display device. Preferably, in at least one method step, the additional computing unit (in particular a dataset generator) preferably compiles multiple operational input datasets associated with the display device at periodic time intervals each time input is captured and / or relative to each other. Each operational input dataset preferably includes the same data input fields.
[0036] Additional computing units (particularly dataset generators, such as cryptographic components) preferably have a data backup interface designed to output at least one operational input dataset. The data backup interface can be configured as a wireless interface, particularly for wireless data transmission.
[0037] The dataset generator can be connected to the secure computing unit via a connection arranged outside the image computing unit for the transmission of input data. The dataset generator can be connected to the secure computing unit via the image computing unit for the transmission of input data. The dataset generator can be connected to the input unit via a connection arranged outside the image computing unit for the transmission of input data. The dataset generator can be connected to the input unit via the image computing unit for the transmission of input data.
[0038] The cryptographic component is preferably configured as a secure element IC, a secure coprocessor IC, or some other suitable integrated circuit (IC) with encryption or cryptographic signature capabilities. Statements regarding granting tamper-proof protection to the operational dataset will be specifically understood to mean that the operational dataset is at least partially encrypted, or that at least one encrypted portion (particularly a cryptographic signature) is appended to the operational dataset. Preferably, in at least one method step, at least one operational input dataset is at least partially encrypted and / or has a cryptographic signature applied to it to achieve tamper-proof protection for the operational input dataset. Preferably, in at least one method step, tamper-proof protection, such as a cryptographic signature, is granted to at least one operational input dataset. In at least one method step, at least one operational input dataset may be at least partially encrypted to achieve tamper-proof protection for the operational input dataset. In at least one method step, signature data (e.g., hash data) may be formed from other data in at least one operational input dataset. In at least one method step, signature data of the operational input dataset may be encrypted to achieve tamper-proof protection for the operational input dataset. In at least one method step, signature data (e.g., hash data) may be formed using a hash algorithm. Preferably, for example, in at least one method step, a digital signature (preferably an encrypted signature) is created for at least one operational input dataset and attached to the corresponding at least one unencrypted operational input dataset to achieve tamper-proof protection for the operational input dataset.
[0039] By means of embodiments of the method according to the invention, advantageous data provision can be achieved, which is particularly suitable for making operational input data accessible for extended periods. High security standards can be advantageously achieved. Advantageous tamper-proof protection of operational input datasets can be achieved, particularly by making them tamper-proof. In particular, advantageous authentication documentation of processes during operation of the display device can be achieved. In particular, the method can lead to a more secure HMI and can advantageously reduce the operator's burden regarding communication and documentation. In particular, further advantages are possible at the system level through the resulting risk reduction and / or authentication documentation.
[0040] It is also proposed that, during the compilation of the operational input dataset, additional input data and / or output data be incorporated. Preferably, in at least one method step, input data and / or output data are merged into at least one operational input dataset by means of an additional computing unit (particularly by a dataset generator). Preferably, in at least one method step, output data is incorporated into at least one operational input dataset, specifically in the data form described with respect to the first aspect of the invention, by means of an additional computing unit (particularly by a dataset generator). Advantageously, a comprehensive operational input dataset can be achieved.
[0041] It is also proposed that, during the compilation of the operational input dataset, comparison data created by comparing the input and output data through a checking unit be additionally incorporated. This allows for advantageously comprehensive operational datasets while simultaneously saving memory.
[0042] It is also proposed that, during the creation of the operational dataset or operational input dataset, index data (preferably timestamp data, count data, and / or reference data) be additionally incorporated into the operational dataset or operational input dataset. Preferably, in at least one method step, index data in the form of timestamps, sequential numbers, and / or some other reference information item is incorporated into the operational dataset or operational input dataset. Preferably, each operational input dataset includes input data and input validation data, and preferably includes index data. Each operational input dataset may additionally include output data, input data, and / or comparison data. Advantageously, the checkable integrity of the operational dataset and / or operational input dataset can be achieved.
[0043] It is also proposed to perform tamper-proofing on the operational dataset or operational input dataset through asymmetric encryption (especially using elliptic curve cryptography (ECC) or Rivest-Shamir-Adleman (RSA) encryption algorithms). For example, tamper-proofing of signature data is preferably implemented using a private key. Tamper-proofing of the operational dataset or operational input dataset can be achieved, in particular, through cryptographic signatures on other unencrypted operational datasets. This provides favorable tamper-proofing protection for the data.
[0044] The method also proposes storing tamper-proof operation datasets or tamper-proof operation input datasets. Preferably, in at least one method step, at least partially encrypted and / or encrypted signed operation datasets and / or at least partially encrypted and / or encrypted signed operation input datasets are stored on a recorder unit. This enables advantageous archiving of the operation parameters of the display device.
[0045] Furthermore, it is proposed that the method be at least partially repeated. The entire method is preferably repeated at periodic time intervals, such as 10s, 5s, 1s, etc. Preferably, the entire method is fully executed whenever user-specific input is captured. This allows for advantageous, uninterrupted, and particularly memory-saving archiving of the display device's operating parameters.
