METHOD AND DEVICE FOR TRANSMITTING A MESSAGE IN A SECURITY-RELEVANT INSTALLATION
Patent Information
- Application Number
- DE502018015857
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-06-22
- Filing Date
- 2018-06-06
- Publication Date
- 2025-06-26
- Estimated Expiration
- 2038-06-06
AI Technical Summary
Existing systems are vulnerable to Denial of Service (DoS) attacks, where overloaded receivers cannot process incoming messages, leading to service shutdown and potential targeted attacks, especially in safety-critical facilities.
A method where nodes in a network determine check values based on messages and decide whether to forward or block them, using settings that require attackers to exert significant effort to bypass security measures.
This method effectively prevents DoS attacks by increasing the effort required for malicious messages to reach receivers, making attacks unattractive and ensuring that only legitimate messages are processed.
Description
[0001] The invention relates to a method for transmitting a message in a security-relevant system from at least one sender to at least one receiver via a network with at least one node at which the message is received and forwarded towards the receiver.
[0002] Within data networks, such as the Internet, messages are constantly being transmitted from senders to recipients. Transmission occurs via nodes that determine the respective recipient of each message and forward the message accordingly. If a receiver is overloaded with too many incoming messages, this can lead to a denial of service at the receiver. This is known as a Denial of Service (DoS). In this case, for example, the number of messages for a recipient is so large that the recipient cannot process them all, causing the service to shut down. This can also be used for targeted attacks against a recipient and can therefore lead to significant problems.
[0003] US 2014 / 365775 A1 discloses a system and a device designed to prevent a DoS attack. US 2006 / 075084 A1 discloses a method designed to detect congestion in a Voice over Internet Protocol (VoIP).
[0004] This represents a serious problem that must be addressed, particularly in facilities with safety-critical functions, such as railway or military installations or nuclear power plants. To prevent this problem, in the past, only closed networks were used, to which only known participants had access. With the recent, more frequent use of open networks, anyone with access to the network can inject messages and block the network or certain recipients. Therefore, the IEC 62443 standard, for example, requires that measures be taken to protect availability.
[0005] The invention is therefore based on the object of providing a method of the type mentioned above which offers better protection against denial of service (DoS) attacks.
[0006] According to the invention, the object is achieved by the method mentioned at the outset in that at least one check value dependent on the message is determined and the message is forwarded or not forwarded by the at least one node depending on the determined check value.
[0007] Depending on the determined check value, the message is either blocked or forwarded to the recipient. If the determined check value for a message does not meet the set requirements, as is to be expected for messages intended to harm or paralyze the recipient, the message is blocked, does not reach the recipient, and therefore cannot cause any damage to the recipient. This can prevent a denial of service (DoS) at the recipient. Even a message with malicious intent can meet the check value requirements. However, this requires a certain amount of effort on the part of the attacker, which is not usually expected. The attack becomes too complex, and the attacker loses interest.
[0008] In the method according to the invention, protection against attacks is achieved by increasing the effort and thus the costs of an attack to such an extent that an attack becomes unattractive to a potential attacker. The method according to the invention can be integrated into the specification of a network protocol. Alternatively, the method according to the invention can of course also be based on an existing network protocol.
[0009] The invention can be further developed by advantageous embodiments which are described below.
[0010] According to the invention, check values of messages forwarded by the node are stored at least temporarily, and the message is not forwarded if the check value of the message matches one of the stored check values. This has the advantage that duplicates are easily identified and blocked. For example, each node can store a configurable number of check values of the most recent messages in a list. The check values of new messages are compared with the known check values in the list before forwarding and discarded if they match.
