FILTER, ARRANGEMENT AND OPERATING METHOD FOR AN ARRANGEMENT

DE502020011057D1Active Publication Date: 2025-06-05SIEMENS MOBILITY GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502020011057
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-06-20
Filing Date
2020-06-03
Publication Date
2025-06-05
Estimated Expiration
2040-06-03

AI Technical Summary

Technical Problem

Existing technologies face challenges in securely managing remote queries for safety-critical systems, particularly in preventing manipulation and ensuring that safety-related messages are not transmitted.

Method used

A filter system comprising an input interface, an output interface, and two interface modules (first and second) that manage command protocols and ensure only authorized commands are forwarded, with the second interface module's software being unchangeable via the input interface.

Benefits of technology

The filter system effectively prevents manipulation and ensures that safety-related messages are not transmitted, maintaining the integrity and security of safety-critical systems during remote queries.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] From the patent application WO 2018 / 033318 A1, a filter for protected operation of a safety-critical system by means of remote query is known.

[0002] The invention relates to a filter having the features of the preamble of patent claim 1. An arrangement and a method for operating an arrangement are also specified.

[0003] Generic filters are known from the documents US 2011 / 173443 A1 and EP 2 706 722 A2.

[0004] One problem to be solved is to specify a filter for secure remote interrogation of a safety-critical system with easily verifiable properties. Further problems to be solved are to specify an arrangement with such a filter and a method for operating such an arrangement.

[0005] This object is achieved by a filter having the features of claim 1. Advantageous embodiments are specified in subclaims 2 to 8.

[0006] The filter according to the invention comprises an input interface for receiving a command based on a first protocol and an output interface for outputting a command. A command is therefore fed to the filter from outside via the input interface. The input interface enables, for example, data transfer with a remote interrogation unit. For example, the input interface is a serial interface, such as a USB interface or an Ethernet interface, for receiving a command based on a corresponding protocol. A protocol is understood here to be a communication protocol. The protocol is specified by the hardware and / or software of the filter. The commands are in particular digital commands that are understood by the system, possibly in a modified form.

[0007] The output interface enables communication with a safety-critical system, for example. The filter sends a command to the outside via the output interface. The output interface can be a serial interface, such as a USB interface or an Ethernet interface, for outputting a command based on a corresponding protocol.

[0008] The filter according to the invention comprises a first interface module and a second interface module. The interface modules are preferably simply constructed logic components. For example, the interface modules are microcontrollers or FPGAs. Preferably, the filter does not comprise any further logic components besides the two interface modules, in particular no further microcontrollers, computers, or FPGAs.

[0009] The first interface module is signal-connected to the input interface and to the second interface module. The second interface module is signal-connected to the output interface and to the first interface module. In particular, during normal operation, the input interface is signal-connected exclusively to the first interface module and to the remote interrogation unit. The first interface module is preferably signal-connected exclusively to the input interface and to the second interface module. The second interface module is preferably signal-connected exclusively to the first interface module and to the output interface. During operation, the output interface is preferably connected exclusively to the second interface module and a technical system.

[0010] During normal operation, a command preferably only passes from the input interface to the output interface by passing through the first interface module and the second interface module.

[0011] The first interface module is configured to forward the command received via the input interface to the second interface module, breaking the protocol. This means that during operation, the first interface module receives the command received via the input interface, modifies the communication protocol of the command, and then forwards the command to the second interface module. In other words, the first interface module changes the protocol from the first protocol to a second protocol that is different from the first protocol.

[0012] The protocol break in the first interface module is preferably caused both by the hardware of the first interface module and by software stored on the first interface module.

[0013] The second interface module is configured to forward only those parts of the command coming from the first interface module to the output interface that are stored or stored in the second interface module. In particular, the second interface module comprises an internal memory in which permitted commands or command parts are stored. The second interface module compares, for example, the command coming from the first interface module with the stored commands or command parts and, accordingly, forwards only a known command or known parts of the command.

[0014] The second interface module either forwards the command or command part coming from the first interface module without breaking the protocol, or the second interface module breaks the protocol in the command or command part. For example, the second interface module changes the protocol from the second protocol back to the first protocol or to a third protocol that is different from the first and second protocols. Any protocol break by the second interface module is preferably carried out by both the hardware of the second interface module and the software stored on the second interface module.

[0015] The second interface module comprises software. The software of the second interface module cannot be changed via the input interface. This means that the software of the second interface module cannot be reprogrammed via the input interface. The software is stored, for example, in an internal memory of the second interface module. Access to the internal memory is not possible, for example, via the input interface. Alternatively or additionally, the immutability of the software via the input interface is ensured by the fact that the commands are passed from the first interface module to the second interface module without a standardized protocol, so that reprogramming via the input interface and the first interface module is not possible.

[0016] The second interface module may have a programming interface for reprogramming the second interface module, which is then not signal-connected to the first interface module and / or the input interface. The programming interface can preferably be disabled by a hardware mechanism.

[0017] The software of the second interface module is particularly designed to determine and forward the known parts of a command.

[0018] The filter according to the invention thus comprises an input interface for receiving a command based on a first protocol, an output interface for outputting a command, a first interface module, and a second interface module. The first interface module is signal-connected to the input interface and the second interface module. The second interface module is signal-connected to the output interface and the first interface module. The first interface module is configured to forward the command received from the input interface to the second interface module, breaking the protocol. The second interface module is configured to forward to the output interface only those parts of the command coming from the first interface module that are stored in the second interface module.The software of the second interface module cannot be changed via the input interface.

