METHOD FOR OPERATING AN IoT DEVICE WITH AN APPLICATION, IoT DEVICE AND INDUSTRIAL NETWORK
By receiving and filtering application protocol messages in IoT devices, and utilizing device integrity status and trust filtering, the challenge of rapidly loading patches and adjusting protocols for IoT devices in industrial environments is solved, achieving high security and low downtime operation, suitable for manufacturing, transportation, and maintenance tools and equipment.
Patent Information
- Application Number
- CN202480026428.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-09-11
- Filing Date
- 2024-03-22
- Publication Date
- 2025-11-18
AI Technical Summary
Existing IoT devices struggle to quickly load security patches in industrial environments, and HTTP-based server access control is difficult to implement in industrial application protocols, making devices vulnerable to attacks and potentially causing production failures or interruptions when tampering or intrusion is detected.
By receiving and filtering application protocol messages in IoT devices, limiting communication using device integrity status, filtering messages using device trust, and processing them after decryption, and employing TLS, DTLS, and QUICK encryption protocols, the application protocol itself can be avoided.
It improves the security and resilience of IoT devices, reduces downtime, and effectively protects industrial networks in encrypted communication environments, especially suitable for manufacturing, transportation, and maintenance tools and equipment with high message exchange rates.
Smart Images

Figure CN120982064A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The invention relates to a method for operating an IoT (Internet of Things) device with an application, an IoT device and an industrial network for operating a wireless industrial edge cloud system with one or more base stations. The invention also relates to an orchestration module, a base station and a terminal device. BACKGROUND
[0002] IoT devices, for example industrial control devices, often have vulnerabilities that can be exploited by attackers. Conventional IT security measures attempt to prevent attacks as far as possible, for example by loading security patches. However, in particular in industrial environments, loading security patches cannot usually be done quickly, but only within a maintenance window. Furthermore, the IoT devices themselves that have been tampered with or subjected to an intrusion must be identified so that these devices can be blocked or deactivated. However, this can lead to further consequences, in particular to production failures or interruptions.
[0003] There is therefore a need for IoT devices that are more resistant to attacks. In particular, the IoT devices are to be able to operate their core functions more resiliently in order to withstand threats due to known, unpatched vulnerabilities or known or suspected tampering.
[0004] Unlike HTTP-based server access, the implementation of a zero-trust-based access control is often difficult to implement in practice in industrial application protocols such as MQTT, OPC UA, etc. because the application protocol used has to be adapted for this purpose. SUMMARY
[0005] The invention therefore aims to specify a method for operating an IoT device with an application that is improved compared to the prior art. In particular, it is intended to enable the IoT device to be operated more securely than has previously been known, and / or the IoT device to be operated particularly without interruption. The invention also aims to specify an improved IoT device with which, in particular, the method according to the invention can be carried out. The invention also aims to specify an improved industrial network with two or more such IoT devices.
[0006] This object of the invention is achieved by a method for operating an IoT device with an application having the features specified in claim 1 and by an IoT device having the features specified in claim 7 and by an industrial network having the features specified in claim 11. Preferred refinements of the invention are specified in the dependent claims, the following description and the figures.
[0007] In the method for operating an IoT device with applications which process messages according to application protocols, the IoT device receives the messages of the application protocols and uses a device integrity status of the device and filters the messages of the application protocols according to the device integrity status and processes the messages according to the application protocols after the messages have been filtered.
[0008] The core idea of the present application is therefore to limit the application protocol communication of the applications of an IoT device according to the current device trust. Thereby, the control options are limited and thereby the potential damage that can occur is limited. Unlike what is known from the prior art, the application protocols used do not have to be adapted for this. Rather, by means of the filtering according to the device integrity status, the message can already be filtered out by one or more applications before the message is processed. The device security is therefore significantly improved.
