Procedure for managing a data set

The method for secure data management using a data storage device with unique identifiers and security checksums addresses data corruption and unauthorized access in sensitive data transmission, ensuring reliable and secure data storage and transmission.

DE102024205203A1Pending Publication Date: 2025-12-11ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102024205203
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-06
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing data management systems fail to securely store and transmit sensitive data for devices like drives and sensors, particularly in environments where stringent security standards like DIN EN 61508, DIN EN IEC 61784, and DIN EN ISO 13849 are required, with 'black' communication channels posing risks of data corruption and unauthorized access.

Method used

A method involving a data storage device associated with the device, using a data record with a unique identifier, device identifier, and a key, along with security checksums and data checksums, ensures secure storage and transmission by verifying the device identifier and key during write and read operations, and periodically updating the key to prevent unauthorized access.

Benefits of technology

Ensures secure and reliable storage and transmission of sensitive data, preventing data corruption and unauthorized access, meeting stringent security standards by detecting errors and ensuring data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for managing a data record for a device with respect to a data storage device associated with the device, in particular mechanically connected to the device, wherein the data record (200) has a data record identifier (230), a device identifier (232) and a key (222), wherein the data record identifier is assigned to the data record, and wherein the device identifier is assigned to the device, comprising: for storing the data record: receiving and storing the data record (200) in the data storage device based on the device identifier, and for outputting the data record: reading and outputting the data record from the data storage device based on at least one of the device identifier and the key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method for managing a data set for a device in relation to a data storage device associated with the device, a computing unit and a computer program for carrying it out, as well as a system with such a device. Background of the invention

[0002] In various areas, it may be necessary to securely manage certain data, such as parameters for specific devices like drives and associated sensors and actuators; that is, the data should be protected against errors when storing it in memory, reading it, or transmitting it. Disclosure of the invention

[0003] According to the invention, a method for managing a data set, a computing unit and a computer program for its execution, as well as a system with the features of the independent claims, are proposed. Advantageous embodiments are the subject of the dependent claims and the following description.

[0004] The invention generally relates to devices for which data, such as specific parameters, need to be handled and stored securely. For this purpose, a data storage device associated with the device can be provided. A concrete example, which will be used to explain the invention in more detail below, is a drive or motor (the device) to which an encoder (a so-called rotary encoder or angle encoder, i.e., generally an additional device component) is assigned. However, the invention is also applicable to other types of devices where data needs to be stored or output securely. In the field of drive technology, this could, for example, involve storing secure data in the power section of a drive controller, data that describes the properties of the power section. Generally, data describing the properties of machine elements to which the memory is mechanically connected can be stored in the memory (data storage).The encoder, for example, is connected to the motor. The motor, in turn, is typically connected to a machine element. The memory can contain data from the motor and / or data describing the machine element.

[0005] An encoder is, for example, a sensor that can detect the position or angle of a shaft in a drive or motor and output it as a digital signal. Such an encoder can have a data storage unit in which data, i.e., a data record, can be stored. This data record can consist of one or more parameters that, for example, describe the encoder or its functionality in more detail. The data stored in the encoder, or the data record, can also describe properties of the motor or drive, i.e., properties of the device to which the data storage unit is assigned, or more generally, properties of the machine element to which the motor is connected.

[0006] In addition, the encoder can also include a processing unit with a processor or microcontroller, which manages the data on or in the data storage. The data storage can therefore also be part of the processing unit.

[0007] In an encoder, or rather its data storage, data can be stored via a parameter channel from an evaluation unit. The encoder provides an address space for this purpose in its data storage, for example, a retentive memory. The evaluation unit could be, for example, a drive controller or a control unit. More generally, however, it can also refer to any other external computing unit (i.e., external to the encoder or the data storage).

[0008] The data can be transferred for this purpose via, for example, a communication interface between the evaluation unit and the encoder or its data storage.