[0046] A dataset generator with a cryptographic component is also proposed. The cryptographic component is designed to create operation datasets and / or operation input datasets from operations of a display device, and is designed to provide tamper-proof protection to the operation datasets and / or operation input datasets. Advantageous functional extensions can be achieved for existing display devices.
[0047] A security system with a dataset generator according to the invention is also proposed. The proposed security system includes a checking unit designed to generate input validation data by merging at least input data and output data, and / or to generate comparison data from a comparison of the input data and the output data. The security system preferably includes a dataset generator and a checking unit, particularly as a component, for example, on a common board. Advantageous and extensive functional expansion is possible for existing display devices.
[0048] A security system including a recorder unit is also proposed, designed to store operation datasets and / or operation input datasets. The recorder unit is preferably configured as a memory chip, hard disk, server, etc. The recorder unit can be formed separately from the dataset generator. Alternatively, the recorder unit can be formed externally (particularly separately) relative to the security system (particularly the display device). Advantageous data extraction with archiving capabilities can be achieved.
[0049] A security system including a data backup interface is also proposed, designed to output operational datasets and / or operational input datasets. The data backup interface is preferably configured as a wireless interface for data transmission to the recorder unit. Specifically, cryptographic components can be wirelessly connected to the recorder unit via the data backup interface. This enables advantageous data transmission.
[0050] A display device with a security system according to the invention is also proposed. This allows for the achievement of advantageous security standards for the display device.
[0051] An operator control terminal with a display according to the invention is also proposed. The operator control terminal can be configured for machine control. The operator control terminal can be directly mounted on the machine, particularly on the machine terminal. The operator control terminal can be configured as a field terminal. The operator control terminal can be designed for placement in a factory lobby, or, for example, at a loading platform. A recorder unit can be part of the operator control terminal, particularly disposed within it. An auxiliary computing unit can be part of the operator control terminal, particularly disposed within it. Alternatively, the recorder unit can be formed / distributed externally (particularly separately) relative to the operator control terminal. The auxiliary computing unit can also be formed / distributed externally (particularly separately) relative to the operator control terminal. Advantageous safety standards for the operator control terminal can be achieved.
[0052] A vehicle, particularly a rail vehicle, is also proposed according to the invention. The vehicle may be in the form of a passenger car, truck, helicopter, bus, construction site vehicle (e.g., excavator, roller, or bulldozer), aircraft, agricultural vehicle (e.g., tractor, combine harvester, etc.), or preferably a rail vehicle (e.g., motor vehicle or locomotive). Favorable safety standards for the vehicle can be achieved.
[0053] A signal box for controlling a railway system is also proposed, which has an operator control terminal according to the invention. Favorable safety standards for the signal box can be achieved.
[0054] A control station for process control in industrial plants is also proposed, which has an operator control terminal according to the invention. Favorable safety standards can be achieved for the control station.
[0055] The methods, dataset generators, security systems, display devices, operator control terminals, and / or vehicles, signal boxes, and / or control stations according to the present invention are not intended to be limited to the above-described uses and embodiments. In particular, to perform the functions described herein, the methods, dataset generators, security systems, display devices, operator control terminals, and / or vehicles, signal boxes, and / or control stations according to the present invention may have a different number of individual elements, components, units, and method steps than those described herein. Furthermore, where value ranges are stated in this disclosure, values within those ranges are also intended to be disclosed and used as needed. Attached Figure Description
[0056] Further advantages will become apparent from the following description of the accompanying drawings. The drawings illustrate four exemplary embodiments of the invention. The drawings, description, and claims, taken together, encompass numerous features. Those skilled in the art will readily consider the features individually and combine them to form meaningful further combinations. In the drawings: Figure 1 The schematic diagram illustrates a display device according to the present invention. Figure 2 The method according to the invention is illustrated in the schematic diagram. Figure 3 A second display device according to the present invention is shown in the schematic diagram. Figure 4 The second method according to the invention is shown in the schematic diagram. Figure 5 A third display device according to the present invention is shown in the schematic diagram. Figure 6The third method according to the invention is shown in the schematic diagram. Figure 7 The schematic diagram illustrates a fourth display device according to the present invention. Figure 8 The fourth method according to the present invention is shown in the schematic diagram. Detailed Implementation
[0057] Figure 1 The display device 10a is shown as having a method 100a designed to perform an operation dataset during operation of the display device 10a (see [link]). Figure 2 ).
[0058] In this example, the external computing unit 12a (specifically not part of the display device 10a) makes input data available. The external computing unit 12a is a secure computing unit 12a (specifically a secure programmable controller (SPC)) that makes input data available assuming the input data is "correct" for further processing. Specifically, the external secure computing unit 12a is designed to provide input data in the form of process values. Specifically, the external secure computing unit 12a has an input interface 18a that makes the input data available.
[0059] Display device 10a includes an image computing unit 14a, which is specifically a computing unit. An external secure computing unit 12a is connected to the image computing unit 14a via an input interface 18a. The image computing unit 14a includes a GPU as a processor.
[0060] Display device 10a includes display units, particularly display 16, specifically for pixel-based presentation. Image calculation unit 14a is designed to convert input data in the form of process values into output data in the form of image data, particularly for display 16a. Display 16a is designed to display the image data generated by image calculation unit 14a. The image data generated by image calculation unit 14a may contain errors.
