Method for providing computer-implemented functionality in a computing system

The method addresses the challenge of managing and authorizing access to various vehicle functionalities by using a security module to sign provision requests and access management to verify and grant access keys, resulting in secure and efficient access to multiple functionalities with minimal key management.

DE102023213131A1Pending Publication Date: 2025-06-26ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102023213131
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing vehicle-implemented functionalities lack a secure and efficient method to manage and authorize access to various computer-implemented functionalities, requiring multiple authorization keys to be stored for each functionality.

Method used

A method that uses a security module to sign a provision request with an authorization key, sending it to an access management system, which verifies the request and sends an access key to implement the requested functionality using a functionality container.

Benefits of technology

This method enables secure and efficient access to multiple functionalities with only a single or small number of authorization keys stored, reducing the need for extensive key management and enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for providing a computer-implemented functionality in a computing system (2) having at least one computing unit (4) and a security module (6, 8), comprising signing (210), by the security module (6, 8), a provision request that specifies a requested functionality using an authorization key stored by the security module, sending (420) the signed provision request to an access management system (14), checking (430), by the access management system (14), the authenticity of the signed provision request if the check is successful, sending (440), by the access management system, an access key for the requested functionality to the computing system (2), sending (450) a container request for the requested functionality to a repository (16) that stores a functionality container (18) with the requested functionality;and if the validity of the access key is confirmed, implementing (480), by the at least one computing unit (4), the functionality using the functionality container in the computing system (2);
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to a method for providing a computer-implemented functionality in a computing system and to a method which is carried out in a computing system, and to a computing unit and a computer program for carrying it out.BACKGROUND OF THE INVENTIONVehicle-implemented functionalities may be defined by software, wherein controllers execute computer programs to implement certain functionalities. In this case, parameters of the computer programs can be changeable in order to change the scope of a functionality. For example, in an engine control program for the engine of the same vehicle, different power levels may be parameterized. Different functionalities can likewise be implemented for the same vehicle by different computer programs. For example, an autonomous driving function, for example automatic parking, may be implemented or may not be implemented with the vehicle otherwise unchanged, depending on whether or not a corresponding computer program is installed / enabled. Such differences in the provided functionalities may further depend on respective users of the vehicle.Disclosure of the InventionAccording to the invention, a method for providing a computer-implemented functionality in a computing system and a method which is carried out in a computing system, and a computing unit and a computer program for carrying it out having the features of the independent patent claims are proposed. Advantageous embodiments are the subject matter of the dependent claims and of the following description.The invention makes use of the measure of signing, by the security module, a provision request, which specifies a requested functionality, using an authorisation key stored by the security module, and sending it to an access management system in a method for providing a computer-implemented functionality in a computing system, which has at least one computing unit and a security module. After successfully verifying the authenticity of the signed distribution request, an access key for the requested functionality is sent to the computing system by the access manager. Further, a container request for the requested functionality is sent to a repository storing a functionality container having the requested functionality, and after the validity of the access key is confirmed, the functionality is implemented using the functionality container in the computing system.The invention enables access to a large number of different functionalities requiring authorisation for implementation, wherein only a single authorisation key or a relatively small number of authorisation keys (e.g. specific for specific users of the vehicle) is or are stored by the security module. Storing a large number of keys corresponding to the number of different functionalities is not necessary.The method is performed in a system that includes the computing system, the access manager, and the repository.The term "cryptographic key" or simplified "key" is intended to refer to character strings used in cryptographic methods. These strings should be sufficiently random so that they can be determined (if not known) only by rates or by gross force attacks.According to one embodiment, the container request includes the access key and the method comprises verifying, by the repository, the validity of the access key; and if the verification of the validity is successful, transmitting, by the repository, the functionality container to the computing system. This is convenient because the access key is acknowledged by a system independent of the computing system.According to one configuration in which the functionality container is cryptographically secured, in particular encrypted, in the repository, such that the functionality cannot be implemented without knowledge of the access key, the method comprises, in order to confirm the validity of the