[0009] In other words, the application described supports the goal of increasing the resilience of an IoT system. According to the application, it is possible to achieve at least a limited operation of the or the IoT device even in the event of a persistent attack, wherein the potential damage effects can be controlled by means of the filtering according to the device integrity status of the IoT device. According to the application, this resilience protection can be implemented in an environment protected according to the Zero-Trust-Philosophy, since this resilience protection also works in encrypted communication. Here, this resilience protection can also be implemented in an industrial IoT environment, wherein established application protocols, in particular control protocols, are used, which cannot simply be extended or adapted.
[0010] Preferably, the device integrity information is formed in such a way that information about the software components of the IoT device is used and information about the vulnerabilities of the software components is used. The device integrity information can be calculated from the vulnerabilities of the software components due to a mapping of the known vulnerabilities of the software components to those software components actually implemented in and / or at and / or on the IoT device. It is precisely the consideration of the software components actually used that enables a particularly reliable evaluation of the device integrity information and thus enables the method according to the application to be implemented particularly effectively.
[0011] Preferably, in the method according to the application, preferably by means of TLS and / or DTLS and / or QUICK, the messages according to the application protocol are decrypted before they are filtered according to the device integrity status. In this extension, the method according to the application is compatible with typical IoT device environments that frequently or always use encrypted communication. Since the messages are filtered after they are decrypted and before they are processed by the application protocol of the one or more applications, the method according to the application can be implemented in a variety of ways and compatibly with previously used methods.
[0012] In a preferred extension of the method according to the application, the application protocol comprises OPC UA and / or XMPP and / or MQTT. These application protocols are particularly difficult or completely unable to be effectively adapted in production environments, so that the method according to the application has a great advantage, especially in this extension.
[0013] In the method according to the application, the IoT device preferably operates in an industrial network. Especially in industrial networks, a failure of an IoT device is disadvantageous due to the resulting loss of productivity. According to the application, on the one hand, the failure time of an IoT device can be significantly reduced, and at the same time, a high security can be maintained when using the IoT device.
[0014] It is particularly preferred that, in the method according to the application, the IoT device is a manufacturing device and / or a transportation device and / or a maintenance tool and / or a logistics device. Especially the above-mentioned application cases often require the use of IoT devices with a high message exchange rate. Therefore, the method according to the application can be used particularly advantageously in the above-mentioned application cases.
[0015] The IoT device according to the application is designed to operate by means of the method according to the application as described above. The IoT device according to the application has applications that process messages according to an application protocol, the IoT device is designed to receive messages of these application protocols, wherein there is a message filter for the messages, which is designed to filter the messages of the application protocols according to the device integrity status, wherein the message filter supplies the filtered messages to the applications for processing the messages according to the application protocols. Thus, for the IoT device according to the application, the same advantages arise as already set out more extensively for the method according to the application.
[0016] The IoT device according to the application preferably has a decryption device, which is set up to decrypt the messages, preferably by means of TLS and / or DTLS and / or QUICK, and which is set up to transmit the decrypted messages to the message filter.
[0017] In a preferred extension of the IoT device according to the application, the IoT device is a manufacturing device and / or a transportation device and / or a maintenance tool and / or a logistics device. Alternatively and equally preferred, the IoT device according to the application constitutes an information-physical device.
[0018] Preferably, in the IoT device according to the application, the application protocols include OPC UA and / or XMPP and / or MQTT.
[0019] The industrial network according to the application has two or more IoT devices in communication connection with each other.
[0020] Especially preferred, the industrial network constitutes an information-physical system. BRIEF DESCRIPTION OF DRAWINGS
[0021] Subsequently, the application is explained in more detail in accordance with the embodiments shown in the drawings.
[0022] Only one drawing Figure 1 The industrial IoT system ISYS is shown schematically in a block diagram. The shown IoT system ISYS is a manufacturing system. In other not specifically shown embodiments, the IoT system ISYS can also be a transportation logistics system, such as a transportation logistics system equipped with autonomous vehicles, or a maintenance system, or other industrial IoT system ISYS, such as an information-physical system. DETAILED DESCRIPTION
[0023] The industrial IoT system ISYS comprises a plurality of IoT devices IOTD. In the shown embodiment, the IoT devices IOTD are manufacturing tools, such as drilling tools. The IoT devices IOTD comprise sensors S and actuators A for interacting with the physical world PW. The sensors S are used for detecting workpieces, and the actuators A are used for machining workpieces, e.g. drill heads for drilling holes in workpieces. The sensors S and actuators A are read and manipulated in a per se known manner by means of input-output interfaces IO through the remaining components of the IoT devices IOTD. Furthermore, the IoT devices are kept in communication connection with each other.