[0061] Display device 10a has a check unit 20a, which is a separate computing unit. Image computing unit 14a is designed to transmit output data to check unit 20a. External security computing unit 12a is designed to send input data to check unit 20a. Specifically, check unit 20a is connected to image computing unit 14a for data transmission. Specifically, check unit 20a is connected to external security computing unit 12a for data transmission. Specifically, check unit 20a is a computing unit formed separately from image computing unit 14a and specifically arranged on a different board or circuit board. Check unit 20a is designed to generate comparison data, such as difference data, from a comparison of input data and output data. Check unit 20a has a comparison component 21a for comparing input data with output data. Check unit 20a is designed such that if at least irregularities exist in the comparison data, the check unit initiates a security-guided response, such as a restart.
[0062] The inspection unit 20a includes an image interface 22a connected to the image computing unit 14a. The inspection unit 20a also includes a dataset interface 24a.
[0063] Display device 10a has a recovery unit 29a, which is designed to convert output data in the form of image data into fingerprint data and / or process values. Recovery unit 29a has a first recovery component 26a, which is designed to convert output data in the form of image data into fingerprint data. Recovery unit 29a has a second recovery component 28a, which is designed to convert output data in the form of fingerprint data into process values. Recovery unit 29a is configured as a calculation unit. Recovery unit 29a is configured as part of inspection unit 20a. Recovery unit 29a (specifically the second recovery component 28a) is connected to comparison component 21a for data transmission.
[0064] The display device 10a has an additional computing unit, specifically a dataset generator 30a. The dataset generator 30a includes a cryptographic component 32a. In particular, the dataset generator 30a is a computing unit that is formed separately from the image computing unit 14a and is specifically arranged on a different board or circuit board. The cryptographic component 32a (specifically the entire dataset generator 30a) is configured, for example, as a secure element IC.
[0065] The dataset generator 30a is connected to the inspection unit 20a to transmit comparison data and to the recovery unit 29a to transmit the process values determined by the recovery unit 29a to the dataset generator 30a. For example, the inspection unit 20a and the dataset generator 30a are configured as a security system 40a on a common board or circuit board, specifically formed separately from the image calculation unit 14a. The recovery unit 29a (particularly the second recovery component 28a) is connected to the dataset generator 30a (particularly the cryptographic component 32a) for data transmission.
[0066] The dataset generator 30a has an index unit 34a. The index unit 34a is designed to provide and / or output index data, such as increment counter data, for each operational dataset. The dataset generator 30a is designed to compile at least one operational dataset having operational data associated with the display device 10a. The dataset generator 30a is designed to compile multiple operational datasets associated with the display device 10a at periodic time intervals relative to each other. Each operational dataset includes the same data input fields. The dataset generator 30a is connected to the secure computing unit 12a via a connection arranged outside the image computing unit 14a.
[0067] The dataset generator 30a includes, for example, a data backup interface 36a on the cryptographic component 32a, which is designed to provide at least one operational dataset. The data backup interface 36a is configured as a wireless interface, specifically for wireless data transmission.
[0068] The dataset generator 30a (specifically, the cryptographic component 32a) is designed to compile and manipulate datasets from input data, output data, comparison data, and index data. The dataset generator 30a (specifically, the cryptographic component 32a) is designed to create signature data related to the input data, output data, comparison data, and index data, for example, by applying a hash algorithm.
[0069] For example, in this case, the signature data is hash data relating to other data in the operational dataset. In this example, each operational dataset includes input data, output data, index data, comparison data, and signature data. The dataset generator 30a (specifically, the cryptographic component 32a) is designed to append cryptographic signatures to the operational dataset, specifically by encrypting the signature data. The dataset generator 30a (specifically, the cryptographic component 32a) is designed to at least partially encrypt the operational dataset by asymmetric encryption, specifically encrypting at least the signature data of the operational dataset.
[0070] Security system 40a includes a recorder unit 50a. Recorder unit 50a is designed to store created, cryptographically signed, and / or at least partially encrypted operational datasets. Recorder unit 50a is designed to obtain created, cryptographically signed, and / or at least partially encrypted operational datasets from dataset generator 30a (specifically cryptographic component 32a) via data backup interface 36a.
[0071] Figure 2 A method 100a for creating an operational dataset during operation of a display device 10a is illustrated schematically.
[0072] In one method step, particularly the input data step 102a, secure input data is transmitted to the image computing unit 14a to generate presentable output data. In another method step, particularly the input data step 102a, secure input data is transmitted directly from the secure computing unit 12a to the checking unit 20a (particularly the comparison component 21a). In yet another method step, particularly the input data step 102a, secure input data is transmitted directly from the secure computing unit 12a to the dataset generator 30a (particularly the cryptographic component 32a). The input data is configured in the form of process values. The input data is generated by the secure computing unit 12a.
[0073] In one method step, particularly generation step 104a, the image computing unit 14a generates presentable output data, particularly image data, from the input data.