[0009] The storage and use of secure or security-relevant data generally requires stricter standards than non-security-relevant data. This includes, for example, requirements for security technology, such as those specified in DIN EN 61508, DIN EN IEC 61784, DIN EN ISO 13849, etc.

[0010] The communication paths of data from a source, such as a PC with an engineering tool, to the secure storage location (in this case, the encoder's memory unit) via, for example, a fieldbus, or via non-safety-enabled devices such as controllers or drive regulators, are referred to as "black" channels. This means that such channels are not implemented safely.

[0011] Against this background, a procedure is proposed that allows for the secure management of a data record for a device with respect to a data storage device assigned to that device – that is, storing and / or reading (and then outputting) the data record to and from the data storage device. This can also be described, for example, as parameterizing the device or the device's additional component. In particular, the data storage device is also mechanically connected to the device, thus enabling a permanent association.

[0012] Each data record consists of a data record identifier, a device identifier, and a key. It goes without saying that the data record can also contain user data. To store the data record in the data storage system, the data record is received and then stored based on the device identifier. Retrieving the data record from the data storage system, on the other hand, is done based on the key and / or device identifier. The retrieved data record can then be output.

[0013] The record identifier is assigned to the record; that is, it is an identifier suitable for identifying the record itself. It can also be referred to as an ID or parameter ID. This is, for example, a number that uniquely describes which record (or parameter it contains) is being referred to. If a black channel were to transpose the record identifier during writing or reading, this can be detected because the record identifier is embedded within the record itself.

[0014] The device identifier is assigned to the device. This identifier can be, for example, the device's serial number or another unique identifier or ID. This ensures that a received data record can be correctly assigned to the device, meaning that the data originates from the expected storage location (e.g., the serial number of the motor).

[0015] In one embodiment, the data record is stored in the data memory at a location specified by the device identifier (e.g., a specific address or memory address). When writing via a black channel, this ensures that the data record (or the contained parameter) is correctly located during subsequent read operations. The address for this memory location is, for example, the serial number (SN) of the device in which the encoder is installed. The serial number is typically printed on the outside of the motor (or other device) and can be used for verification.

[0016] In one embodiment, a device identifier is stored in the data storage, separately from the data record. Alternatively, the device identifier could be stored in a separate data storage device that is assigned to the device, particularly one that is mechanically connected to the device and / or the data storage device. The device identifier, e.g., the serial number, can be reliably written to the encoder or the data storage device during production. Storing the data record in the data storage device then expediently includes comparing the device identifier from the data record with the device identifier in the data storage device. Similarly, reading and outputting the data record can also include comparing the device identifier from the data record with the device identifier in the data storage device. Expediently, the data record is only stored in or output to the data storage device if the device identifier from the data record matches the device identifier in the data storage device.If the two device identifiers do not match, this indicates an error. The device identifier, e.g., the serial number of the motor, can therefore become part of any secure data record.

[0017] When a data record or secure parameter is written to the encoder, the device identifier (e.g., the serial number) contained in the data record or parameter can be checked. When a data record or parameter is read from the encoder, it can be verified, for example, by the encoder itself, that the device identifier is contained in the data record or parameter.

[0018] The key ensures that the data record is up-to-date, meaning it is the most recently written record and not an outdated one. In one embodiment, reading and outputting the data record from the data storage involves receiving a key, for example, from an external processing unit (e.g., the aforementioned evaluation unit). The external processing unit can generate the key, for example, using a random number generator. The data record containing the received key is then output, particularly to the external processing unit.

[0019] A key previously contained in the data set is replaced, in particular, by the received key, i.e., a current key. The key in the data set can be removed from the data stored in the data memory after a predetermined period, for example, by initializing it with a default value. It is conceivable that the key is replaced by the value or the number zero. The key can also be initialized in this way when the encoder is initialized (e.g., when the power is switched on). While such a default value is technically a key, it is not a valid key with which reading the data in the aforementioned sense would be possible.