access key, transmitting, by the repository, the secured functionality container to the computing system in response to the container request and cancelling, in particular decrypting, by the computing system, the cryptographic securing of the functionality container using the access key. In this embodiment, the container request and the transmission of the functionality container can take place before the provision request (i.e. before signing and / or sending the provision request).According to one embodiment, the access key is sent to the computing system as an encrypted access key by the access manager. This encryption of the access key may be in addition to an encryption of the message in which the access key is sent to the computing system. This enables, in particular, embodiments in which the (unencrypted) access key is known only in the security module.According to one embodiment, the encrypted access key is optionally decrypted by the security module and buffer-stored by the security module without being transmitted to a computing unit or another module of the computing system, and the access key is inserted into the container request by the security module, wherein the container request is encrypted by the security module after this insertion. According to this embodiment, the container request can be generated without the requesting, possibly compromised, computing unit receiving access to the access key.According to one embodiment, the encrypted access key is optionally decrypted by the security module and temporarily stored by the security module without being transmitted to a computing unit or another module of the computing system, wherein the cryptographic protection of the functionality container is canceled by the security module. Here too, the (unencrypted) access key can be prevented from becoming known in the computing system outside the security module.According to one configuration, in which the computing system has a communication module, the communication with the access management and the repository takes place via the communication module. Communication with the access manager and the repository includes sending the signed provision request, receiving the access key as part of sending the access key to the computing system, sending the container request to the repository, and, optionally, receiving the functionality container from the repository. The communication module represents a central unit in the computing system, via which messages with external systems are exchanged. The communication module can be configured to exchange data within the computing system only with the at least one computing unit. This allows the use of a security module that satisfies very high security requirements, e.g., a hardware security module. Alternatively, it can also be provided that the communication module is configured to exchange data within the computing system with the at least one computing unit and with the security module.This simplifies the data exchange in the computing system, so that in particular less computing power and / or data bandwidth of a bus used for the data exchange is required.According to one embodiment, the sending of the provision request and / or the sending of the access key and / or the sending of the container request and / or, if appropriate, the transmitting of the functionality container takes place in cryptographically secured form, wherein respective messages are encrypted and / or signed. In this way, in particular the authenticity and integrity of messages can be confirmed and attackers can be prevented from obtaining access to transmitted data, e.g. from knowing the access key or from obtaining knowledge about requested functionalities.According to one embodiment, messages are encrypted and / or signed and / or decrypted and / or signature verified in the computing system by the security module, with cryptographic keys used in this case being stored by the security module. The use of the security module is expedient since it is typically particularly secure against attacks. The security module can store keys, for example, in an internal and / or security module-specific memory and / or in a separate memory area, to which only the access module has access, of an external memory.According to one configuration, the provision request and / or the container request is generated by one of the at least one arithmetic unit of the computing system, in particular the one by which the requested functionality is to be implemented. Accordingly, the process is controlled by the arithmetic unit.According to one embodiment, the functionality container contains a program module and / or program parameters. The program module (or computer program module) can be executed by the computing unit in order to implement the functionality. Program parameters may be used to change the functionality of already installed program modules.A method according to the invention, which is carried out in a computing system having at least one computing unit and one security module, comprises signing, by the security module, a provision request which specifies a requested functionality using an authorisation key stored by the security module; sending the signed provision request to an access manager; receiving an access key for the requested functionality from the access manager; sending a container request for the requested functionality to a repository which stores a functionality container having the requested functionality. In this case, either the container request contains the access key and the method comprises receiving the functionality container from the repository and implementing the functionality by the at least one computing unit using the functionality container; or the functionality container is received as a cryptographically secured functionality container from the repository and the method comprises cancelling the cryptographically secured functionality container using the access key and implementing the functionality by the at least one computing unit using the functionality container.The method performed in a computing system having at least a computing unit and a security module may further comprise method