[0074] In one method step, particularly in the output data step 106a, output data is transmitted from the image calculation unit 14a to the inspection unit 20a (particularly the comparison component 21a) via the recovery unit 29a. In another method step, particularly in the output data step 106a, output data is transmitted from the image calculation unit 14a to the display 16a.
[0075] In at least one method step, particularly in recovery step 108a, the output data is first converted into fingerprints by recovery unit 29a (particularly the first recovery component 26a and the second recovery component 28a), and then into recovered process values. In at least one method step, particularly recovery step 108a, the output data in the form of image data is converted into fingerprint data and / or process values, specifically by recovery unit 29a (particularly the first recovery component 26a and / or the additional recovery component 28a).
[0076] In one method step, particularly in transmission step 110a, output data is transmitted from recovery unit 29a (particularly the first recovery component 26a and the second recovery component 28a) to comparison component 21a of inspection unit 20a in the form of process values recovered from the output data. In one method step, particularly in transmission step 110a, output data is transmitted (particularly from the second recovery component 28a) to cryptographic component 32a in the form of process values generated from image data by recovery unit 29a (particularly from the second recovery component 28a). In at least one method step, particularly in transmission step 110a, output data is transmitted from inspection unit 20a to dataset generator 30a (particularly cryptographic component 32a). In one method step, particularly in transmission step 110a, index data (particularly from the index unit) is transmitted to dataset generator 30a (particularly to cryptographic component 32a).
[0077] In the three method steps (output data step 106a, recovery step 108a and transmission step 110a), the output data is transmitted from the image calculation unit 14a to the inspection unit 20a (specifically the comparison component 21a) in the form of process values recovered from the output data.
[0078] In one method step, particularly the data comparison step 112a, comparison data is generated by the inspection unit 20a (particularly the comparison component 32a) from a comparison of input and output data, specifically for the purpose of initiating a security-oriented response via the response unit 60a. The response unit 60a is part of the display device 10a. The response unit 60a is formed separately from the inspection unit and the data set generator 30a. Alternatively, the response unit 60a can also be readily formed as a component together with the inspection unit. In one method step, particularly the data comparison step 112a, comparison data is transferred from the inspection unit 20a (particularly from the comparison component 32a) to the data set generator 30a (particularly the cryptographic component 32a).
[0079] In one method step, specifically dataset step 114a, dataset generator 30a compiles an operational dataset using operational data related to display device 10a. In one method step, specifically dataset step 114a, during the compilation of the operational dataset, all three types of data—comparison data, output data, and input data—are merged into the operational dataset. In one method step, specifically dataset step 114a, output data is merged into the operational dataset in the form of process values. In one method step, specifically dataset step 114a, index data is merged into the operational dataset.
[0080] In one method step, particularly protection step 116a, the dataset generator 30a (particularly cryptographic component 32a) imparts tamper-proof protection to the operational dataset, for example, by encrypting a signature. In one method step, particularly protection step 116a, the dataset generator 30a (particularly cryptographic component 32a) forms signature data from other data in the operational dataset, for example, hash data. In one method step, particularly protection step 116a, the dataset generator 30a (particularly cryptographic component 32a) forms signature data using a hash algorithm, for example, as hash data. In one method step, particularly protection step 116a, the dataset generator 30a (particularly cryptographic component 32a) at least partially encrypts the operational dataset, particularly encrypting the signature data of the operational dataset, in order to achieve tamper-proof protection for the operational dataset, particularly to provide a tamper-proof operational dataset. In one method step, particularly protection step 116a, the signature data is encrypted to achieve tamper-proof protection for the operational dataset. In one method step, particularly protection step 116a, the signature data is formed using a hash algorithm, for example, hash data. In one method step, particularly protection step 116a, a digital signature (particularly an encrypted signature) is created for at least one operational dataset and appended to the corresponding unencrypted operational dataset to achieve tamper-proof protection of the operational dataset. In another method step, particularly protection step 116a, the signature data is created and / or encrypted using asymmetric encryption, in this case, for example, using an elliptic curve cryptography (ECC) algorithm or a Rivest-Shamir-Adleman (RSA) encryption algorithm.
[0081] In the repetitive method steps, particularly multiple dataset steps 114a, the dataset generator 30a compiles multiple operational datasets related to the display device 10a, especially relative to each other at periodic time intervals. Method 100a is preferably repeated at periodic time intervals, such as 10s, 5s, 1s, etc.
[0082] In one method step, particularly in recorder step 118a, an operational dataset that is at least partially encrypted and / or cryptographically signed is stored, specifically on recorder unit 50a.
[0083] The cryptographic component 32a is designed to create at least one operation dataset (in particular multiple operation datasets) and / or at least one operation input dataset (in particular multiple operation input datasets) through the operation of the display device 10a, and to provide tamper-proof protection (in particular cryptographic signature and / or at least partial encryption) to the operation dataset (in particular multiple operation datasets) and / or the operation input dataset (in particular multiple operation input datasets).
[0084] Security system 40a includes a dataset generator 30a. Security system 40a includes an inspection unit 20a. Inspection unit 20a is designed to generate comparison data from a comparison of input data and output data. Security system 40a includes a recorder unit 50a. Recorder unit 50a is designed to store operation datasets and / or operation input datasets.