[0020] Furthermore, it may be stipulated that the external computing unit compares the key from the received data set with the key previously transmitted by the external computing unit. Only if these two keys match can the secure transmission of the data set be assumed.

[0021] In one embodiment, the data set also includes a data checksum, where the checksum is calculated over a portion of the data set comprising user data and the data set identifier. Such a data checksum, e.g., a CRC, can further enhance security.

[0022] In one embodiment, the data set further includes a security checksum, wherein the security checksum is calculated over a portion of the data set that comprises the device identifier and the key, and which specifically also includes the data checksum. Such a security checksum, e.g., a CRC, can further enhance security.

[0023] The storage of the data set in the data memory, and thus the stored data set itself, can be used by various application levels. For example, an encoder manufacturer can use this to store encoder properties necessary for the reliable evaluation of the safety parameters generated by the encoder. Similarly, a motor (or other device) manufacturer can use this to store properties of the motor in which the encoder is installed, properties required for safe motor functions. This might be necessary, for example, to generate a safe torque. A safety evaluation unit can also utilize this; for instance, the safety functions in the controller or drive can use the storage of their safety parameters in the encoder to reliably transfer these parameters from the old device to the new one when replacing the device (this is then a programming module function).A mechanical engineer can also use this to, for example, document safety-relevant properties of the mechanics in which the motor is installed.

[0024] A computing unit according to the invention (i.e., generally a system for data processing), e.g., a computing unit of an encoder, is, in particular in terms of programming, configured to carry out a method according to the invention.

[0025] The invention also relates to a system comprising a device, a computing unit according to the invention, and a data storage device associated with the device. The data storage device can also be part of the computing unit. For example, the system can thus comprise a motor with an encoder and a computing unit with data storage contained therein.

[0026] Implementing a method according to the invention in the form of a computer program or computer program product with program code for carrying out all method steps is also advantageous, as this incurs particularly low costs, especially if an executing control unit is already available for other tasks. Finally, a machine-readable storage medium is provided with a computer program stored on it as described above. Suitable storage media or data carriers for providing the computer program are, in particular, magnetic, optical, and electrical storage media, such as hard drives, flash memory, EEPROMs, DVDs, etc. Downloading a program via computer networks (Internet, intranet, etc.) is also possible. Such a download can be wired or wireless (e.g., via a WLAN network, a 3G, 4G, 5G, or 6G connection, etc.).

[0027] Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawing.

[0028] The invention is schematically illustrated in the drawing using an exemplary embodiment and is described below with reference to the drawing. Brief description of the drawings Fig. Figure 1 schematically shows a device to illustrate the invention. Fig. 2 schematically a data set to explain the invention. Fig. Figure 3 schematically shows the sequence of a procedure in one embodiment. embodiment(s) of the invention

[0029] In Fig. Figure 1 schematically and exemplarily illustrates a device 100 designed as a drive or motor for the purpose of explaining the invention. The motor 100 has a motor shaft 102. An encoder 110 is also associated with the motor 100, by means of which, for example, a position or angle of the motor shaft 102 can be determined.

[0030] The encoder 110 is also shown in an enlarged view, which shows that the encoder 110 has, for example, a computing unit 112 and a data memory 114, e.g., designed as part of the computing unit 112. The data memory 114 is thus also assigned to the motor 100.

[0031] Furthermore, an external computing unit 120, designed as an evaluation or control unit, is provided, which here – again only as an example – is assigned to the motor 100. For instance, the external computing unit 120 can read data from the data storage device 114. The evaluation unit 120 can be, but does not have to be, mechanically connected to the motor 100. If the evaluation unit 120 is connected to the motor 100, the data set can also be stored in the evaluation unit 120 using the same concept; that is, the data storage device can be located in the evaluation unit 120. This would also ensure a clear assignment of the data storage device 114 to the motor 110.

[0032] Furthermore, an example computer 130 is shown, which can also be an external computing unit, and by means of which, for example, initial data can be stored on the data storage device 114. The computer 130 typically communicates with the encoder 110 via the evaluation unit 120.