steps mentioned in this application with respect to the system comprising the computing system, the access management and the repository, as far as they are performed by the computing system.A computing unit according to the invention, e.g. a control device of a motor vehicle, is configured, in particular by programming, to carry out a method according to the invention.The implementation of a method according to the invention in the form of a computer program or computer program product with program code for carrying out all method steps is also advantageous since this causes particularly low costs, in particular if an executing control device is also used for further tasks and is therefore present in any case. Finally, a machine-readable storage medium is provided with a computer program stored thereon, as described above. Suitable storage media or data carriers for providing the computer program are, in particular, magnetic, optical and electrical memories, such as hard disks, flash memories, EEPROMs, DVDs, among others. Download of a program via computer networks (Internet, intranet, etc.) is also possible. Such a download can be effected in a wired or wired or wireless manner (e.g. via a WLAN network, a 3G, 4G, 5G or 6G connection, etc.).Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawing.The invention is schematically illustrated in the drawing on the basis of exemplary embodiments and is described below with reference to the drawing.Brief Description of the DrawingsFIG. 1 shows, by way of example, the structure of a system in which the method according to the invention can be implemented. FIG. 2 shows a flow diagram of the method according to an embodiment of the invention. FIG. 3 is a flow chart according to a general embodiment of the invention.Embodiment(s) of the InventionFIG. 1 shows, by way of example, the structure of a system in which the method according to the invention can be implemented.A computer system 2, in particular in a vehicle 3, is shown here, which comprises a plurality of computing units or computing modules. In detail, computing units 4 (or control units) are shown which implement specific functionalities of the vehicle 3 by executing computer programs which are present, for example, in the form of computer program modules or computer program containers. Three arithmetic units are shown by way of example. In general, any number of computing units may be provided. In this application, the terms "program module" and "program container" are also used for the terms "computer program module" and "computer program container", respectively.Furthermore, security modules are shown, wherein a hardware security module 6 and a protected area 8 (secure enclave) are shown by way of example in a computing unit, e.g. based on a TPM, trusted platform module or the like). A security module provides security-relevant functions in the computer system and serves as a trust anchor, i.e. cryptographic functions provided by the security module and / or (cryptographic) keys or the like stored by the security module are considered to be trusted or protected against manipulations. At least one safety module is provided for the method according to the invention. In addition to the function as a trust anchor, security modules can be configured to execute the provided cryptographic functions at high speed, for example by realizing them by hardware circuits.A (central) communication module 10 is provided, which is configured to implement communication of data between the vehicle 3 or the computing system 2 and (vehicle) external computers or systems, e.g. by means of radio connections or mobile radio connections (for example by means of WiFi or by means of a 3G, 4G, 5G or 6G connection).A load distribution module 12 can be provided, which is configured to distribute computing loads (in particular the execution of specific program modules) between the computing units 4 depending on the load of individual computing units.The computing units 4, the safety modules 6, 8, the communication module 10 and, if appropriate, the load distribution module 12 are illustrated in FIG. 1 as separate units or modules, by way of example. In general, the computing units and / or computing modules or functions provided by them can be provided at least partially jointly in a computing unit. In particular, a safety module (hardware safety module 6, protected area 8) can be provided or implemented in one of the computing units 4. Likewise (and independently of the security module), the communication module 10 can be provided or implemented in one of the computing units 4. If necessary, the load distribution module 12 can be provided or implemented in one of the computing units 4 (independently of the security module and of the communication module).The system of FIG. 1 further comprises an access management 14 (or rights management) and a repository 16 for functionality containers 18. Both are provided remotely or externally from the vehicle and its computer system. The access management 14 is provided in a computer and / or computer system, for example a server and / or a server system. Similarly, the repository 16 (independent of access management) is provided in a computer and / or computer system, for example a server and / or a server system. These computers and / or computer systems are connected to a data communication system (for example the Internet) and are configured to exchange data with the vehicle or the communication module 12 via the data communication system. Data communication is therefore possible both between the vehicle or the communication module 12 and the access management 14 and between the vehicle or the communication module 12 and the repository 16.The access management 14 stores authorisation information, on the basis of which it can be determined which functionalities can be provided by a computing system or respectively. For this purpose, the authorization information comprises one or more cryptographic keys (or key information), referred to as confirmation keys. Each of the confirmation keys can be used within the scope of a cryptographic method to check the authenticity of provision requests. Provisioning requests are sent to