[0085] The security system 40a includes a data backup interface 36a, which is designed to output the operational dataset to the recorder unit 50a.
[0086] Display device 10a includes a security system 40a. The security system 40a is designed to be separable from the display device 10a. Specifically, the security system 40a is configured, for example, as a card module, which can be traceably integrated into / coupled to an existing display device. Operator control terminal 70a includes the display device 10a. Operator control terminal 70a includes, for example, a security computing unit 12a. Operator control terminal 70a does not need to include a security computing unit 12a.
[0087] A vehicle (not shown) (particularly a rail vehicle) may include an operator control terminal 70a. A signal box (not shown) for controlling a railway system may include an operator control terminal 70a. A control station (not shown) for process control in an industrial plant may include an operator control terminal 70a. As an example, in this case, the vehicle includes an operator control terminal 70a having a display device 10a.
[0088] Figure 3 , Figure 4 , Figure 5 , Figure 6 , Figure 7 and Figure 8 Further exemplary embodiments of the invention are shown. The following description and drawings are essentially limited to the differences between the exemplary embodiments, wherein, with respect to the same specified components, particularly those having the same reference numerals, reference may also be made in principle to the drawings (especially the accompanying drawings). Figures 1 to 2 And / or descriptions of other exemplary embodiments. For distinction between exemplary embodiments, the letter character 'a' has been appended as a suffix. Figure 1 Reference numerals in the exemplary embodiments shown in Figures… Figures 3 to 8 In an exemplary embodiment, the letter character 'a' has been replaced by letter characters 'b' through 'd'.
[0089] Figure 3 An alternative display device 10b is shown. Figure 3Recorder unit 50b is specifically shown. Recorder unit 50b is designed to store created, cryptographically signed, and / or at least partially encrypted operational datasets. Recorder unit 50b is externally formed and arranged relative to security system 40b. Recorder unit 50b is externally formed and arranged relative to operator control terminal 70b.
[0090] Data set generator 30b is connected to inspection unit 20b to transmit comparison data. Data set generator 30b (particularly password component 32b) is directly connected to recovery unit 29b (particularly first recovery component 26b) for transmitting fingerprint data determined from output data in the form of image data. Specifically, recovery unit 29b (particularly inspection unit 20b) is directly connected to data set generator 30b (particularly password component 32b) for data transmission.
[0091] In this example, the inspection unit 20b and the dataset generator 30b form a public safety system 40b, wherein the inspection unit 20b and the dataset generator 30b are formed as different (particularly complementary) modules on different boards or circuit boards (which are formed independently of the image computing unit 14b).
[0092] A vehicle (not shown) (particularly a rail vehicle) may include an operator control terminal 70b. A signal box (not shown) for controlling a railway system may include an operator control terminal 70b. A control station (not shown) for process control in an industrial plant may include an operator control terminal 70b. For example, in this case, the signal box includes an operator control terminal 70b with a display device 10b.
[0093] Figure 4 A method 100b for creating an operational dataset during operation of a display device 10b is illustrated schematically.
[0094] The difference between method 100b and method 100a of the first example lies in the method steps, particularly the transmission step 110b, in which the output data is not transmitted to the dataset generator 30b (particularly the password component 32b) in the form of process values generated from the image data by the recovery unit 29b, but rather in the form of fingerprint data generated from the image data by the first recovery component 26b.
[0095] In the three method steps, namely the output data step 106b, the recovery step 108b, and the transmission step 110b, the output data is transmitted from the image computing unit 14b to the comparison component 21b in the form of fingerprint data recovered from the output data. In one method step, particularly the transmission step 110b, the output data is transmitted to the cryptographic component 32b in the form of fingerprint data generated from the image data by the recovery unit 29b (particularly the first recovery component 26b).
[0096] In one method step, particularly in the transmission step 110b, output data is transmitted from the computing unit (particularly the image computing unit 14b) to the dataset generator 30b (particularly to the cryptographic component 32b) via the recovery unit 29b.
[0097] In one method step, specifically dataset step 114b, fingerprint data is incorporated as output data into the operational dataset.
[0098] Figure 5 An alternative display device 10c is shown. A dataset generator 30c is connected to the inspection unit 20c to transmit comparison data. The dataset generator 30c (particularly the cryptographic component 32c) is directly connected to the image calculation unit 14b for transmitting output data in the form of image data. Specifically, the recovery unit 29c (particularly the first recovery component 26c and / or the second recovery component 28c) is not directly connected to the dataset generator 30c (particularly the cryptographic component 32c). The image calculation unit 14c is directly connected to the dataset generator 30c (particularly the cryptographic component 32c) for transmitting output data in the form of image data.
[0099] A vehicle (not shown) (particularly a rail vehicle) may include an operator control terminal 70c. A signal box (not shown) for controlling a railway system may include an operator control terminal 70c. A control station (not shown) for process control in an industrial plant may include an operator control terminal 70c. As an example, in this case, the control station includes an operator control terminal 70c having a display device 10c.
[0100] Figure 6 A method 100c for creating an operational dataset during operation of a display device 10c is illustrated schematically.
