Method and system for making power source markings trustworthy and verifiable

CN122550183APending Publication Date: 2026-08-11ABB (SCHWEIZ) AG
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-06
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

因此,在工业环境中,存在如何提高功率来源标记过程的安全性和可验证性的问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122550183A_ABST
    Figure CN122550183A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to methods and systems for making power source markings trustworthy and verifiable. The invention provides a method for implementing a power source marking process with increased security in an industrial environment. The method includes providing, at a device configured to generate a power source marking, a hardware-protected storage for storing a signing key that is bound to the device and to be used by a power source marking algorithm for calculating a power source marking; providing, at the device, a trusted execution environment (TEE) for implementing and / or executing the power source marking algorithm in the TEE; and providing, at the device, a remote attestation mechanism for an external party to verify the power source marking algorithm and / or the device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for implementing power source tagging processing with increased security in an industrial environment. The invention also relates to a computer-implemented method for ensuring power source tagging processing in an industrial environment. Furthermore, the invention relates to an apparatus for generating power source tags with increased security in an industrial environment, a data processing apparatus, a computer-readable medium, and a computer program product. Background Technology

[0002] In industrial environments, the source of energy data can be traced and tagged. This enables the generation of power source tags, indicating the energy used in product manufacturing, such as a blend of renewable and non-renewable energy sources. While power tracking and tagging algorithms and processes can be specified, no security considerations have been addressed. However, ensuring the security and reliability of the power source tagging process is crucial to its commercial value.

[0003] Without protection, attackers can tamper with various parts of the power source tagging process. For example, an attacker could manipulate the power source algorithm that calculates the actual power source tag. This would allow an attacker to obtain seemingly green power source tags while using polluting energy to produce products—a trick known as "greenwashing." Worse still, attackers might attempt to steal confidential information, such as identity and keys, from the benign device that generates the power source tag. This would allow an attacker to impersonate the device and generate power source tags with arbitrary content without manipulating any power input data or algorithms. Another problem arises from the fact that power source tagging is currently not verifiable. Therefore, external parties (e.g., auditors, customers, or regulatory agencies) cannot verify the authenticity and correctness of the power source tagging process. This means that the power source tagging process and the tags generated therefrom are black boxes that must be blindly trusted.

[0004] The problems described above highlight the need to make the power source marking process safe and verifiable. Therefore, in industrial environments, there is a question of how to improve the safety and verifiability of the power source marking process.

[0005] Therefore, in industrial environments, there is room and need for improvement in enhancing the safety and verifiability of power source labeling processes. Summary of the Invention

[0006] In view of the above, the purpose of this disclosure is to overcome at least some of the shortcomings of power source labeling processes in industrial environments in terms of safety and verifiability. Therefore, to address one or more of these drawbacks, this disclosure provides, in a first aspect, a method for implementing power source tagging processing with increased security in an industrial environment. The method includes: providing, at a device configured to generate power source tags, a hardware-protected storage device for storing a signature key, which is bound to the device and used by a power source tagging algorithm to compute the power source tags. The method further includes: providing, at the device, a Trusted Execution Environment (TEE) for the power source tagging algorithm to be implemented and / or executed within the TEE. The method also includes: providing, at the device, a remote verification mechanism for an external party to verify the power source tagging algorithm and / or the device.

[0007] It is important to note that the method described in the first aspect can be understood as a method performed by a service provider or application provider. The service provider or application provider provides systems or infrastructure for storing signature keys, implementing and / or executing power source tagging algorithms, and verifying the power source tagging algorithm and / or the device.

[0008] This method can be implemented, at least in part, by a computer.

[0009] For example, the phrase "power source labeling processing" means that one or more power source labels are identified or calculated. A power source label can label the source of a certain amount of power or energy, where the source is, for example, at least one of renewable energy and energy from fossil fuels (i.e., non-renewable energy). Therefore, a power source label can be associated with a product, a portion of a product (e.g., one or more raw materials, components, or semi-finished products used), and one or more processing steps for manufacturing or obtaining the product or a portion of the product. A power source label can indicate a certain amount of power or energy required to manufacture the product or a portion of the product, or to perform one or more processing steps. Additionally or alternatively, a power source label can also indicate the type and / or energy mix required to manufacture the product, a portion of the product, or to perform one or more processing steps. For example, the energy mix may indicate the share of renewable energy and the share of energy from fossil fuels.

[0010] The device configured to generate power source tags can be any device suitable for generating power source tags, such as one or more servers.

[0011] The term "hardware protected" means using specific hardware as a security measure, for example, to prevent attacks on certain assets (like encryption keys). For example, certain hardware can be used because it is physically implemented in a certain way and / or that hardware is facilitated by some kind of software implementation (e.g., FPGA).

[0012] For example, the term "signature key" means the encryption key that generates a digital signature or message authentication code.

[0013] The term "binding" means that signing keys cannot be stolen from the device. They can be (re)generated, stored, and used by the device to generate digital signatures, but they cannot be copied to other devices or accessed by other devices. This property is ensured by using hardware-protected storage devices.

[0014] For example, the statement "the power source tagging algorithm uses a signature key to compute the power source tag" means that the power source tagging algorithm uses one or more signature keys to sign one or more computation processes performed by the power source tagging algorithm, and / or to sign one or more results obtained from one or more computation processes, and / or to sign one or more inputs of one or more computation processes.

[0015] Furthermore, the power source labeling algorithm can be understood as being provided or implemented within the TEE. In other words, any input to the power source labeling algorithm from outside the TEE must first enter the TEE, while any output intended for the power source labeling algorithm to be sent outside the TEE must first leave the TEE.

[0016] For example, the term "external party" means at least one of the user, other devices, and / or other systems. It is important to note that verification can also be performed by other devices or systems instead of the user, for example, to enable automatic responses in the event of an integrity violation.

[0017] The method described in the first aspect has several advantages.

[0018] First, the power source tagging process is protected, for example, through hardware-protected storage devices (including signing keys) and / or by implementing the power source tagging algorithm within the TEE, ensuring that the algorithm remains secure and tamper-proof throughout its execution. This protection prevents any external entity from modifying or accessing the algorithm and allows its integrity and confidentiality to be maintained. Once set up, the power source tagging process is immune to manipulation, and attackers can only stop its execution, not alter its operation. This also protects the confidentiality used in generating and protecting power source tags, thus maintaining the authenticity and trustworthiness of the tags by facilitating secure operation. Furthermore, this feature protects the intellectual property rights of the power source tagging algorithm, creating a substantial barrier for competitors attempting to clone or copy these algorithms. By securing the tagging process and ensuring its verifiability, this enhances the reliability and commercial value of power source tags, fostering trust among customers, auditors, and regulatory bodies.