and received from the access manager by computing systems (such as the one shown). Each provision request contains, in particular, an indication of at least one requested functionality which is to be provided in the respective computing system. Each acknowledgement key has associated with it one or more functionalities in the entitlement information, wherein, when authenticity of a provision request is acknowledged upon checking with the acknowledgement key, the sender of the provision request (i.e. the computing system that sent the provision request to access manager) is authorised to use or implement the one or more functionalities. As a cryptographic method for checking the authenticity of provision requests, an asymmetric cryptographic method can be used, wherein a provision request is signed with a cryptographic key called an authorisation key, which forms a key pair with the confirmation key (by the sender of the provision request) and checked with the confirmation key (by the access management).If the authenticity of a provision request is confirmed upon checking with the confirmation key and if the at least one requested functionality included in the provision request is included in the one or more functionalities associated with the confirmation key, the access manager 14 determines that the sender is authorized to implement the at least one requested functionality. In this case, the access manager 14 sends a message including an access key (access code or token) to the sender (computing system) of the provision request. The access key is transmitted in particular in encrypted form. The access key may be specific to the sender of the provision request, e.g. derived from a general access key, wherein information contained in the provision request is received.If the at least one requested functionality included in the provision request is not included in the one or more functionalities and / or if authenticity of a provision request is not confirmed upon checking with the confirmation key, the access manager 14 may determine that the sender is not authorized to implement the at least one requested functionality. In this case, the access manager 14 may be configured to not send a message to the sender (computing system) of the provision request or to send a message indicating that the provision request has failed.The repository 16 stores functionality data or functionality container 18 for a plurality of computer-implemented functionalities. In general terms, functionality containers contain data that enable a computing system or its computing units to provide (at least) one functionality. Functionality containers 18 may be present, for example, in the form of an executable program module and / or in the form of program parameters. A program module can be installed and executed in a computing unit, for example, in order to provide a corresponding functionality. Program parameters can be used to parameterize an already installed program module and, for example, influence its execution, so that in principle different functionalities corresponding to different parameterization are provided. The functionality containers 18 are each assigned access keys.The repository 16 is configured to receive messages, referred to as container requests, which each contain at least one access key and optionally specify at least one requested functionality container, and to transmit the at least one functionality container 18 to which the at least one access key is assigned or, after checking whether the at least one access key is valid for the at least one requested functionality container (e.g. is assigned thereto), to the sender of the container request. The container requirements are in particular encrypted.According to an alternative or additional embodiment, it can be provided that the repository 16 is configured to transmit the at least one requested functionality container 18 to the sender of the container request in response to a message, likewise referred to as a container request, in which at least one functionality container 18 is requested, wherein the container request contains no access key and / or said access key is not checked. In this embodiment, the functionality containers 18 are cryptographically secured, i.e. a receiver of a functionality container cannot initially implement the functionality provided therein. Only knowing the access key corresponding to the functionality container enables the functionality provided by the functionality container to be implemented. For example, the functionality container may be encrypted, wherein the access key may be used for decryption.Both approaches can be considered steps to confirm the validity of the access key. In any case, the functionality can be used or implemented only when the access key is validated. In the first of the above-mentioned approaches, the confirmation is carried out directly by the repository. In the second procedure, the confirmation takes place indirectly on the part of the receiver (computing system or computing unit) of the (cryptographically secured) functionality container.FIG. 2 shows a flow diagram of the method according to an embodiment of the invention. This embodiment constitutes a configuration of the first of the aforementioned procedures. It is a system corresponding to that shown in FIG. 1, wherein columns show a computing unit 4, a security module in the form of a hardware security module 6, a communication module 10, an access management 14 and a repository 16. The computing unit 4, the hardware security module 6 and the communication module 10 are, as explained in connection with FIG. 1, comprised in a computing system 2 (in particular of a vehicle). Instead of a hardware security module 6, another security module, for example a protected area 8, can also be used. Steps of the method are illustrated by arrows.The method shown is intended to provide a desired computer-implemented functionality by the computing unit 4 in the computing system 2 or vehicle.In step 110, the computing unit 4 first creates a provision request for the desired functionality and transmits a request to the hardware security module 6 to sign the provision request. The hardware security