[0101] Method 100c differs from method 100a of the first example in the method steps, particularly the transmission step 110c (where output data is not transmitted to cryptographic component 32c in the form of process values generated from image data by recovery unit 29c (particularly the first recovery component 26c and the second recovery component 28c)) and the output data step 106c (where output data is transmitted to dataset generator 30c, particularly to cryptographic component 32b, in the form of image data).
[0102] In one method step, particularly the output data step 106c, the output data is transmitted in the form of image data from the computing unit (particularly the image computing unit 14c) to the dataset generator 30b (particularly to the cryptographic component 32b).
[0103] In one method step, specifically dataset step 114c, image data is incorporated into the operational dataset as output data.
[0104] Figure 7 An alternative display device 200d is shown. The display device 200d includes an input unit 205d. The display device 200d includes a display unit 206d. The input unit 205d is arranged on the display unit 206d. Specifically, the display device 200d includes a touchscreen display. The touchscreen display is formed by the display unit 206d and the input unit 205d arranged on the display unit 206d. The display device 200d includes a computing unit (particularly an image computing unit 202d). The image computing unit 202d is connected to the display unit 206d of the display device (particularly for transmitting output data to the display unit 206d).
[0105] Display device 200d includes additional computing units (particularly checking unit 203d). Checking unit 203d is designed to generate input verification data from merging at least input and output data. Display device 200d includes a recovery unit 204d and a comparison component 207d according to the foregoing example. Display device 200d includes additional computing units (particularly dataset generator 210d). Additional computing units (particularly dataset generator 210d) include a cryptographic component 212d. Display device 200d is coupled to an auxiliary computing unit (particularly coupled to a secure computing unit 201d, preferably coupled to a secure programmable controller (SPC)). Dataset generator 210d has an indexing unit 214d. Indexing unit 214d is designed to provide and / or output index data for the dataset for each operation, such as incremental counter data. Secure computing unit 201d is coupled, for example, to dataset generator 210d (particularly cryptographic component 212d) and checking unit 203d (particularly comparison component 207d) for the transmission of input data.
[0106] For example, additional computing units (particularly inspection unit 203d) and supplementary computing units (particularly dataset generator 210d) are formed into a single computing unit, particularly a security system 240d, preferably on a common board or circuit board, which is formed and / or arranged as a separate component, particularly relative to the computing unit (particularly image computing unit 202d). The display device 200d includes a data receiver 220d.
[0107] Figure 8 A method 300d for creating an operational input dataset during operation of a display device 200d is illustrated schematically.
[0108] In one method step, specifically input data step 302d, secure input data is transmitted to image computing unit 202d to generate presentable output data. In another method step, specifically input data step 302d, secure input data is transmitted to inspection unit 203d. In yet another method step, specifically input data step 302d, secure input data is transmitted to dataset generator 210d (specifically cryptographic component 212d). The input data is configured in the form of process values. The input data is generated by secure computing unit 12a.
[0109] In one method step, particularly in generation step 304d, the image computing unit 202d generates presentable output data, particularly image data, from the input data.
[0110] In one method step, specifically output data step 306d, output data is transmitted from image calculation unit 302d to inspection unit 203d. In one method step, specifically output data step 106a, output data is transmitted from image calculation unit 302d to display unit 206d (specifically, the display of a touch screen display).
[0111] In at least one method step, particularly in recovery step 308d, the output data is first converted into fingerprints by recovery unit 204d, and then into recovered process values. In at least one method step, particularly in recovery step 308d, the output data in the form of image data is converted into fingerprint data and / or process values, particularly by recovery component 204d.
[0112] In at least one method step, particularly in transmission step 310d, output data is transmitted from recovery unit 204d to comparison component 207d of inspection unit 203d in the form of process values recovered from the output data. In at least one method step, particularly in transmission step 310d, output data is transmitted from inspection unit 203d to dataset generator 210d (particularly cryptographic component 212d) in the form of process values generated by recovery unit 204d from image data.
[0113] In one method step, particularly in the capture step 311d, input performed at the input unit 205d (in this case, touch input) is captured as input data by reading from the input unit 205d. In one method step, particularly in the capture step 311d, the input data is transmitted to the inspection unit 203d. In one method step, particularly in the capture step 311d, the input data is transmitted to the dataset generator 210d (particularly the password component 212d).
[0114] In one method step, particularly merging step 312d, checking unit 203d generates input verification data by merging at least input data and output data using checking unit 203d (particularly comparison component 207d). In one method step, particularly merging step 312d, the input verification data is transmitted to dataset generator 210d, particularly to cryptographic component 212d. In one method step, particularly merging step 312d, index data is transmitted to dataset generator 210d, particularly to cryptographic component 212d. Merging step 312d may include comparison steps 112a-c from the foregoing examples.
[0115] In one method step, specifically the dataset step 314d, the dataset generator 30a compiles the operational input dataset using operational input data related to the display device 200d.
[0116] In one method step, specifically dataset step 314d, during the compilation of the operational input dataset, input validation data, index data, input data, optional comparison data, optional output data, and optional input data are merged into the operational input dataset. In one method step, specifically dataset step 114a, output data is merged into the operational input dataset in the form of process values.