[0033] For the sake of clarity, the communication links or data channels required for storing and / or reading data into or from data storage 114 are not shown here.

[0034] In Fig. Figure 2 schematically shows a data set 200 to illustrate the invention. The data set 200 can, for example, be stored in the data storage device 114 according to Fig. Data is stored at position 1 and then read and output from there. For example, data record 200 could be a parameter with a length of 2 bytes.

[0035] Data record 200 contains various components or fields, labeled 202 to 224, which include different values ​​or information and are explained below. 202 represents the actual length, and 204 the maximum length. The length includes, for example, the total number of bytes of user data and backup data (serial number, etc.). The maximum length is typically determined by the reserved memory area. The user data length, on the other hand, is usually variable and can be set by the user. The number of bytes for backup data is typically constant. Fields 206 to 208 (with potentially additional fields not shown here) contain data (i.e., one data point per field) and thus the fields that contain, or can contain, specific values ​​from the data record. These are therefore the so-called user data.

[0036] 210 and 212 are each part of a data record identifier, which is collectively designated as 230. For example, 210 can be the first part and 212 the second part of the data record identifier 230.

[0037] Number 214 is a data checksum calculated from a portion of data record 200; in the example shown, the data checksum 214 is calculated from fields 206 to 212, i.e., user data and data record identifier. The security checksum can be, for example, a CRC (Counter-Reference Code).

[0038] The numbers 216, 218, and 220 are each part of a device identifier, e.g., a serial number of motor 100 according to... Fig. 1, which is designated as 232 in its entirety. For example, 216 can be the first part, 218 the second part, and 220 the third part of the device identifier 232.

[0039] Number 222 is a key, and number 224 is a security checksum calculated from a portion of data record 200; in the example shown, the security checksum 224 is calculated from fields 214 to 222, and thus also the data checksum 214. The security checksum can be calculated, for example, as a CRC (Counter-Reference Code).

[0040] In Fig. Figure 3 schematically illustrates the sequence of a procedure in one embodiment. The procedure, or the steps described herein, can be implemented, for example, on the computing unit 122 according to... Fig. 1, and possibly also the external computing unit 120 or 130.

[0041] In this process, a data set such as data set 200 is used according to Fig. 2 in a data storage device such as data storage device 114 according to Fig. 1 filed or read from it and output.

[0042] First, the storage process will be explained in more detail using one embodiment as an example. For this purpose, in step 300, the data record 200 is received and, in step 302, stored in the data memory; this is done based on the device identifier 230.

[0043] In step 304, a device identifier stored on the data storage device can be compared with the device identifier 230 contained in the received data record 200. Ideally, both device identifiers should be identical; the data record is then stored. This can mean, in particular, that data record 200 is stored in the data storage device at an address or storage location 306 determined by the device identifier.

[0044] If, however, the two device identifiers do not match, an error occurs and the data record is not stored in the data storage.

[0045] Next, the output process will be explained in more detail using an embodiment. For this purpose, in step 320, a key 322 is received, for example, from the external processing unit 120. The key 322 can be generated in the external processing unit, for example, using a random number generator. The received key can then be inserted, for example, into the data record 200.

[0046] Furthermore, in step 324, the device identifier stored on the data storage device is compared with the device identifier 230 contained in data record 200. Ideally, both device identifiers should be identical; the data record is then output in step 326, for example to the external processing unit.

[0047] If, however, the two device identifiers do not match, an error has occurred and the data record will not be output.

[0048] In the external processing unit, the key from the output and received data set (step 328) can then be compared again with the previously transmitted key. If the two keys do not match, an error occurs and the data set is, for example, no longer used.

[0049] Furthermore, in step 330, the key in the data record on the data storage, which was replaced as described previously, can be replaced with a null value after a predetermined period of time. A new key must then be received for further interpretation.

[0050] In addition to the above-described possibilities for making the data set itself, as well as its storage and retrieval, secure, further possibilities can be considered.