[0024] In the shown embodiment, the application protocol communication is restricted in dependence on a current device trust DT. In this way, the control options opened by the application protocol communication are restricted in dependence on the damage that can potentially occur under the control options. By means of the shown solution according to the application, the application AP PP used does not need to be adapted as such.
[0025] In the illustrated solution according to the application, a "Device Resilience Agent" DRA is provided on the IoT device IOTD. On the one hand, the Device Resilience Agent DRA takes over the packet filtering of the data stream NWIF received by the IoT device IOTD by means of a packet filter PF in a manner known per se. After the packet filtering has taken place, the data stream NWIF is decrypted in a manner known per se, in the present case by means of the encryption protocols TLS, DTLS and QUICK.
[0026] In addition, however, the IoT device IOTD also has a Message Filter MF for filtering messages MESS of the application protocols APPP used. By means of this Message Filter MF, the decrypted data stream is not used directly in the application protocols APPP, in the present case, for example, OPC UA and XMPP and MQTT.
[0027] Instead, the Message Filter MF, which is limited in the illustrated embodiment, filters the messages MESS specifically for each respectively used application protocol APPP and hands over the correspondingly filtered messages MESS to the respective application protocol APPP for further processing.
[0028] Thus, in the method according to the application, the device communication of the IoT device IOTD is encrypted, as is usual in the case of a zero trust approach. At the same time, however, by virtue of the filtering of the messages MESS by means of the special Message Filter MF, possible undesirable influences, such as impairments, are avoided or limited. As a result, the resilience of the IoT device IOTD and, by means of this, of the industrial system ISYS is improved.
[0029] The Device Resilience Agent DRA determines the device trust state DTS and adjusts the filtering rules of the Message Filter MF in accordance with the device trust state. In addition, it is also possible to adjust the IoT control functions of the IoT device IOTD and / or the packet filter of the IoT device IOTD and / or the I / O interface of the IoT device IOTD.
[0030] The device trustworthiness DT of the IoT device IOTD can be determined locally at the IoT device IOTD, for example by a device integrity monitoring system on the IoT device IOTD, in the form of what is known per se and as a so-called Device Health Check, which is performed by a Device Health Agent DHA. Alternatively or additionally, the device trustworthiness DT can also be determined externally to the device, in the example shown by a Zero Trust Device Manager ZTDM. This device trustworthiness can also use vulnerability information, which is provided directly by the device manufacturer MAN of the IoT device IOTD by means of a device vulnerability database DVD, or which is determined indirectly by means of an SBOM "Software Bill of Material" of the IoT device IOTD provided by the device manufacturer MAN and known vulnerabilities of software components used by the IoT device IOTD. These vulnerabilities of the software components can then be mapped to the device vulnerabilities by means of a mapping database ZUO. The vulnerabilities of the software components can be obtained, for example, from a software vulnerability database SVD. The vulnerability information of the IoT device IOTD determined in this way can also be entered into the device vulnerability database DVD. The Zero Trust Device Manager ZTDM uses the vulnerability information of the IoT device IOTD of the device vulnerability database DVD in order to determine the device trustworthiness DT of the IoT device IOTD. Thereby, the current device trustworthiness DT can be determined on the basis of currently known vulnerabilities of the software components used. Furthermore, the integrity proof of the IoT device IOTD, or the device compliance status of the device management system, can be evaluated.
[0031] Optionally and not shown, security situation information can be used and evaluated, which indicates which vulnerabilities are being actively exploited and which areas or network areas are affected thereby. Such information can be provided, for example, by a Security-Monitoring-System.