[0117] In one method step, particularly protection step 316d, the dataset generator 210d (particularly cryptographic component 212d) imparts tamper-proof protection (e.g., cryptographic signature) to the operational input dataset, specifically to provide a tamper-proof operational input dataset. In one method step, particularly protection step 316d, the dataset generator 210d (particularly cryptographic component 212d) forms signature data, such as hash data, from other data in the operational input dataset. In one method step, particularly protection step 316d, the dataset generator 210d (particularly cryptographic component 212d) forms signature data, for example, as hash data, using a hash algorithm. In one method step, particularly protection step 316d, the dataset generator 210d (particularly cryptographic component 212d) at least partially encrypts the operational input dataset (particularly encrypting the signature data of the operational input dataset) to achieve tamper-proof protection of the operational input dataset, specifically to provide a tamper-proof operational input dataset. In one method step, particularly protection step 316d, the signature data is encrypted to achieve tamper-proof protection of the operational input dataset. In one method step, particularly protection step 316d, signature data is formed using a hash algorithm, such as hash data. In another method step, particularly protection step 316d, a digital signature (particularly an encrypted signature) is created in at least one operational input dataset and appended to the corresponding unencrypted operational input dataset to achieve tamper-proof protection of the operational input dataset. In yet another method step, particularly protection step 316d, signature data is created and / or encrypted using asymmetric encryption (in this case, for example, using an elliptic curve cryptography (ECC) algorithm or a Rivest-Shamir-Adleman (RSA) encryption algorithm).
[0118] The protection step 316d includes encrypting at least a portion of the operational input dataset by means of cryptographic component 212d (particularly by means of asymmetric encryption, in this case, for example using an elliptic curve cryptography (ECC) algorithm or a Rivest-Shamir-Adleman (RSA) encryption algorithm).
[0119] In the repetitive method steps, particularly multiple dataset steps 314d, the dataset generator 210d compiles multiple operational input datasets in relation to the display device 200d, specifically relative to each other at periodic time intervals. For example, whenever an input (e.g., touch input) is made, that is, at initiation, method 300d can be executed completely repeatedly. When no input is made, method 300d can be executed partially repeatedly, particularly for creating operational datasets according to the first aspect of the invention. At least when an input (especially touch input) is made, method 300d is executed completely repeatedly.
[0120] In one method step, particularly recorder step 318d, an encrypted operational input dataset is stored (especially on recorder unit 230d).
[0121] The cryptographic component 210d is designed to create at least one operation input dataset (in particular multiple operation input datasets) through the operation of the display device 200d, and to provide tamper protection to the operation input dataset (in particular multiple operation input datasets).
[0122] The security system 240d includes a dataset generator 210d. The security system 240d includes an inspection unit 203d. The inspection unit 203d is designed to generate input validation data by merging at least input data and output data.
[0123] The operator control terminal 270d includes a display unit 200d and a recorder unit 230d. The recorder unit is externally formed relative to the security system 240d. The recorder unit 230d is externally formed relative to the display device 200d. The recorder unit 230d is designed to store operation input datasets. The security system 240d includes a data backup interface 236d, which is designed to output operation input datasets to the recorder unit 230d.
[0124] Display device 200d includes a security system 240d. The security system 240d is designed to be separate from the display device 200d. Specifically, the security system 240d is configured, for example, to be traceably integrated into / coupled to a card module of the existing display device 200d. Operator control terminal 270d includes the display device 200d. Operator control terminal 270d includes, for example, a security computing unit 201d.
[0125] A vehicle (not shown) (particularly a rail vehicle) may include an operator control terminal 270d. A signal box (not shown) for controlling a railway system may include an operator control terminal 270d. A control station (not shown) for process control in an industrial plant may include an operator control terminal 270d.
[0126] Figure Labels 10 Display devices 12 Secure Computing Units 14 Image computing units 16 monitors 18 Input Interfaces 20 Inspection Units 21 Comparison Components 22 Image Interface 24 Dataset Interface 26 Recovery Components 28 Recovery Components 29 Recovery Units 30 Dataset Generator 32. Cryptographic Components 34 Index Units 36 Data Backup Interface 40 Security Systems 50 recorder units 60 reaction units 70 Operator Control Terminal 100 methods 102 Input Data Steps 104 Generation Steps 106 Output Data Steps 108 Recovery Steps 110 Transmission Steps 112 Steps for comparing data 114 Dataset Steps 116 Protection Steps 118 Recorder Steps 200 display devices 202 Image Computing Unit 203 Inspection Unit 204 Recovery Unit 205 Input Units 206 display units 207 Comparison Component 210 Dataset Generator 212 Cryptographic Components 214 Index Units 220 Data Dormitory 230 recorder unit 236 Data Security Interface 240 Security System 270 Operator Control Terminal 300 methods 302 Input Data Steps 304 generation steps 306 Output Data Steps 308 Recovery Steps 310 Transmission Steps 311 Capture Steps 312 Merging Steps 314 Dataset Steps 316 Protection Steps 318 Recorder Steps
Claims
1. A method for creating a tamper-proof operational dataset during operation of a display device (10a-c, 200d), the method comprising: The input data is transmitted to the computing unit (14a-c, 202d) to generate presentable output data. The output data is transmitted to the inspection unit (20a-c, 203d). The input data is transmitted to the inspection unit (20a-c, 203d). Comparison data is generated by the inspection unit (20a-c, 203d) from the comparison between the input data and the output data. The method is characterized in that, Data is compiled using cryptographic components (32a-c, 212d) to form the operational dataset, which includes at least two of the following three types of data: input data, output data, and / or comparison data. The operation dataset is protected against tampering by the cryptographic components (32a-c, 212d) in order to provide the tamper-proof operation dataset.