[0019] Secondly, the secure verifiability provided by the remote verification mechanism ensures that auditors can trust the power source tagging process and are confident that it has not been tampered with, which is crucial for safeguarding the power source tagging itself. Auditors are empowered to verify the accuracy and authenticity of the entire power source tagging process. This verification capability can be performed dynamically during operation, allowing audits to be conducted at flexible frequencies at any time. This also enables auditors or third parties to confirm that the power source tagging algorithm operates on designated devices, has not been tampered with, and is executed on authorized hardware, thereby strengthening trust in the integrity of the tagging process.

[0020] Third, it offers a significant advantage in preventing "greenwashing" in power source labeling. By ensuring the integrity and verifiability of energy data, it prevents deception through misleading advertising of product environmental qualifications. This transparency not only builds trust with consumers but also enhances the credibility of companies committed to genuine sustainability efforts, giving them a competitive edge in a fiercely competitive market.

[0021] Fourth, it demonstrates a strong commitment to sustainability. By taking robust measures to safeguard and verify the source of energy used in its products, the company demonstrates its dedication to transparent environmental practices. This proactive approach not only enhances credibility in the eyes of consumers, regulators, and stakeholders but also aligns with global efforts to achieve the Sustainable Development Goals. It positions the organization as a leader in environmental responsibility, cultivating a positive reputation and competitive advantage in a market increasingly focused on sustainability initiatives.

[0022] Fifth, it enhances customer trust and corporate reputation, crucial business benefits. By ensuring the authenticity and transparency of energy source labeling, manufacturers strengthen their credibility as trusted suppliers committed to sustainable practices. This builds stronger relationships with environmentally conscious consumers who value transparency and integrity in product sourcing. Furthermore, a positive sustainability reputation can attract new customers, differentiate the brand in a competitive market, and increase customer loyalty.

[0023] Sixth, compliance with safety standards and requirements is ensured, which brings significant business benefits. By adhering to established safety protocols and regulations, manufacturers demonstrate their commitment to protecting sensitive energy source data from tampering or misuse. This compliance enhances trust among customers, partners, and regulatory bodies, ensuring that the power source labeling process meets stringent safety standards. Furthermore, compliance with these standards reduces the risk associated with data breaches or fraudulent activities, protects the company's reputation, and minimizes potential legal and financial liabilities.

[0024] According to several examples of this disclosure, a method of providing a hardware-protected storage device for storing a signature key may further include binding the hardware-protected storage device to the device.

[0025] Therefore, only this device can access the hardware-protected storage device, specifically, it can access the data stored in the hardware-protected storage device and / or can store data in the hardware-protected storage device. This further enhances security.

[0026] According to several examples of this disclosure, a method for providing a hardware-protected storage device for storing a signature key may further include granting exclusive access to the signature key to a power source tagging algorithm implemented in the TEE.

[0027] For example, the term "exclusive" means that only the power source tagging algorithm can access the signature key.

[0028] Therefore, only the power source tagging algorithm can access the signature key, specifically, it can use and / or read the signature key or (re)generate the signature key. This further increases security.

[0029] According to several examples of this disclosure, a method for providing a hardware-protected storage device for storing a signature key may further include: providing a hardware-protected storage device for further storing power source tag metadata, which will be used by a power source tagging algorithm to verify the correct calculation of the power source tag; and providing exclusive access to the power source tag metadata to the power source tagging algorithm implemented in the TEE.

[0030] For example, the term "power source tag metadata" means additional or supplementary data tagged by power source tags regarding the source of power or energy. For instance, power source tag metadata can indicate weather conditions (e.g., sunny or windy), which can allow for further verification and understanding of the source of power or energy, such as energy obtained via a photovoltaic system or wind turbine.

[0031] For example, the term "exclusive" means that only the power source tagging algorithm can access the power source tagging metadata.

[0032] Therefore, the reliability and trustworthiness of power source tags are further improved because the use of power source tag metadata is guaranteed and protected, for example, because only the power source tag algorithm can access (i.e., use and / or read) the power source tag metadata.

[0033] According to several examples of this disclosure, providing a remote verification mechanism may include providing a remote verification mechanism to measure the integrity of the program code of the power source tagging algorithm in order to verify the power source tagging algorithm.

[0034] It is important to note that the remote verification mechanism for the integrity of the program code of the power source tagging algorithm can be implemented using existing implementations of remote verification. For example, this can be achieved by calculating a cryptographic hash of the program code and signing the cryptographic hash along with a random number from an external party using a device-related signing key.

[0035] Therefore, the reliability, trustworthiness, security, and protection of the verification process are further improved.

[0036] According to several examples of this disclosure, providing a remote verification mechanism may include providing the results of verification or measurement of integrity and transmitting the results to an external party to compare the results with a priori known reference results.

[0037] Therefore, the reliability, trustworthiness, security, and protection of the verification process are further improved.

[0038] According to a second aspect, a computer-implemented method for securing power source tagging processing in an industrial environment is provided. The method includes: storing a signature key in a hardware-protected storage device provided at a device configured to generate power source tags; the signature key being bound to the device and used by a power source tagging algorithm to compute power source tags. The method further includes: implementing and / or executing the power source tagging algorithm in a trusted execution environment (TEE) provided at the device. The method also includes: verifying the power source tagging algorithm and / or the device using a remote authentication mechanism provided at the device.

[0039] It should be noted that the method according to the second aspect can be understood as a method performed by a service user or application user (e.g., by an external party mentioned in the method according to the first aspect). The service user or application user stores the signing key, implements and / or executes the power source tagging algorithm, and verifies the power source tagging algorithm and / or the device.

[0040] Furthermore, it should be noted that if the same terms and / or expressions used to define the method according to the first aspect are also used to define the method according to the second aspect, they should be understood in the same way.

[0041] The method described in the second aspect has the following advantages:

[0042] First, the power source tagging process is protected, for example, through hardware-protected storage devices (including signing keys) and / or by implementing the power source tagging algorithm within the TEE, ensuring that the algorithm remains secure and tamper-proof throughout its execution. This protection prevents any external entity from modifying or accessing the algorithm and allows its integrity and confidentiality to be maintained. Once set up, the power source tagging process is immune to manipulation, and attackers can only stop its execution, not alter its operation. This also protects the confidentiality used in generating and protecting power source tags, thus maintaining the authenticity and trustworthiness of the tags by facilitating secure operation. Furthermore, this feature protects the intellectual property rights of the power source tagging algorithm, creating a substantial barrier for competitors attempting to clone or copy these algorithms. By securing the tagging process and ensuring its verifiability, this enhances the reliability and commercial value of power source tags, fostering trust among customers, auditors, and regulatory bodies.