module 6 signs the provision request by means of an authorisation key stored by the hardware security module 6 and transmits the signed provision request to the computing unit 4 in step 120 (or notifies it where the signed provision request is stored, or that the signature is present, for example if corresponding predetermined memory areas are provided).The processing unit 2 transmits the signed provision request to the access management unit 14. In this case, in step 130, the signed provision request is initially transmitted from the processing unit 2 to the communication module 10 or the processing unit 2 notifies the communication module 10 specifying a memory area that the signed provision request is to be transmitted to the access management unit 14. The communication module 10 transmits the signed provision request to the access management 14 in step 140.In step 150, the access manager 14 checks the authenticity of the received (signed) provision request using an acknowledgment key as explained in connection with FIG. 1. If the authenticity (and thus the authorisation of the computing system to implement the functionality) is confirmed (valid signature) during the checking, the access management 14 transmits a corresponding access key in encrypted and in particular signed form to the communication module 10 of the computing system 2 in step 160.The encrypted and possibly signed access key is transmitted in step 170 from the communication module 10 to the arithmetic unit 4, which transmits it in step 180 to the hardware security module 6. In step 190, the hardware security module 6 decrypts the encrypted access key, checking the signature of the access key if necessary.In step 200, the HSM 6 encrypts the (decrypted) access key and optionally signs for the encrypted access key. This encryption is effected, for example, using a symmetrical encryption method, using a key which is known, in particular, only to the HSM 6 and the computing units of the computing system, so that, for example, attackers who listen to the data traffic in the computing system cannot get in possession of the key. Furthermore, a key can be used which is known only to the requesting computing unit 4 (and the HSM), so that other computing units in the computing system cannot get possession of this key.The access key encrypted and possibly signed by the HSM 6 is transmitted to the computing unit 4 in step 210. Also, the HSM 6 stores the (decrypted) access key (for further use in step 240). The arithmetic unit 4 verifies the encrypted and possibly signed access key, wherein in particular the digital signature (which was optionally generated by the HSM) of the key is verified.In the case of a successful verification, the computing unit 4 transmits, in step 230, a message to the HSM 6 with an indication (or path indication) of a storage location of the requested functionality container, the computer-implemented functionality which is to be provided by the computing unit 4 in the vehicle or computing system, and a specification of the requested functionality container. This specification is in particular a uniform resource locator (URL; for example "uniform resource locator") on German. This transmission can be effected cryptographically secured, i.e. the message with the indication can be signed by the computing unit and optionally encrypted.The HSM 6 can verify (i.e. check the signature of) the message with the specification of the storage location and the specification of the requested functionality container and, if appropriate, decrypt it. In step 240, the HSM 6 supplements the message specifying the location and specification of the requested functionality container with an encrypted version of the access key (cached in the HSM in step 210) to obtain a container request. The encryption to obtain the encrypted version of the access key is done so that only the repository 16 can decrypt it. For example, by means of an asymmetric encryption method, wherein a public key is used in the encryption.The message (container request) supplemented by the encrypted version of the access key is transmitted in step 250 from the HSM 6 to the computing unit 4, which transmits it in step 260 to the communication module 10. These transmissions can be secured again by means of a signature. The communication module transmits, if appropriate after (successful) verification of the signature, the message, or at least the specification of the requested functionality container and the encrypted version of the access key, as a container request in step 270 to the indication relating to the storage location, i.e. to the repository 16, contained in the message.The repository 16 decrypts the encrypted version of the access key, for example using a private key of the asymmetric encryption method mentioned in step 240, checks whether the access key that is valid for the requested functionality container (i.e. is assigned to it), and transmits the functionality container to the computing system 2, i.e. its communication module 10, in step 280 if the check is successful.The communication module 10 transmits the signed and optionally encrypted functionality container in step 290 to the computing unit 2, which in turn transmits the latter to the HSM 6 in step 300. The HSM 6 checks the signature of the functionality container and decrypts it if necessary. If the test is successful, the functionality container is transmitted in step 310 by the HSM 6 to the computing unit 4 (optionally secured again by a signature and / or encryption).In step 320 (optionally after checking the signature and / or decryption), the computing unit 4 implements the functionality provided in the functionality container. If the functionality container contains a program module, it is thus stored in a suitable memory and the execution of this program module by the computing unit is started. If the functionality container contains program parameters, at least one program module already present in the computing unit is modified with these program parameters and executed with these program parameters.In the embodiment of FIG. 2, a hardware security module 6 is assumed, the functionality of which is essentially limited to providing