[0011] In order to further increase the effort required for an attacker, a setting value influencing the check value is determined according to the invention such that the check value fulfills a predetermined condition and the setting value is transmitted with the message, whereby the message is only forwarded by the node if the check value fulfills the predetermined condition. For example, the setting value is transmitted in a data packet together with the message. The setting value is determined, for example, by the sender before the message is sent and sent in the data packet with the message. In this embodiment, the check value is formed from the message and the setting value and must fulfill the specific condition. The condition can be, for example, that the check value is greater than, less than, or equal to a predetermined threshold value. The threshold value can, for example, be specified centrally.The condition is thus a kind of cryptographic puzzle that must be solved by selecting the setting value. The sender must therefore exert a certain amount of effort before sending to determine the setting value and thus solve the cryptographic puzzle. While all senders, including benign ones, must exert this effort, this very effectively fends off malicious senders because they will shy away from the effort. In order to respond dynamically to threats, the predetermined condition can be changed, particularly depending on network load. This allows the condition to be scaled depending on whether, for example, a DoS attack is detected or suspected. The effort required by a potential attacker, as well as by legitimate senders, is changed.
[0012] In a further advantageous embodiment, the check value can be determined taking into account a predefined default value that is not transmitted with the message. This has the advantage that the default value is independent of the message and, for example, is distributed centrally to the network participants and updated cyclically. Only with the current and correct default value will messages reach the correct check value and be transmitted. Messages that use an outdated default value are dropped and blocked.
[0013] To use simple and established functions, the check value can be determined using a hash function or checksum calculation. For example, to compare two hash values generated using a hash function, a natural number is derived from each hash value in a known way. The natural numbers thus determined can then be compared.
[0014] Furthermore, the procedure can be modified depending on network load. This has the advantage that a high network load can be used to suspect a DOS attack, thus allowing an immediate increase in security requirements.
[0015] To simplify the effort at the nodes, the check value can be appended to the message and / or forwarded with the message. The check value can, for example, be transmitted in the same data packet with the message. The invention further relates to a safety-relevant system, in particular a railway system, with at least one receiver and at least one network connected to the receiver for transmitting messages to the receiver, wherein the network has at least one node for receiving and forwarding messages for the receiver. To increase protection against denial of service attacks, the invention provides that the system is designed to apply the method according to one of the above-mentioned embodiments.
[0016] In the following, the invention is explained with reference to the attached figures and the exemplary embodiments shown therein.
[0017] They show: Figure 1 shows an exemplary embodiment of a safety-critical system according to the invention; Figure 2 shows a schematic representation of an exemplary embodiment of a data packet for use in the method according to the invention; Figure 3 shows a schematic representation of an exemplary embodiment of the method according to the invention.
[0018] Figure 1 shows a schematic representation of a railway system 1 with a sender 2, a receiver 3, and a network 4 between the sender 2 and the receiver 3. The network 4 has a node 5 that receives messages 6 and forwards them towards the receiver 3. The messages 6 are each part of data packets 7 that are sent within the network 4.
[0019] To protect the receivers 3 of the railway system 1 from so-called denial of service (DoS) attacks, the method according to the invention is applied in the network 4. When messages M are transmitted, additional information is sent in the data packet N.
[0020] As in Figure 2As shown, the data packet N includes, in addition to the message M, a setting value n and a check value H. In the exemplary embodiment of the figures, the check value H is a hash value determined using a hash function, which is determined as a function of the message M and the setting value n. Thus, H(M|n) applies. The setting value n is set by the sender 2 before sending the data packet 7 such that the check value H fulfills a predetermined condition. This condition is, for example, that the check value H is below a predetermined threshold value x H(M|n) <x. Alternativ kann die Bedingung selbstverständlich auch sein, dass der Prüfwert H oberhalb oder gleich dem Schwellwert x ist. Der Absender 2 löst ein kryptografisches Puzzle, um den Einstellwert n zu bestimmen.
[0021] A cryptographic puzzle P is a task that, in principle, can only be solved by trial and error—analogous to a real puzzle with a single-color pattern. An example cryptographic puzzle P is to find a value for the setting value n such that, for a fixed message M, the check value H (M, n) is smaller than the specified threshold x.
[0022] In the following, an exemplary embodiment of the method according to the invention is described with reference to the schematic flow diagram in Figure 3 explained.
[0023] In step 10, node 5 first receives the data packet N, which contains the message M to be transmitted. The data packet N comprises the message M and a cryptographic puzzle P, which depends on the message M, a check value a, the setting value n, and the threshold value x.