[0043] Secondly, the secure verifiability provided by the remote verification mechanism ensures that auditors can trust the power source tagging process and are confident that it has not been tampered with, which is crucial for safeguarding the power source tagging itself. Auditors are empowered to verify the accuracy and authenticity of the entire power source tagging process. This verification capability can be performed dynamically during operation, allowing audits to be conducted at flexible frequencies at any time. This also enables auditors or third parties to confirm that the power source tagging algorithm operates on designated devices, has not been tampered with, and is executed on authorized hardware, thereby strengthening trust in the integrity of the tagging process.

[0044] Third, it offers a significant advantage in preventing "greenwashing" in power source labeling. By ensuring the integrity and verifiability of energy data, it prevents deception through misleading advertising of product environmental qualifications. This transparency not only builds trust with consumers but also enhances the credibility of companies committed to genuine sustainability efforts, giving them a competitive edge in a fiercely competitive market.

[0045] Fourth, it demonstrates a strong commitment to sustainability. By taking robust measures to safeguard and verify the source of energy used in its products, the company demonstrates its dedication to transparent environmental practices. This proactive approach not only enhances credibility in the eyes of consumers, regulators, and stakeholders but also aligns with global efforts to achieve the Sustainable Development Goals. It positions the organization as a leader in environmental responsibility, cultivating a positive reputation and competitive advantage in a market increasingly focused on sustainability initiatives.

[0046] Fifth, it enhances customer trust and corporate reputation, crucial business benefits. By ensuring the authenticity and transparency of energy source labeling, manufacturers strengthen their credibility as trusted suppliers committed to sustainable practices. This builds stronger relationships with environmentally conscious consumers who value transparency and integrity in product sourcing. Furthermore, a positive sustainability reputation can attract new customers, differentiate the brand in a competitive market, and increase customer loyalty.

[0047] Sixth, compliance with safety standards and requirements is ensured, which brings significant business benefits. By adhering to established safety protocols and regulations, manufacturers demonstrate their commitment to protecting sensitive energy source data from tampering or misuse. This compliance enhances trust among customers, partners, and regulatory bodies, ensuring that the power source labeling process meets stringent safety standards. Furthermore, compliance with these standards reduces the risk associated with data breaches or fraudulent activities, protects the company's reputation, and minimizes potential legal and financial liabilities.

[0048] According to several examples of this disclosure, the method may also include binding a hardware-protected storage device to the device.

[0049] Therefore, only this device can access the hardware-protected storage device, specifically, it can access the data stored in the hardware-protected storage device and / or can store data in the hardware-protected storage device. This further enhances security.

[0050] According to several examples of this disclosure, the implementation may include implementing a power source tagging algorithm in the TEE to have exclusive access to the signature key.

[0051] For example, the term "exclusive" means that only the power source tagging algorithm can access the signature key.

[0052] Therefore, only the power source tagging algorithm can access the signature key, specifically, it can use and / or read the signature key or (re)generate the signature key. This further increases security.

[0053] According to several examples of this disclosure, the storage may further include: storing power source tag metadata in a hardware-protected storage device, the metadata being used by the power source tagging algorithm to prove the correct calculation of the power source tag; and exclusive access to the power source tag metadata by the power source tagging algorithm implemented in the TEE.

[0054] For example, the term "exclusive" means that only the power source tagging algorithm can access the power source tagging metadata.

[0055] Therefore, the reliability and trustworthiness of power source tags are further improved because the use of power source tag metadata is guaranteed and protected, for example, because only the power source tag algorithm can access (i.e., use and / or read) the power source tag metadata.

[0056] According to several examples of this disclosure, the verification may include measuring the integrity of the program code of the power source tagging algorithm via a remote verification mechanism in order to verify the power source tagging algorithm.

[0057] It is important to note that the remote verification mechanism for the integrity of the program code of the power source tagging algorithm can be implemented using existing implementations of remote verification. For example, this can be achieved by using a cryptographic hash value calculated on the program code, and a signed cryptographic hash value combined with a random number from an external party that has a device-related signing key.

[0058] Therefore, the reliability, trustworthiness, security, and protection of the verification process are further improved.

[0059] According to several examples of this disclosure, the method may also include transmitting the result of the verification or measurement of integrity to an external party so as to compare the result with a priori known reference result.

[0060] Therefore, the reliability, trustworthiness, security, and protection of the verification process are further improved.

[0061] According to a third aspect, an apparatus is provided for generating power source tags with increased security in an industrial environment. The apparatus includes a hardware-protected storage device for storing a signature key, which is bound to the apparatus and used by a power source tagging algorithm to calculate the power source tag. The apparatus includes a Trusted Execution Environment (TEE) in which the power source tagging algorithm is implemented and / or executed. The apparatus includes a remote verification mechanism for external parties to verify the power source tagging algorithm and / or the apparatus.

[0062] It should be noted that the terms and / or expressions used to define the device according to the third aspect have the same meaning as those used to define the method according to the first aspect.

[0063] According to a fourth aspect, a data processing apparatus is provided. The data processing apparatus includes one or more processors configured to perform the method according to a second aspect.

[0064] According to a fifth aspect, a data processing system is provided. The data processing system includes the apparatus described in the third aspect and / or the apparatus described in the fourth aspect. Additionally or alternatively, the data processing system includes components for performing the method described in the first aspect and / or the method described in the second aspect.

[0065] According to a sixth aspect, an industrial plant is provided that includes the equipment described in the third aspect and / or the equipment described in the fourth aspect. Additionally or alternatively, the industrial plant includes the data processing system described in the fifth aspect.

[0066] According to several examples, "industrial plant" can mean an industrial factory, autonomous industrial plant, or industrial production plant, including one or more pipelines, production lines, and / or assembly lines for converting one or more reactants into products and / or for assembling one or more components into a final product. According to several examples, "industrial plant" can mean an industrial plant in the oil industry, natural gas industry, mining industry, chemical industry, wind and power industry, or food and beverage industry.

[0067] According to a seventh aspect, a computer-readable medium is provided that includes instructions, which, when executed by a computing system, cause the computing system to perform the method according to a first aspect and / or the method according to a second aspect. The computer-readable medium may be temporary or non-temporary, volatile or non-volatile.

[0068] According to an eighth aspect, a computer program product including instructions is provided that, when executed by a computing system, enable the computing system to perform or cause the computing system to perform the method according to the first aspect and / or the method according to the second aspect. The computer program product may include a computer-readable medium comprising the instructions of the computer program product.

[0069] According to a ninth aspect, a mode of use is provided that employs at least one of the apparatus according to a third aspect, the apparatus according to a fourth aspect, the data processing system according to a fifth aspect, the industrial plant according to a sixth aspect, the computer-readable medium according to a seventh aspect, and the computer program product according to an eighth aspect.

[0070] Each of the third to ninth aspects has several advantages.