predetermined cryptographic functions (e.g. decryption, encryption, signing, signature checking) for the computing units 4. These functions are provided, for example, by a computing unit that requires a function transmitting data to which the function is to be applied to the hardware security module 6 and calling the hardware security module 6 to apply the function to the data. The data can be transmitted to the hardware security module 6 for example by the arithmetic unit writing the data to which the function is to be applied into predefined memory areas of the hardware security module 6 or writing memory addresses which indicate where the data to which the function is to be applied are stored into predefined address registers (or the like) of the hardware security module 6. Cryptographic keys (or the like) used by the cryptographic functions are stored by the hardware security module 6 and are in particular not known to the computing unit. When multiple keys are stored by the hardware security module, the invocation of the compute unit to the hardware security module to apply the function may include an indication of which key to use. The keys are designated for this purpose in a suitable manner, e.g. numbered.Due to the functionality of such a hardware security module 6 that is limited to the provision of cryptographic functions, it is in particular not able to communicate with the communication module 10 or the latter is not able to access the hardware security module and thus does not transmit data that are to be transmitted to other systems or are received by other systems directly to the communication module or receive data from it. This results in the structure shown, in which data to which the HSM 6 applies a cryptographic function and which are to be transmitted to an external system are not transmitted directly from the HSM to the communication module 10, but are first transmitted again to the computing unit and are transmitted from the latter to the communication module which communicates with the external system (e.g. steps 120 and 130 or steps 250 and 260). Data received from external systems by the communication module, to which a cryptographic function is to be applied by the HSM, is likewise not transmitted directly to the HSM, but first to the computing unit and then from the latter to the HSM (e.g. steps 170 and 180 or steps 290 and 300).In other embodiments, the security module may have further functionality, wherein the security module may transmit data to the communication module or may receive data from the communication module. In other words, communication or accesses between the communication module and the security module are then possible in the same manner or at least in a similar manner (e.g. restricted to a subset) as between the computing unit and the security module. In this embodiment, the intermediate step in which data is communicated between the security module and the computing module via the computing unit can be omitted (e.g. after step 110, the data, i.e. the signed provision request, is transmitted from the security module to the communication module, instead of steps 120 and 130). In this case, it is also conceivable for the arithmetic unit, communication module and security module to interact, for example the communication module transmitting data to the security module and the arithmetic unit causing a cryptographic function to be applied.FIG. 3 shows a flowchart according to an embodiment of the invention, in which the denomination of individual elements of the computing system that execute certain steps is largely omitted. The method relates to the provision of a computer-implemented requested functionality in a vehicle, which has a computing system having at least one computing unit and a security module.In step 410, a provision request specifying a requested functionality is signed by the security module using an entitlement key stored by the security module.In step 420, the signed provision request is sent from the computing system to an access manager.In step 430, the authenticity of the signed provision request is checked by the access management.In step 440, if the test is successful, the access manager sends an access key for the requested functionality to the computing system. If the test fails, the access key is not sent to the computing system, optionally sending an error message or the like.In step 450, a container request requested functionality is sent to a repository storing a functionality container having the requested functionality.Depending on how the validity of the access key is to be confirmed (cf. the description of FIG. 1, in particular of the repository), various procedures are possible. The first approach includes steps 460 and 465. The second approach includes steps 470 and 475.According to the first approach, the container request includes the access key. In step 460, the validity of the access key is checked by the repository. In step 465, if the validity check is successful, the functionality container is communicated to the computing system by the repository. If the test is not successful, the functionality container is not transmitted, wherein an error message or the like is optionally sent to the computing system.According to the second procedure, the functionality container is cryptographically secured in the repository, so that the implementation of the requested functionality is not possible without knowledge of the access key. The cryptographic protection can include, in particular, encryption. In step 470, the secured functionality container is transmitted to the computing system by the repository in response to the container request. In step 475, the cryptographic protection of the functionality container is canceled by the computing system using the access key. Cancelling the cryptographic protection comprises in particular decrypting. In particular, steps 470 and 475 may already be performed before step 420 or step 410 was performed, i.e., before the provision request.In step 480, when or after the validity of the access key is confirmed, the functionality is implemented by the computing unit using the functionality container in the computing system.