[0051] To increase safety, or the so-called safety level, the safe parameters or the data set can be stored redundantly in the encoder or the data memory. If the encoder is a dual-channel design, a parameter is stored, for example, in each of the two safe channels.

[0052] It can also be ensured that the parameters or data set have arrived in the encoder or data memory and have been stored permanently. For example, the encoder's supply voltage can be switched off and on again between writing the stored parameters and reading them back.

[0053] Furthermore, it can be configured that a data source from which the data set is received reads the written secure parameters back from the encoder and checks their validity. If the read operation is successful, the data or data set is compared with the originally written data (i.e., the complete data set and not just, for example, the device identifier or the key). They must be identical. If this is not the case, an error occurs.

[0054] The aforementioned options or measures for the secure management of data can eliminate various possible errors, especially according to DIN EN 61784-3.

[0055] The (secure) key can, for example, rule out errors caused by existing old data being stored instead of the new data, as well as incorrect storage locations. The device identifier can also rule out these errors, in addition to data corruption and masquerading (i.e., data from an unsecure source being mistaken for data from a secure source). The data record identifier can rule out data corruption, parameter swapping, and masquerading.

Claims

[1] Method for managing a data set for a device (100) in relation to a data storage device (114) which is associated with the device, in particular mechanically connected to the device, wherein the data record (200) has a data record identifier (230), a device identifier (232) and a key (222), wherein the data record identifier is assigned to the data record, and wherein the device identifier is assigned to the device, comprehensive: For storing the data record: Receiving (300) and storing (302) the data record (200) in the data storage (114) based on the device identifier, and for outputting the data set: Read and output (326) the data set from the data store, based on at least one of the device identifier and the key. [2] Method according to claim 1, wherein the storage (302) of the data record in the data storage takes place in a storage location (306) in the data storage specified by the device identifier. [3] Method according to claim 1 or 2, wherein a device identifier (230) is stored in the data storage or another data storage which is assigned to the device, in particular mechanically connected to the device and / or the data storage, and wherein a) storing the data record in the data storage and / or b) reading and outputting the data record from the data storage: Matching (304, 324) the device identifier from the data set with the device identifier in the data store or the other data store. [4] Method according to claim 3, wherein the data set is only a) stored in the data storage and / or b) output if the device identifier (230) from the data set (200) matches the device identifier in the data storage or in the other data storage. [5] Method according to any of the preceding claims, comprising reading and outputting the data set from the data storage: Receiving (320), in particular from an external computing unit, a key (322); and Output (326) of the data set containing the received key, in particular to the external computing unit. [6] Method according to claim 5, wherein the key in the data record is removed from the data record stored in the data storage after a predetermined period of time (330), in particular by initialization with a default value. [7] Method according to claim 5 or 6, further comprising: Matching (328) the key from the received data set with the key transmitted by the external computing unit. [8] Method according to any of the preceding claims, wherein the device identifier comprises a serial number of the device. [9] Method according to any of the preceding claims, wherein the data set further comprises a data checksum, wherein the data checksum is formed over a part of the data set comprising user data and the data set identifier. [10] Method according to any of the preceding claims, wherein the data set further comprises a security checksum, wherein the security checksum is formed over a part of the data set which includes the device identifier and the key, and which in particular, with reference to claim 9, includes the data checksum. [11] Method according to any of the preceding claims, wherein the device is designed as a drive or motor, and wherein the data storage is part of an encoder. [12] Computing unit comprising means for carrying out the method according to any of the preceding claims. [13] System comprising a device, a computing unit according to claim 12, and a data storage device associated with the device. [14] Computer program comprising instructions which, when the program is executed by a computer, cause it to execute the method according to claims 1 to 10. [15] Computer-readable storage medium on which the computer program according to claim 14 is stored.

Citation Information

Patent Citations

  • Method and apparatus for expiring encrypted data

    US20060210085A1