[0071] First, the power source tagging process is protected, for example, through hardware-protected storage devices (including signing keys) and / or by implementing the power source tagging algorithm within the TEE, ensuring that the algorithm remains secure and tamper-proof throughout its execution. This protection prevents any external entity from modifying or accessing the algorithm and allows its integrity and confidentiality to be maintained. Once set up, the power source tagging process is immune to manipulation, and attackers can only stop its execution, not alter its operation. This also protects the confidentiality used in generating and protecting power source tags, thus maintaining the authenticity and trustworthiness of the tags by facilitating secure operation. Furthermore, this feature protects the intellectual property rights of the power source tagging algorithm, creating a substantial barrier for competitors attempting to clone or copy these algorithms. By securing the tagging process and ensuring its verifiability, this enhances the reliability and commercial value of power source tags, fostering trust among customers, auditors, and regulatory bodies.

[0072] Secondly, the secure verifiability provided by the remote verification mechanism ensures that auditors can trust the power source tagging process and are confident that it has not been tampered with, which is crucial for safeguarding the power source tagging itself. Auditors are empowered to verify the accuracy and authenticity of the entire power source tagging process. This verification capability can be performed dynamically during operation, allowing audits to be conducted at flexible frequencies at any time. This also enables auditors or third parties to confirm that the power source tagging algorithm operates on designated devices, has not been tampered with, and is executed on authorized hardware, thereby strengthening trust in the integrity of the tagging process.

[0073] Third, it offers a significant advantage in preventing "greenwashing" in power source labeling. By ensuring the integrity and verifiability of energy data, it prevents deception through misleading advertising of product environmental qualifications. This transparency not only builds trust with consumers but also enhances the credibility of companies committed to genuine sustainability efforts, giving them a competitive edge in a fiercely competitive market.

[0074] Fourth, it demonstrates a strong commitment to sustainability. By taking robust measures to safeguard and verify the source of energy used in its products, the company demonstrates its dedication to transparent environmental practices. This proactive approach not only enhances credibility in the eyes of consumers, regulators, and stakeholders but also aligns with global efforts to achieve the Sustainable Development Goals. It positions the organization as a leader in environmental responsibility, cultivating a positive reputation and competitive advantage in a market increasingly focused on sustainability initiatives.

[0075] Fifth, it enhances customer trust and corporate reputation, crucial business benefits. By ensuring the authenticity and transparency of energy source labeling, manufacturers strengthen their credibility as trusted suppliers committed to sustainable practices. This builds stronger relationships with environmentally conscious consumers who value transparency and integrity in product sourcing. Furthermore, a positive sustainability reputation can attract new customers, differentiate the brand in a competitive market, and increase customer loyalty.

[0076] Sixth, compliance with safety standards and requirements is ensured, which brings significant business benefits. By adhering to established safety protocols and regulations, manufacturers demonstrate their commitment to protecting sensitive energy source data from tampering or misuse. This compliance enhances trust among customers, partners, and regulatory bodies, ensuring that the power source labeling process meets stringent safety standards. Furthermore, compliance with these standards reduces the risk associated with data breaches or fraudulent activities, protects the company's reputation, and minimizes potential legal and financial liabilities.

[0077] With appropriate modifications, optional features of the first and / or second aspects can form part of any of the third to ninth aspects.

[0078] The computer program product according to the eighth aspect can be stored on the computer-readable medium according to the seventh aspect.

[0079] For example, the term “acquire” as used herein may include: receiving from another system, device, apparatus, or process; receiving via interaction with a user; loading or retrieving from a storage device or memory; measuring or capturing using a sensor or other data acquisition device; or receiving or acquiring as a result of one or more data processing steps.

[0080] The indefinite articles “one” or “a” do not exclude plural forms. Furthermore, unless otherwise stated or the context clearly indicates a singular form, the articles “one” and “a” as used herein should generally be interpreted as “one or more”.

[0081] Unless otherwise stated or the context clearly indicates, the phrases “one or more of A, B, and C,” “at least one of A, B, and C,” and “A, B, and / or C” as used herein are intended to mean all possible permutations and combinations of one or more of the listed items. That is, the phrase “A and / or B” means (A), (B), or (A and B), while the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0082] The term "comprising" does not exclude other elements or steps. Furthermore, the terms "comprising," "including," and "having" are used interchangeably herein.

[0083] This invention may include one or more individual or combined aspects, examples, or features, whether or not they have been specifically disclosed individually or in combination. Any optional features or sub-aspects of the foregoing aspects may be applied to any other aspect as appropriate.

[0084] The aspects described above will become apparent and will be clarified with reference to the specific embodiments provided below. Attached Figure Description

[0085] A detailed description will now be given by way of example only, with reference to the accompanying drawings, in which:

[0086] - Figure 1 The illustrations depict power source labeling solutions according to several examples of this disclosure;

[0087] - Figure 2 The illustration shows a flowchart indicating a method according to several examples of this disclosure;

[0088] - Figure 3 The illustration shows a flowchart indicating a method according to several examples of this disclosure;

[0089] - Figure 4 The illustration shows a block diagram schematically illustrating an apparatus for generating power source markers according to several embodiments of the present disclosure; and

[0090] - Figure 5 The illustration shows a block diagram schematically illustrating a data processing apparatus according to several embodiments of the present disclosure. Detailed Implementation

[0091] Based on several examples of this disclosure, this disclosure provides a solution for making the power source tagging process secure and verifiable. For example, to improve understandability (but not limited to this), by making the power source tagging process secure and verifiable, such a power source tagging process can be extended as disclosed in document EP4481647 (which describes a technique for tracking and tagging the source of energy data).

[0092] Therefore, according to various examples of this disclosure, hardware-protected storage devices and trusted execution environments (TEEs) are introduced to protect the power source tagging algorithm, its keys, and data from unauthorized access and tampering. Additionally, a remote verification mechanism is integrated to enable external parties to verify the integrity of the tagging process, ensuring that an attacker has not tampered with the algorithm or input data. Thus, this disclosure makes the power source tagging process more trustworthy, prevents "greenwashing," allows compliance with security standards and regulations, and enhances customer trust and manufacturer reputation.

[0093] For example, to improve understandability (but not limited to this), document EP4481647 proposes a technique for tracking and tagging energy data sources. This document generates power source tags indicating the energy source used to manufacture products, such as a combination of renewable and non-renewable energy sources. While document EP4481647 details the power tracking and tagging algorithms and processes, it does not address security issues. However, ensuring the security and trustworthiness of the power source tagging process is crucial to its commercial value. Another drawback is that document EP4481647 does not implement verifiable power source tagging.

[0094] Based on several examples of this disclosure, in order to make the power source tagging process secure and verifiable, this disclosure provides a novel combination of security measures or security means, namely: (i) a hardware-protected storage device for the signature key (and optionally, also for the power source metadata); (ii) a trusted execution environment (TEE) that runs the power source tagging algorithm and its protection mechanisms; and (iii) a remote verification mechanism that provides reliable evidence of the power source tagging process.