2. The method according to claim 1, characterized in that, The output data is transmitted to the cryptographic components (32a-c, 212d) in the form of image data.
3. The method according to claim 2, characterized in that, The image data includes video data.
4. The method according to at least claim 1, characterized in that, The output data is transmitted to the cryptographic component in the form of fingerprint data generated from the image data by the computing units (29a-c, 204d).
5. The method according to at least claim 1, characterized in that, The output data is transmitted to the cryptographic component (32a-c, 212d) in the form of process values generated from the image data by the computing units (29a-c, 204d).
6. The method according to at least claim 1, characterized in that, In the compilation of the operational dataset, all three data points from the comparison data, the output data, and the input data are merged into the operational dataset.
7. A method for creating a tamper-proof operational input dataset during operation of a display device (200d), the display device (200d) having display units (16a-c, 206d) and an input unit (205d) disposed on the display units (206d), the method comprising: The input data is transmitted to the computing unit (202d) to generate presentable output data. The presentable output data is transmitted to the inspection unit (203d). Inputs made at the input unit (205d), such as touch inputs, are captured as input data by reading out the input unit (205d). The input data is transmitted to the inspection unit (203d). Input verification data is generated by the inspection unit (203d) from the merging of at least the input data and the output data. The method is characterized in that, The operation input dataset is formed by merging data through the cryptographic component (212d) from the input verification data and the input data, and the operation input dataset is tamper-proofed through the cryptographic component (212d) in order to provide the tamper-proof operation input dataset.
8. The method according to claim 7, characterized in that, In the compilation of the operation input dataset, the input data and / or the output data are further combined.
9. The method according to at least claim 7, characterized in that, In the compilation of the operation input dataset, comparison data created by the inspection unit (203d) from the comparison of the input data and the output data is further incorporated.
10. The method according to at least claim 1 or 7, characterized in that, In the creation of the operation dataset or the operation input dataset, index data is additionally incorporated into the operation dataset or the operation input dataset. The index data is preferably timestamp data, count data, and / or reference data.
11. The method according to at least claim 1 or 7, characterized in that, The tamper protection of the operation dataset or the operation input dataset is performed at least in part by asymmetric encryption, preferably using elliptic curve cryptography (ECC) or Rivest-Shamir-Adleman (RSA) encryption algorithms.
12. The method according to at least claim 1 or 7, characterized in that, The tamper-proof operation dataset or the tamper-proof operation input dataset is stored.
13. The method according to at least claim 1 or 7, characterized in that, The method is repeated at least in part.
14. A dataset generator having cryptographic components (32a-c, 212d), characterized in that, The cryptographic components (32a-c, 212d) are designed to create operation datasets and / or operation input datasets from operations of the display devices (10a-c, 200d), and are designed to provide tamper-proof protection for the operation datasets and / or the operation input datasets.
15. A security system having the dataset generator (30a-c, 210d) according to claim 14, characterized in that, It has a check unit (20a-c, 203d), which is designed to generate input verification data from the merging of at least input data and output data, and / or generate comparison data from the comparison of input data and output data.
16. The security system with a dataset generator (30a-c, 210d) according to claim 15 or 16, characterized in that, It has a recorder unit (50a-c, 230d) which is designed to store the operation dataset and / or the operation input dataset.
17. The security system with a dataset generator (30a-c, 210d) according to claim 15 or 16, characterized in that, It has a data backup interface (36a-c, 236d), which is designed to output the operation dataset and / or the operation input dataset.
18. A display device having a security system (40a-c, 240d) according to at least one of claims 15 to 17.
19. An operator control terminal having a display device (10a-c, 200d) according to claim 18.
20. A vehicle having an operator control terminal (70a-c, 270d) according to claim 19, particularly a rail vehicle.
21. A signal box for controlling a railway system having an operator control terminal (70a-c, 270d) according to claim 19, or a control station for process control in an industrial plant having an operator control terminal (70a-c, 270d) according to claim 19.
Citation Information
Patent Citations
Method for presenting safety-relevant information on a display device and device for carrying out the method
EP2273369A1
Method for representation of safety-relevant information on a display and apparatus for the application of the method
EP2353089B1
Dispositif et procédé pour une saisie relevant de la sécurité au moyen d'un appareil d'affichage avec saisie tactile
EP2551787B1
Monitoring unit for safety-related graphical user interfaces
EP3712770B1
Method for representation of safety-relevant information on a display and apparatus for the application of the method
WO2011003872A1