Device for testing IT systems and computer program product
The device addresses the risk of internet-based testing by providing a USB-connected, offline IT system testing solution with secure data processing and automated evaluation for comprehensive vulnerability assessment.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2026-01-26
- Publication Date
- 2026-04-02
AI Technical Summary
Existing IT system vulnerability testing methods are risky due to internet-based data transmission and are ineffective for systems not connected to a network.
A device with a USB interface and electronic circuitry that directly connects to IT systems, allowing offline testing, data storage, and processing, featuring encryption and automated evaluation, and includes a database for recognizing and responding to various systems.
Enables secure, offline testing of IT systems with automated data processing and reporting, ensuring unauthorized access prevention and efficient vulnerability identification.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a device for testing IT systems according to the preamble of claim 1 and to a computer program product.
[0002] It is common practice to use specialized software to check for vulnerabilities in IT systems. This software typically runs on a server on the internet and checks the IT system, which is also accessible via the internet, for vulnerabilities. However, a disadvantage is that data transmission over the internet is risky, and some IT systems to be checked are not connected to the internet at all.
[0003] The object of the invention is to create a device for testing IT systems which enables the testing of a wide variety of IT systems in a particularly simple and safe manner.
[0004] This task is accomplished by a device for testing IT systems, which comprises an electronic circuit with a processor for executing an operating system and stored program code, as well as an interface for temporary connection to the IT system under test. The direct connection of the device to the IT system allows for the testing of IT systems that are not connected to a network or the internet. Furthermore, the test results can be stored directly in the device and automatically processed, evaluated, and used to derive further actions, thus reliably preventing unauthorized access to the data.
[0005] The USB interface is particularly advantageous. This has the benefit that most common IT systems have a corresponding USB interface, making it especially easy to connect the device to these systems. Furthermore, the USB interface allows for extensive intervention in the IT system under test, as the device identifies itself to the IT system as a Human Interface Device (HID).
[0006] Furthermore, the electronic circuitry of the device can be advantageously designed to draw the electrical energy required for operation exclusively via the interface, in particular the USB interface. This eliminates the need for an external energy storage device, such as a battery, while still allowing the device to be portable.
[0007] To prevent unauthorized access to the data by third parties, it can be advantageous for the processor to have an encryption function. This prevents the data from being intercepted and reused, even in the event of physical contact with the processor.
[0008] Furthermore, the electronic circuit can be configured to store an operating system, which advantageously runs independently when powered. This ensures that when the device is connected to an IT system under test, the operating system starts automatically and executes the stored program code, significantly simplifying the testing of the IT system. The operating system can include a "secure boot" mechanism for encrypting partitions.
[0009] The device can be further configured to send and / or receive data from the temporarily connected IT system via its interface. This enables the device to send a wide variety of commands to the IT system under test and to receive and evaluate the IT system's response. Based on the received data, the operating system can select which additional data to send to enable specific testing. The operating system can also select the data to be sent based on the IT system under test. The device can be configured to recognize the IT system under test. To this end, the device can include a database with information on various IT systems, allowing it to send specific data for testing the IT system based on the recognized system. Furthermore, the device extends...The operating system learns from this database and can therefore also react to foreign / unknown systems.
[0010] Additionally, the operating system can be configured to process, evaluate, document, and preferably encrypted the data transmitted to and / or received from the temporarily connected IT system. This also enables the potentially automatic generation of test reports with an assessment of risks and the security level. For example, images can be automatically recognized and screenshots of the IT system under test can be taken for the test report. The processing and evaluation of the data preferably take place exclusively via the electronic circuitry or processor, and the data to be evaluated is not disclosed.
[0011] For particularly easy operation, the device may include a display unit, in particular an e-paper display, and / or at least one input unit. Information can be displayed via the display unit, and commands can be sent to the device via the input unit. The display unit and the input unit can also be combined into a touchscreen.
[0012] Furthermore, the device may also include a radio module, in particular a Wi-Fi and / or Bluetooth module, which may also allow the radio interfaces of the IT system under test to be checked for vulnerabilities.
[0013] Furthermore, the device may also include a modem, in particular a radio modem, which enables, for example, the retrieval of software updates from the Internet, especially via the 4G or 5G network.
[0014] A method for testing an IT system is also described, in which the described device is connected to a corresponding interface of the IT system via its interface, and the device then sends data to the IT system. Such an automated process enables a particularly simple and rapid testing of the IT system. The device can send a variety of data, especially commands, to the IT system to identify vulnerabilities. The data can be retrieved from the device's data storage, if necessary individually depending on the specific IT system.