[0095] First, the hardware-protected storage device ensures that the signing key is unique and bound to the device that generated the power source tag. This means that the signing key can only be accessed by the device, and there is no way to steal the signing key or tamper with its use. In the same way, the power source metadata used to prove the correct calculation of the power source tag is also hardware-protected. Details regarding how the signing key and power source metadata are used to provide trust and authenticity in the power source tag do not form part of this disclosure.

[0096] Secondly, a TEE (Technical Equipment Environment) can be used, which protects the code and data on the device that generates the power source tagging algorithm. Today, a wide variety of devices, from servers to small embedded systems, provide some form of TEE (e.g., but not limited to these examples: Intel SGX, Intel TDX, ARM TrustZone, AMD SEV). The TEE provides a protected environment in which the power source tagging algorithm is implemented and / or executed. This ensures that other code on the device (even privileged code, such as the operating system kernel) cannot interfere with or tamper with the execution of the power source tagging algorithm.

[0097] Third, a remote verification mechanism can be implemented for the power source tagging process. Remote verification (e.g., as outlined in Principles of remote attestation by Coker, G., Guttman, J., Loscocco, P. et al., International Journal of Information Security, Vol. 10, pp. 63-81, 2011. https: / / doi.org / 10.1007 / s10207-011-0124-7) allows an external party to verify whether a remote system is indeed running the claimed software. According to several examples of this disclosure, remote verification can be used to enable external parties to verify that the power source tagging device (i) is indeed running the undisturbed and latest version of the power source tagging code, and / or (ii) is a trusted device authorized to generate power source tags. In this way, the power source tagging process is made verifiable by an external party, who can be provided with verification of the correct and trustworthy implementation and execution of the power source tagging process.

[0098] In summary, based on several examples of this disclosure, the provided security measures not only safeguard the power source marking process but also enable external verification of the process, thereby providing several novel features and commercial benefits.

[0099] Now for reference Figure 1 , Figure 1 The illustrations depict power source labeling solutions or processes according to several examples of this disclosure. Figure 1A system 100 is schematically illustrated, comprising a manufacturer or manufacturing company 110, an external party 120 (e.g., an auditor), and an energy management system (EMS) 130. The EMS 130 may include equipment for generating power source tags with increased security in an industrial environment, or at least a portion of the EMS 130 may be provided at that equipment (i.e., may operate or be executed at that equipment) for generating power source tags with increased security in an industrial environment. The EMS 130 includes a TEE 140, and a power tagging algorithm or power source tagging algorithm 150 is provided in the TEE 140, i.e., the power source tagging algorithm 150 is implemented and / or executed in the TEE 140. Therefore, it can be understood that equipment for generating power source tags with increased security in an industrial environment includes the TEE 140. Furthermore, as... Figure 1 As indicated herein, the EMS 130 or the device includes a hardware-protected storage device 160 for storing a signature key 170 bound to the device, which will be used by the power source tagging algorithm 150 to calculate one or more power source tags 180. Furthermore, as Figure 1 As further indicated, the EMS 130 or the device includes a remote verification mechanism 190, for example, to allow an external party 120 to verify the power source tagging algorithm 150 and / or the device or EMS 130.

[0100] Manufacturing company 110 inputs energy data to EMS 130, or provides energy data to equipment used to generate power source tags with increased security in an industrial environment. In doing so, the energy data may be input to TEE 140 and / or stored in hardware-protected storage device 160. The energy data may include power source tag metadata. Power source tagging algorithm 150 can use the energy data, and optionally also the power source tag metadata, to calculate one or more power source tags 180, which can then be provided as output from EMS 130 or from that equipment.

[0101] For example, to increase comprehensibility, let's assume, without limitation, that manufacturing company 110 produces a certain product A. To obtain this product A, several different processing steps S1, S2, and S3 will be performed. In these processing steps S1, S2, and S3, several different starting materials B and C, as well as several different semi-finished products and components D and E, are processed according to a predetermined workflow. For step S1, an energy amount E1 may be required; for step S2, an energy amount E2 may be required; and for step S3, an energy amount E3 may be required. E1 may include an energy structure M1, E2 may include an energy structure M2, and E3 may include an energy structure M3. For example, M1 may include 100% renewable energy, M2 may include 100% fossil fuel energy (i.e., energy from fossil fuels), and M3 may include 50% renewable energy and 50% energy from fossil fuels. The energy data provided by manufacturing company 110 may include all of this data / information E1 to E3 and M1 to M3. Then, the power source tagging algorithm 150 can use all this data / information E1 to E3 and M1 to M3 to calculate one or more power source tags 180 for a specific product A. An external party 120 can verify the calculation of one or more power source tags 180 for a specific product A.

[0102] exist Figure 1 The study further demonstrates that, due to the security measures implemented, attacker 200 has no possibility of manipulating the power source labeling algorithm 150 or manipulating energy data.

[0103] It is important to note that the focus of this disclosure is on protecting the power source tagging process, specifically, on providing a particular combination of different security measures to protect the process of generating or computing the power source tag 180. For example, this can be achieved by using a key (signature key 170) to generate a signed power source tag (power source tag 180).

[0104] The following section will provide a more detailed overview based on... Figure 1 The safety measures are illustrated.

[0105] According to several examples of this disclosure, a hardware-protected storage device 160 and a TEE 140 are employed to protect power source tagging codes, data, and keys. It should be noted that the hardware-protected storage device 160 and / or TEE 140 are not limited to specific hardware technologies, and therefore descriptions of hardware-related features are omitted. Instead, this document specifies the attributes and configurations required for a secure storage and execution environment. Typically, the key or signing key 170 needs to be stored in a hardware-protected key storage device (e.g., hardware-protected storage device 160). This storage should be bound to the device performing the power source tagging process (i.e., the power source tagging device, such as the aforementioned device for generating power source tags with increased security in an industrial environment), and the private key should be protected so that it cannot be imported or exported from the device. Instead, the key can only be generated on the device itself (e.g., generated during boot) and subsequently used by the device. While the private signing key is confidential and protected, the public portion of the signing key can be known to other parties (e.g., external party 120), including any entity intending to verify the power source tag.

[0106] According to several examples of this disclosure, power source tagging code is implemented and / or executed within TEE 140. Only power source tagging code running within TEE 140 can access the hardware-protected key storage device 160, meaning that no other code (even privileged kernel code) can use the power source tagging key storage device 160. Furthermore, power source tagging metadata (which can be used to cross-check the legitimacy of the generated power source tagging 180) can also be stored within TEE 140, thereby protecting it from modification by potentially malicious code running on the power source tagging device.