[0032] In a complex industrial system ISYS with a large number or plurality of IoT devices IOTD, the application can be implemented on all or only a subset of the IoT devices IOTD used. The IoT devices IOTD can generally be implemented as fixed integrated components. Alternatively, the IoT devices IOTD can be implemented as components with a plurality of sub-modules, for example as a storage programmable controller with expansion modules in the form of technology modules or remote input-output modules, or as virtualized IoT components, for example virtualized PLCs.
[0033] The components in form of message filters MF and device resilience agents DRA provided by the resilient functionality according to the application for an IoT device IOTD, e.g. implemented in a protected trusted execution environment, in the shown embodiment in the ARM TrustZone. Alternatively, the protected trusted execution environment can also be implemented as a separate resilience processor module, or as a FPGA, or as an ASIC.
[0034] In other embodiments, not specifically shown, which otherwise correspond to the shown embodiment, the implementation is protected against special attacks, e.g. by using exploit protection techniques like ASLR or Stack Protection or Memory Encryption or Control Flow Integrity or a combination of such exploit protection techniques. Thereby, even if the general device functionality of the IoT device IOTD, e.g. the network stack or control functionality CF of the IoT device IOTD, has been compromised, such special resilient functionality is difficult or impossible to attack and thereby is trustworthy.
[0035] Additionally, in other embodiments, it is indicated by the operator of the industrial system ISYS which actions are allowed at which security level. Thereby, it is intended to be able to limit specified actions or functionalities of the IoT device IOTD based on the current threat situation.
Claims
1. A method for operating an IoT device (IOTD) with one or more applications that process messages (MESS) according to an application protocol (APPP), wherein, The IoT device (IOTD) receives messages of the application protocol (APPP), wherein a device integrity status (DT) of the device is used and the messages (MESS) of the application protocol (APPP) are filtered according to the device integrity status (DT), and after the messages have been filtered, the messages (MESS) are processed by the one or more applications according to the application protocol (APPP).
2. The method according to the previous claim, wherein, The application protocol (APPP) is not changed or not changed or adapted according to the device integrity status (DT).
3. The method of any of the above claims, wherein, The IoT messages (MESS) are decrypted, preferably by means of TLS and / or DTLS and / or QUICK, before the IoT messages of the application protocol (APPP) are filtered according to the device integrity status (DS).
4. The method of any of the above claims, wherein, The application protocol (APPP) comprises OPC UA and / or XMPP and / or MQTT.
5. The method of any of the above claims, wherein, The IoT device (IOTD) operates in an industrial network (ISYS).
6. The method of any of the above claims, wherein, The IoT device (IOTD) is a manufacturing device and / or a transportation device and / or a maintenance tool and / or a logistics device.
7. An IoT device designed for operation by means of a method according to any one of the preceding claims, the IoT device having one or more applications which process messages according to an application protocol (APPP), and the IoT device being designed for receiving messages (MESS) of the application protocol (APPP), wherein There is a message filter (MF) for messages (MESS), which is designed to filter messages (MESS) of the application protocol (APPP) according to a device integrity status (DT), wherein the message filter (MF) supplies the filtered messages (MESS) to the one or more applications for processing the messages according to the application protocol (APPP).
8. The IoT device according to the preceding claim, which has a decryption device, which is set up to decrypt the messages (MESS), preferably by means of TLS and / or DTLS and / or QUICK, and which is set up to pass the decrypted messages (MESS) to the message filter (MF).
9. The IoT device according to any one of the preceding claims, which is a manufacturing device and / or a transportation device and / or a maintenance tool and / or a logistics device.
10. The loT device of any of the above claims, wherein, The application protocol (APPP) comprises OPC UA and / or XMPP and / or MQTT.
11. An industrial network having two or more IoT devices according to any of the preceding claims, wherein, The IoT devices (IOTD) are communicatively connected to one another.
12. The industrial network according to the preceding claim, which constitutes an information-physical system.
Citation Information
Patent Citations
Application-specific network data filtering
CN115943378A
Devices and method for testing devices
EP3758320A1
Trusted cyber physical system
US20230035007A1
Automation system having at least one component with at least one app, and manufacturing system
WO2023025731A1