Claims

A method for providing computer-implemented functionality in a computing system (2) having at least one computing unit (4) and a security module (6, 8), comprising: signing (210), by the security module (6, 8), a provision request specifying a requested functionality using an entitlement key stored by the security module; sending (420) the signed provision request to an access manager (14); checking (430), by the access manager (14), the authenticity of the signed provision request; if the check is successful, sending (440), by the access manager, an access key for the requested functionality to the computing system (2); sending (450) a container request for the requested functionality to a repository (16) storing a functionality container (18) having the requested functionality; and when the validity of the access key is confirmed, implementing (480), by the at least one arithmetic unit (4), the functionality using the functionality container in the computing system (2).The method of claim 1, wherein the container request includes the access key, and further comprising, to confirm validity of the access key: checking (460), by the repository (16), validity of the access key; and if the checking of validity is successful, transmitting (465), by the repository, the functionality container to the computing system (2).The method according to claim 1, wherein the functionality container (18) is cryptographically secured, in particular encrypted, in the repository (16), such that the implementation of the requested functionality is not possible without knowledge of the access key, further comprising, in order to confirm the validity of the access key: transmitting (470), by the repository (16), the secured functionality container to the computing system (2) in response to the container request; and cancelling (475), in particular decrypting, by the computing system (2), the cryptographically securing of the functionality container using the access key.The method according to any of the preceding claims, wherein the access key is sent to the computing system (2) by the access manager (14) as an encrypted access key.Method according to claim 4, if dependent on claim 2, wherein the encrypted access key is decrypted by the security module (6, 8) and buffered by the security module without being transmitted to a computing unit (4) or another module of the computing system (2); wherein the access key is inserted into the container request by the security module (6, 8); and wherein the container request is encrypted by the security module after this insertion.Method according to claim 4, if dependent on claim 3, wherein the encrypted access key is decrypted by the security module (6, 8) and buffered by the security module without being transmitted to a computing unit (4) or another module of the computing system; wherein the cryptographic protection of the functionality container is canceled by the security module (6, 8).The method of any preceding claim, wherein the computing system (2) comprises a communication module (10); wherein communication with the access manager (14) and the repository (16) is via the communication module; wherein communication with the access manager (14) and the repository (16) includes sending the signed provision request, receiving the access key as part of sending the access key to the computing system, sending the container request to the repository, and, optionally, receiving the functionality container from the repository.Method according to one of the preceding claims, wherein the sending of the provision request and / or the sending of the access key and / or the sending of the container request and / or, if appropriate, the transmitting of the functionality container takes place in cryptographically secured form, wherein respective messages are encrypted and / or signed.Method according to Claim 8, wherein the encryption and / or the signing and / or the decryption and / or the signature checking of messages in the computing system are carried out by the security module (6, 8); cryptographic keys used in this case being stored by the security module.Method according to one of the preceding claims, wherein the provision request and / or the container request is generated by at least one computing unit (4) of the computing system (2), in particular the one by which the requested functionality is to be implemented.Method according to one of the preceding claims, wherein the functionality container (18) contains a program module and / or program parameters.A method performed in a computing system (2) having at least one computing unit (4) and a security module (6, 8), comprising: signing, by the security module (6, 8), a provision request specifying a requested functionality using an entitlement key stored by the security module; sending the signed provision request to an access manager (14); receiving an access key for the requested functionality from the access manager (14); sending a container request for the requested functionality to a repository (16) storing a functionality container (18) having the requested functionality; wherein the container request contains the access key and the method comprises: receiving the functionality container from the repository (16) and implementing the functionality by the at least one computing unit (4) using the functionality container (18); or wherein the functionality container is received as a cryptographically secured functionality container from the repository and the method comprises: cancelling the cryptographically secured functionality container using the access key and implementing the functionality by the at least one computing unit (4) using the functionality container (18).A computing system (2) configured to perform all method steps of a method according to claim 12.Computer program which causes a computing unit (4) of a computing system (2) to carry out all method steps of a method according to Claim 12 or to cause them to be carried out, in particular by the security module, when it is executed on the computing unit.A machine readable storage medium having stored thereon a computer program according to claim 14.

Citation Information

Patent Citations

  • US000010341304B1