[0107] According to several examples of this disclosure, in order to enable the power source tagging process to be verified by others, a security mechanism known as remote verification (remote verification mechanism 190) can be utilized. Remote verification mechanism 190 measures the integrity of the power source tagging algorithm 150 running in TEE 140. One method of measuring the code is to calculate the cryptographic hash value of the program code. This measurement can be performed at load time or during runtime and is designed to detect whether the power source tagging algorithm 150 has been tampered with. Afterwards, an external verifier (e.g., Figure 1The external party 120 (illustrated in the diagram) can execute an interactive challenge-response protocol with the power source tagging device to verify its software integrity. During protocol execution, the power source tagging device can sign its software integrity measurement results and transmit them to the verifier (e.g., an external auditor). The verifier can compare the received software integrity measurement results with known good measurements of the power source tagging algorithm known to the verifier in advance to determine whether the power source tagging process has been tampered with. This verification mechanism can be executed at any time during the operation of the power source tagging device. In this way, the verifier can determine that the power source tagging device (i) is indeed running the tamper-proof and latest version of the power source tagging code, and (ii) is a trusted device authorized to generate power source tags.

[0108] Therefore, protections for the power source tagging process are provided based on several examples of this disclosure. More specifically, the features disclosed herein that protect the power source tagging process ensure that the algorithm remains secure and tamper-proof throughout its execution. This protection prevents any external entity from modifying or accessing the algorithm, thus maintaining its integrity and confidentiality. Once set up, the power source tagging process is immune to manipulation, and an attacker can only stop its execution but cannot alter its operation. This also protects the confidentiality used in generating and protecting power source tags, thereby maintaining the authenticity and trustworthiness of the tags by facilitating secure operation. Furthermore, these features protect the intellectual property rights of the power source tagging algorithm, creating a substantial barrier for competitors attempting to clone or copy these algorithms. By securing the tagging process and ensuring its verifiability, this disclosure enhances the reliability and commercial value of power source tagging, thereby fostering trust among customers, auditors, and regulatory agencies.

[0109] Furthermore, according to several examples in this disclosure, external verification of the power source tagging process is provided. More specifically, the features of secure verifiability ensure that auditors can confidently utilize energy data, knowing that the data has not been tampered with, which is crucial for securing the source tagging itself. Auditors are empowered to verify the accuracy and authenticity of the entire power source tagging process. This verification capability can be performed dynamically during operation, allowing audits to be conducted at flexible frequencies at any time. These features also enable auditors or third parties to confirm that the power source tagging algorithm operates on designated devices, has not been tampered with, and is executed on authorized hardware, thereby reinforcing trust in the integrity of the tagging process.

[0110] Furthermore, several examples of this disclosure can prevent "greenwashing." More specifically, this disclosure provides significant business benefits by preventing "greenwashing" in power source labeling. By ensuring the integrity and verifiability of energy data, it prevents deception that falsely advertises the environmental qualifications of products. This transparency not only builds trust with consumers but also enhances the credibility of companies committed to genuine sustainability efforts, giving them a competitive edge in a market.

[0111] Furthermore, several examples in this disclosure demonstrate a commitment to sustainability. More specifically, this disclosure showcases a strong commitment to sustainability. By taking robust measures to safeguard and verify the source of energy used in products, companies demonstrate their dedication to transparent environmental practices. This proactive approach not only enhances credibility in the eyes of consumers, regulators, and stakeholders but also aligns with global efforts to achieve the Sustainable Development Goals. It positions the organization as a leader in environmental responsibility, cultivating a positive reputation and competitive advantage in markets that increasingly value sustainability initiatives.

[0112] Furthermore, according to several examples disclosed herein, customer trust in the manufacturer and the manufacturer's reputation among customers are enhanced. More specifically, enhanced customer trust and reputation are key business benefits resulting from implementing at least a portion of the solutions disclosed herein. By ensuring the authenticity and transparency of energy source labeling, the manufacturer enhances its credibility as a trusted supplier committed to sustainable practices. This builds stronger relationships with environmentally conscious consumers who value transparency and integrity in product sourcing. Moreover, a positive sustainability reputation can attract new customers, differentiate the brand in a competitive market, and increase customer loyalty.

[0113] Furthermore, compliance with security standards and requirements is provided based on several examples of this disclosure. More specifically, implementing at least a portion of the solutions disclosed herein ensures compliance with security standards and requirements, resulting in significant business benefits. By adhering to established security protocols and regulations, manufacturers demonstrate their commitment to protecting sensitive energy source data from tampering or misuse. This compliance enhances trust among customers, partners, and regulatory bodies, ensuring that the power source labeling process meets stringent security standards. Moreover, compliance with these standards reduces the risks associated with data breaches or fraudulent activities, protects the company's reputation, and minimizes potential legal and financial liabilities.

[0114] Now for reference Figure 2 , Figure 2The illustration shows a flowchart indicating a method according to several embodiments of the present disclosure. This method is used to implement power source tagging processing with increased safety in an industrial environment. The power source tagging processing can be as described in reference... Figure 1 This process is described in the description. The method can be described as follows: (See reference...) Figure 1 The manufacturing company 110 is responsible for performing this procedure. Therefore, manufacturing company 110 can also be understood as representing a service provider or application provider. However, it should be noted that, alternatively, this procedure can also be performed by a third party, i.e., by a service provider or application provider different from manufacturing company 110. For example, this third party could be a provider or custodian, as described in the reference. Figure 1 The description of the EMS 130 party, and / or the provision or escrow as referenced above. Figure 1 The power source marking device outlined herein (i.e., a device for generating power source markings with increased safety in an industrial environment) is one party to this.

[0115] This method begins with S200.

[0116] In S210, the method includes providing a hardware-protected storage device 160 at a device configured to generate a power source tag 180 for storing a signature key 170, the signature key 170 being bound to the device and used by the power source tagging algorithm 140 to calculate the power source tag 180. The device may be as referenced above. Figure 1 The power source marking device is described in the overview.

[0117] In S220, the method includes: providing a TEE 140 at the device for implementing and / or executing a power source labeling algorithm 150 in the TEE 140.

[0118] In S230, the method includes: providing a remote verification mechanism 190 at the device for an external party 120 to verify the power source tagging algorithm 140 and / or the device.

[0119] The method ends at S240.

[0120] Now for reference Figure 3 , Figure 3 A flowchart illustrating a method according to several examples of this disclosure is shown. This method is computer-implemented and is used to ensure power source tagging processing in an industrial environment. Power source tagging processing can be as described in reference... Figure 1 This process is described in the description. The method can be described as follows: (See reference...) Figure 1 The manufacturer is described as 110 and / or as per reference. Figure 1This description refers to an external party 120 and / or an action performed by a third party. Therefore, manufacturing company 110 and / or external party 120 can be understood as representing a service user or application user. This will be described in more detail below.