[0024] During the first test in the following method step 20, it is checked whether the check value H from the data packet N occurs in a list L. The check values H of the last data packets N are stored in the list L. In the embodiment in Figure 3 For example, the list L contains a number w of the last check values H. The list L is constantly updated with newly transmitted data packets N, i.e., new check values H are included and the oldest check values H are removed, for example, like a shift register. If it is determined in step 20 that the check value H of the current data packet N occurs in the list L, it is a duplicate of an old data packet and the forwarding of the current data packet N is prevented. Figure 3The list L is stored in block 30, to which step 20 has access. The discarding of the data packet M and the associated blocking is shown in method step 40. If the check value H does not occur in the list L, the current check value H is added to the list L and the method continues with step 50.
[0025] In the next step 50 of the method according to the invention, it is checked whether a predetermined cryptographic puzzle P has been solved. The puzzle P takes into account the message M and the setting value n, both of which are present in the data packet N, and the predetermined check value a and the threshold value x, both of which are present in the module 60. If this check in step 50 leads to the predetermined correct solution, the data packet N and thus the message M are forwarded to the receiver 3 in step 70. If step 50 does not lead to the correct solution, the data packet N and thus the message M are not forwarded to the receiver 3 and are discarded in step 40.
[0026] The one in step 50 in the embodiment in Figure 3 used cryptographic puzzle P has the condition that the check value H of the message M, the setting value n and the check value a is smaller than the threshold value x.Both the threshold x and the check value a can be specified centrally (not shown). The check value a is updated cyclically by the central location. The threshold x can also be specified decentrally and scaled, for example, depending on the load on network 4. If network 4 is under high load, a denial of service (DoS) attack could occur, and the threshold x is changed in such a way that the effort required to create the data packet N is increased. Although this also involves more effort for benign senders 2, it also fends off malicious senders.
[0027] The Figure 3The method illustrated is only one possible embodiment of the method. Other embodiments are possible. For example, steps / blocks 20, 30 or, alternatively, steps / blocks 50, 60 may be omitted. Block 60 may alternatively have more or fewer parameters.
Claims
1. Method for transmitting a message (M) in a safety-relevant installation (1) from at least one sender (2) to at least one receiver (3) via a network (4) with at least one node point (5), at which the message (M) is received and forwarded in the direction of the receiver (3), wherein at least one test value (H) dependent upon the message (4) is ascertained and the message (M) is forwarded or not forwarded from the at least one node point (5) as a function of the ascertained test value (H), characterised in that test values (H) of messages (M) forwarded from the node point (5) are stored at least temporarily and the message (M) is not forwarded if the test value of the message (M) corresponds to one of the stored test values (H), and a setting value (n) influencing the test value (H) is determined such that the test value (H) meets a predefined condition, and the setting value (n) is transmitted with the message (M), wherein the message (M) is only forwarded from the node point (5) if the test value (H) meets the predetermined condition.
2. Method according to claim 1, characterised in that the condition used is that the test value (H) is greater than or less than or equal to a predetermined threshold value (x).
3. Method according to claim 2, characterised in that the threshold value (x) is predefined by a central authority.
4. Method according to claim 1 or 2, characterised in that the predetermined condition is modified, in particular as a function of a utilisation of the network (4).
5. Method according to one of the aforementioned claims, characterised in that the test value (H) is ascertained while taking into consideration a predefined default value (a) that is not transmitted with the message (M).
6. Method according to one of the aforementioned claims, characterised in that the test value (H) is ascertained by means of a hash function or checksum formation.
7. Method according to one of the aforementioned claims, characterised in that the method is modified as a function of a utilisation of the network (4).
8. Method according to one of the aforementioned claims, characterised in that the test value (H) is attached to the message (M) and / or is forwarded with the message (M).
9. Safety-relevant installation with at least one receiver (3) and at least one network (4) that is connected to the receiver (3) for the transmission of messages (M) to the receiver (3), wherein the network (4) has at least one node point (5) for receiving and forwarding messages (M) for the receiver (3), characterised in that the installation is embodied to apply the method according to one of the aforementioned claims.
10. Safety-relevant installation according to claim 9, characterised in that the installation is embodied as a railway engineering installation (1).