[0015] The device can document the data transmitted to and / or received from the connected IT system and store it in a data storage device, preferably encrypted, which is helpful for logging the test.
[0016] Furthermore, a computer program product is also claimed, which includes the instructions that, when the program is executed by the processor of the device, cause it to execute the described method.
[0017] Further features and advantages of the invention will become apparent from the following description of a preferred embodiment based on the Fig. 1.
[0018] In Fig. Figure 1 shows a schematic representation of a device 1 for testing IT systems. The device 1 comprises a housing 4 formed from a lower part 2 and an upper part 3, in which an electronic circuit (not shown here) with a processor for executing stored program code is arranged. The electronic circuit also includes an interface 5 (shown only schematically here) for temporarily connecting the device 1 to an IT system under test.
[0019] The device 1 can be physically connected directly to a corresponding interface of an IT system via interface 5, which is preferably designed as a USB interface. For example, interface 5 can be designed as a USB plug that is inserted into a USB socket of an IT system. A corresponding USB plug can also be permanently connected to the electronic circuit or the housing 4, so that the device 1 is designed similarly to a USB flash drive.
[0020] Alternatively, interface 5 can also be designed as a socket, in particular a USB socket, into which a (USB) connection cable can be plugged. Alternatively, interface 5 can also be designed as a USB plug, which is connected to the electronic circuit in the housing 4 via a suitable cable.
[0021] The device 1 preferably has particularly compact dimensions, in particular it is provided that each side of the cuboid housing 4 is shorter than 15 cm, in particular shorter than 10 cm.
[0022] In addition, in this embodiment, an e-paper touch display 6 with an outward-facing graphical surface is provided in the upper part 3 of the housing 4, which enables the display of data and the input of commands.
[0023] The electronic circuit is designed such that the electrical energy required for operation is drawn exclusively via interface 5 when connected to an IT system under test. Consequently, no energy storage device, in particular no battery, is provided in the housing 4. Reference symbol list: 1 Device 2 lower part 3 Top 4 cases 5 Interface 6 E-Paper touchscreen
Claims
[1] Device (1) for testing IT systems comprising an electronic circuit with a processor for executing a stored program code and an interface (5) for temporary connection with an IT system to be tested. [2] Device (1) according to claim 1, characterized by , that the interface (5) is designed as a USB interface. [3] Device (1) according to claim 1 or 2, characterized by , that the electronic circuit is designed to obtain the electrical energy required for operation exclusively via the interface (5), in particular the USB interface. [4] Device (1) according to any one of the preceding claims, characterized by that the processor has an encryption function. [5] Device (1) according to any one of the preceding claims, characterized by, that the electronic circuit is designed to store an operating system which runs independently when powered on. [6] Device (1) according to claim 5, characterized by , that the operating system is trained to send data to and / or receive data from the temporarily connected IT system via the interface (5). [7] Device (1) according to claim 6, characterized by , that the operating system is trained to recognize the IT system to be tested and to select the data to be sent depending on the IT system to be tested and / or based on received data. [8] Device (1) according to claim 6 or 7, characterized by that the operating system is designed to document the data transmitted to and / or received from the temporarily connected IT system and to store it in a data storage device, preferably encrypted. [9] Device (1) according to any of the preceding claims, characterized by a display device (6), in particular an e-paper display, and / or input devices. [10] Device (1) according to any of the preceding claims, characterized by a radio module, in particular a Wi-Fi and / or Bluetooth module. [11] Device (1) according to any of the preceding claims, characterized by a modem, especially a radio modem. [12] Computer program product for testing an IT system comprising the commands which, when the program is executed by a processor of a device (1), cause it to send data to the IT system after a connection via the interface (5) with a corresponding interface of the IT system. [13] Computer program product according to claim 12 comprising the instructions which, when the program is executed by the processor of the device (1), cause it to send a variety of data, in particular instructions, to the IT system in order to identify vulnerabilities. [14] Computer program product according to claim 13 comprising the instructions which, when the program is executed by the processor of the device (1), cause it to recognize the IT system to be tested and to select the data to be sent depending on the IT system to be tested and / or on the basis of received data. [15] Computer program product according to claim 14, comprising the instructions which, during the execution of the program by the processor of the device (1), cause it to document data transmitted to the connected IT system and / or data received from it and to store it in a data storage device, preferably encrypted.