[0121] This method begins with S300.

[0122] In S310, the method includes: storing a signature key 170 in a hardware-protected storage device 160 provided at a device configured to generate a power source tag 180, the signature key 170 being bound to the device and used by the power source tagging algorithm 150 to calculate the power source tag 180. The device may be as referenced above. Figure 1 The power source marking device is outlined. It should be noted that the storage can be performed by the manufacturing company 110 or a third party.

[0123] In S320, the method includes implementing and / or executing a power source marking algorithm 150 in a TEE 140 provided at the device. It should be noted that the manufacturing company 110 or a third party may perform this implementation and / or execution.

[0124] In S330, the method includes verifying the power source tagging algorithm 150 and / or the device using a remote verification mechanism 190 provided at the device. It should be noted that this verification can be performed by an external party 120 or a third party.

[0125] This method ends at S340.

[0126] Now for reference Figure 4 , Figure 4 A block diagram schematically illustrates a data processing apparatus or device 400 for generating power source tags according to several examples of the present disclosure. In particular, according to several examples of the present disclosure, an apparatus 400 for generating power source tags with increased security in an industrial environment is provided, as referenced above. Figure 1 As outlined above. Device 400 includes components configured to perform the functions described in the reference above. Figure 2 One or more processors 401 of the method outlined herein.

[0127] According to several examples of this disclosure, device 400 may include tools for operation and / or function as referenced above. Figure 1 The components of this EMS 130 are described in the overview.

[0128] More specifically, based on various examples, it is configured to execute Figure 2The device 400 of the method may include a processing circuitry, processing functions, processing components, processing units, or a processor 401, enabling the device 400 to participate in the generation of power source tags with increased security in an industrial environment. The processor 401 may include one or more processing portions or functions, wherein the processing portions or functions may be provided as one or more physical or virtual entities. The device 400 may include one or more communication interfaces 402. The device 400 may also include a memory or storage unit 403 for storing data, programs, and / or instructions to be executed by the processor. The memory 403 may be internal to the device 400 or external to the device 400 (e.g., on a cloud server). The processor 401 may include one or more portions, for example, that enable the device 400 to perform... Figure 2 The method. According to several examples of this disclosure, provision 410 can be configured to perform according to... Figure 2 The S210 provides such a provision that the provision portion 420 can be configured to perform according to Figure 2 This provision of S220, and the provision portion 430 can be configured to perform according to Figure 2 This is the provision of the S230.

[0129] According to several examples of this disclosure, the corresponding parts of device 400 may also be understood as components for performing specific functions.

[0130] According to several examples of this disclosure, an apparatus for generating power source tags with increased security in an industrial environment can be provided. The apparatus may include a processing circuitry, processing functions, processing components, processing units, or a processor, enabling the apparatus to participate in the generation of power source tags with increased security in an industrial environment. The processor may include one or more processing portions or functions, wherein the processing portions or functions may be provided as one or more physical or virtual entities. The apparatus may include one or more communication interfaces. The apparatus may also include memory or storage units for storing data, programs, and / or instructions to be executed by the processor. The apparatus may include hardware-protected storage devices, a trusted execution environment (TEE), and a remote verification mechanism. The hardware-protected storage devices may be for storing a signature key that is bound to the apparatus and will be used by the power source tagging algorithm to calculate the power source tag. The power source tagging algorithm is implemented and / or executed in the trusted execution environment (TEE). The remote verification mechanism allows an external party to verify the power source tagging algorithm and / or the apparatus.

[0131] Now for reference Figure 5 , Figure 5A block diagram schematically illustrating a data processing apparatus or device 500 for generating power source tags according to several examples of the present disclosure is shown. In particular, several examples of the present disclosure provide a device 500 for ensuring power source tagging processing in an industrial environment, as referenced above. Figure 1 As outlined above. Device 500 includes devices configured to perform the functions described in the reference above. Figure 3 One or more processors 501 of the method outlined herein.

[0132] According to several examples of this disclosure, device 400 may include components for operating and / or performing the above-mentioned references. Figure 1 The components of EMS 130 are outlined below.

[0133] More specifically, based on various examples, it is configured to execute Figure 3 The device 500 of the method may include a processing circuitry, processing functions, processing components, processing units, or a processor 501, enabling the device 500 to participate in power source marking processes in an industrial environment. The processor 501 may include one or more processing portions or functions, wherein the processing portions or functions may be provided as one or more physical or virtual entities. The device 500 may include one or more communication interfaces 502. The device 500 may also include a memory or storage unit 503 for storing data, programs, and / or instructions to be executed by the processor. The memory 503 may be internal to the device 500 or external to the device 500 (e.g., on a cloud server). The processor 501 may include one or more portions, for example, that enable the device 500 to perform... Figure 3 The method. According to several examples of this disclosure, the storage section 510 can be configured to perform according to Figure 3 The storage, implementation, and / or execution portion 520 of the S310 can be configured to execute according to Figure 3 This implementation and / or execution of S320, while the verification section 530 can be configured to execute according to Figure 3 This verification of the S330.

[0134] According to several examples of this disclosure, the corresponding parts of device 500 may also be understood as components for performing specific functions.

[0135] According to several examples of this disclosure, a data processing system for power source tagging processing in an industrial environment is provided. The data processing system includes, according to... Figure 4 Equipment 400 and / or according to Figure 5 The device 500. Additionally or alternatively, the data processing system may also include components for performing operations according to... Figure 2 and / or Figure 3The method is a component. The data processing system can be as shown in the reference... Figure 1 The system 100 shown in the figure.

[0136] According to several examples of this disclosure, an industrial plant is provided, the industrial plant comprising, according to Figure 4 Equipment 400, according to Figure 5 The equipment 500 and / or the data processing system as outlined above. The industrial plant may be an industrial plant that produces a certain product (i.e., the production of the product) that requires the calculation of power source markers.

[0137] According to several examples of this disclosure, a computer-readable medium including instructions that, when executed by a computing system, cause the computing system to perform as described in the references Figure 2 and / or Figure 3 The methods outlined herein. The computer-readable medium may be temporary or non-temporary, volatile or non-volatile.

[0138] According to several examples of this disclosure, a computer program product including instructions is provided that, when executed by a computing system, enable the computing system to perform or cause it to perform as described in the references. Figure 2 and / or Figure 3 The method outlined herein. The computer program product may include a computer-readable medium that includes the instructions of the computer program product. The computer program product may be stored on the aforementioned computer-readable medium.

[0139] Based on several examples of this disclosure, use is provided for at least one of the apparatus 400, apparatus 500, data processing system, industrial plant, computer-readable medium, and computer program product described above. In particular, use is provided as referenced... Figure 2 The outlined method enables power source tagging processing with increased safety in industrial environments; and also provides a method for using, as shown in the reference... Figure 3 The methods outlined herein ensure power source labeling processing in industrial environments.

[0140] After appropriate modifications, as for reference Figures 1 to 3 The optional features of the (multiple) methods outlined may form part of apparatus 400, apparatus 500, data processing system, industrial process, computer-readable medium, computer program product, and their uses.

[0141] Any unit, module, circuit system, or method described herein may be implemented using hardware, software, and / or firmware configured to perform any of the operations described herein. Hardware may include one or more processor cores, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), etc. Software may be embodied as software packages, code, instructions, instruction sets, and / or data recorded on at least one transient or non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, or instruction sets and / or data hard-coded in a memory device (e.g., a non-volatile memory device).

[0142] If implemented in software, the functionality can be stored on or transmitted through a computer-readable medium as one or more instructions or code. Computer-readable media includes computer-readable storage media. A computer-readable storage medium can be any available storage medium accessible to a computer. For example, and not limitingly, such computer-readable storage media can include FLASH storage media, RAM, ROM, EEPROM, CD-ROM or other optical disc storage devices, disk storage devices or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and is accessible to a computer. As used herein, “disk” and “optical disc” include compact optical discs (CDs), laser optical discs, optical discs, digital versatile optical discs (DVDs), floppy disks, and Blu-ray discs (BDs), where disks typically copy data magnetically and optical discs typically copy data optically using lasers. Furthermore, the propagation of signals can also be included within the scope of computer-readable storage media. Computer-readable media also includes communication media, which includes any medium that facilitates the transfer of a computer program from one place to another. For example, a connection can be a communication medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are all included in the definition of communication media. Combinations of the above should also be included within the scope of computer-readable media.

[0143] The applicant hereby individually discloses each individual feature described herein, as well as any combination of two or more such features, provided that such features or combinations can be implemented based on the entire specification and in view of common general knowledge of those skilled in the art, regardless of whether such features or combinations of features solve any problem disclosed herein, and without limiting the scope of the claims. The applicant notes that aspects of the invention can consist of any such individual features or combinations of features.

[0144] It should be noted that embodiments of the present invention are described with reference to different categories. Specifically, some examples are described with reference to methods, while others are described with reference to apparatus. However, those skilled in the art will understand from the specification that, unless otherwise stated, any combination of features related to different categories, in addition to any combination of features belonging to the same category, is also considered to be disclosed in this application. However, all features can be combined to provide a synergistic effect greater than the simple sum of the features.

[0145] While the invention has been detailed and described in the accompanying drawings and foregoing description, these illustrations and descriptions should be considered exemplary rather than limiting. The invention is not limited to the disclosed embodiments. Those skilled in the art will understand and implement other variations of the disclosed embodiments by studying the drawings, the disclosure, and the appended claims.

[0146] The fact that certain measures are stated in mutually different dependent claims does not indicate that a combination of these measures cannot be used advantageously.

[0147] Any reference numerals in the claims should not be construed as limiting the scope of the claims.

Claims

1. A method for implementing power source tagging processing with increased safety in an industrial environment, the method comprising: - At the device configured to generate power source tags, a hardware-protected storage device is provided (S210) for storing a signature key that is bound to the device and will be used by the power source tagging algorithm to calculate the power source tag; - At the device, a Trusted Execution Environment (TEE) is provided (S220) for the power source labeling algorithm to be implemented and / or executed in the TEE; as well as - At the device, a remote verification mechanism (S230) is provided for an external party to verify the power source labeling algorithm and / or the device.

2. The method according to claim 1, wherein the hardware-protected storage providing for storage of the signing key further comprises: Bind the hardware-protected storage device to the device.

3. The method according to claim 1 or 2, The storage device that provides hardware protection for storing the signature key also includes providing exclusive access to the signature key to the power source tagging algorithm implemented in the TEE.

4. The method according to any one of claims 1 to 3, The storage device providing hardware protection for storing the signature key further includes: - Provides a hardware-protected storage device for further storing power source tag metadata, which will be used by the power source tagging algorithm to prove the correct calculation of the power source tag; as well as - Provide exclusive access to the power source tagging metadata to the power source tagging algorithm implemented in the TEE.

5. The method of any of claims 1 to 4, wherein providing the remote attestation mechanism comprises: To verify the power source labeling algorithm, a remote verification mechanism is provided to measure the integrity of the program code of the power source labeling algorithm.

6. The method of any of claims 1 to 5, wherein providing the remote attestation mechanism comprises: The results of the verification or the measured integrity are provided to transmit the results to the external party for comparison with prior known reference results.

7. A computer-implemented method for ensuring the security of power source tagging processing in an industrial environment, the method comprising: - A signature key is stored (S310) in a hardware-protected storage device provided at a device configured to generate a power source tag. The signature key is bound to the device and will be used by the power source tag algorithm to calculate the power source tag. - Implement and / or execute the power source labeling algorithm (S320) in the Trusted Execution Environment (TEE) provided at the device; and - Verify (S330) the power source labeling algorithm and / or the device by using a remote verification mechanism provided at the device.

8. The method of claim 7, further comprising binding the hardware-protected storage device to the device.

9. The method of claim 7 or 8, wherein the implementation includes implementing the power source tagging algorithm in the TEE to have exclusive access to the signature key.

10. The method according to any one of claims 7 to 9, wherein the storage further comprises: - Power source tag metadata is stored in the hardware-protected storage device, and the power source tag metadata will be used by the power source tag algorithm to prove the correct calculation of the power source tag; as well as - The power source tagging metadata is exclusively accessed by the power source tagging algorithm implemented in the TEE.

11. The method of any of claims 7-10, wherein the verifying comprises: To verify the power source tagging algorithm, the remote verification mechanism measures the integrity of the program code of the power source tagging algorithm by calculating the cryptographic hash value of the program code.

12. An apparatus for generating power source markings with increased safety in an industrial environment, the apparatus comprising: - A hardware-protected storage device for storing a signature key, which is bound to the device and will be used by a power source tagging algorithm to calculate the power source tag; - A Trusted Execution Environment (TEE) in which the power source labeling algorithm is implemented and / or executed; as well as - A remote verification mechanism for external parties to verify the power source labeling algorithm and / or the device.

13. A data processing apparatus (500) comprising one or more processors configured to perform the method according to any one of claims 7 to 11.

14. A computer program product comprising instructions that, when executed by a computing system, enable the computing system to perform and / or cause the computing system to perform the method according to any one of claims 1 to 6, and / or perform the method according to any one of claims 7 to 11.

15. A computer-readable medium having thereon stored a computer program product according to claim 14.

Citation Information

Patent Citations

  • Computer-implemented method for determining an energy ratio for a consumed energy

    EP4481647A1