[0019] The present invention is based, among other things, on the following insight: There is an increasing need to be able to carry out maintenance on safety-critical technical systems via a remote connection. However, the system to be maintained may be located in a special security zone to which no direct access is possible (e.g., Category 2 network according to EN 50159). A core property of this security zone is that it must be protected against manipulation. Even with connections of the system to the outside, for example, for remote maintenance or remote query, any possible manipulation must be reliably / securely prevented (perimeter protection). Furthermore, it should be ensured that certain elements cannot be transmitted via such a connection, such as security-relevant messages. protection against manipulation must be ensured and information with certain properties is not sent to the system.

[0020] These properties should be verifiable. The corresponding evidence should be easily understandable for third parties (operators, assessors, regulatory authorities).

[0021] These technical challenges can be solved, on the one hand, through the use of various, interacting IT security measures. For example, multi-level routers or gateways with firewalls are used for this purpose. Only permitted messages are transmitted between the data networks via the firewall; all other data is blocked. This behavior must not be corrupted even by failures. Either the data transmission is interrupted in the event of failures and / or failures do not have an immediate impact due to the multi-level approach and are detected by inspection mechanisms (defense in depth).

[0022] While in safety-critical areas, a dedicated security case must be maintained that performs standard-compliant failure assessments, in the area of ​​IT security, the assumption is generally that a failure implicitly leads to the failure / disconnection of data transmission or that failures are detected by users. Explicit failure assessments are not maintained, and the arguments regarding various interacting components and systems are usually complex and difficult for third parties to understand.

[0023] In addition, the systems are technically very complex and have a wider range of features than is typically required for remote queries. Due to the complexity of commercial IT security components, IT security vulnerabilities cannot be ruled out, so patches are usually provided to ensure IT security in the event of discovered IT security vulnerabilities.

[0024] The present invention solves the above-mentioned technical problems without the aforementioned disadvantages.

[0025] For this purpose, according to the invention, a command transmission from the first interface module to the second interface module is parallel.

[0026] According to the invention, the interface modules each comprise n connections for parallel command transmission.

[0027] At least the i-th terminal of the second interface module is not electrically connected to the i-th terminal of the first interface module.

[0028] Here, n is a natural number. For example, n is at least 2. Preferably, n is at least 4, for example, exactly 4, or exactly 8, or exactly 16. The n ports are each configured for connection to a line. Command transmission between the first interface module and the second interface module can, for example, take place on n parallel lines that connect the n ports of both interface modules.

[0029] Here, i is an integer less than or equal to n. This means that according to the invention at least one connection of the second interface module is not connected to the standard connection of the first interface module. For example, the i-th connection of the second interface module is connected via a line to the j-th connection of the first interface module, where j is an integer less than or equal to n and not equal to i. For this purpose, for example, the lines between the two interface modules are crossed. It is also possible that at least one line is omitted or interrupted, so that the i-th termination of the second interface module is not connected to a connection of the first interface module at all. It is also possible that at least one line is connected offset.

[0030] By ensuring that the i-th port of the second interface module is not connected to the i-th port of the first interface module, the immutability of the second interface module's software via the input interface is ensured. Furthermore, the commands cannot be forwarded unchanged even if the software fails. For example, this measure invalidates security attachments for security-relevant messages, making their transmission impossible.

[0031] Manipulation by remote access is prevented in particular by the fact that the software of the second interface module cannot be modified via the input interface, thus preventing access to the safety-critical system. In particular, due to the protocol breach in the first interface module, there is demonstrably no technical possibility of installing software on the second interface module via the input interface. This is especially true if the first interface module breaches a non-standardized protocol.

[0032] The introduction of illegal commands, such as safety-relevant commands, into the technical system is prevented by the second interface module only forwarding parts of a command that it knows. For example, safety-relevant parts of a command are then not forwarded. Even if this security mechanism fails, the protocol breach at least ensures that the filter is not transparent to the command.

[0033] The non-reprogrammability or immutability of the software of the second interface module via the input interface also prevents the second interface module from being reprogrammed in such a way that it generates safety-relevant commands or command parts itself. Since safety-relevant commands must be secured according to the current state of the art and require comparatively complex computational operations that are not generated randomly, random failures of filter components cannot lead to the generation of safety-relevant commands or command parts unless they contain corresponding algorithms / program parts.

[0034] According to at least one embodiment, the first interface module is configured exclusively to forward the command received via the input interface to the second interface module, breaking the protocol. This means that the software stored on the first interface module is configured only for the aforementioned operations and cannot perform any further operations. In particular, the software of the first interface module is not commercial software. Particularly preferably, the software of the first interface module is not third-party software, in particular, it is not COTS (commercial off-the-shelf) or closed software.

[0035] This makes it particularly easy to select the software for the first interface module, which is advantageous in terms of complete traceability. Especially when no unknown or commercial software is used, the absence of IT security vulnerabilities can be proven, and the potential failures are easily traced. IT security vulnerabilities typically arise when the software used is highly complex and are usually due to specification errors, programming errors, or errors in the application of existing software.

[0036] Particularly preferably, the first interface module is not reprogrammable. For example, the software of the first interface module is stored in a non-writable memory of the first interface module.

[0037] According to at least one embodiment, the software of the second interface module is non-modifiable. For example, the software of the second interface module is stored in a non-writable or non-modifiable memory of the second interface module. Alternatively, a programming interface of the second interface module is destroyed or rendered unusable.

[0038] According to at least one embodiment, the second interface module is configured to recode the command coming from the first interface module. Recoding removes, adds, or modifies information from the original command. For example, individual bits of the command are swapped or omitted. This is particularly advantageous if an attempt is made to pass safety-relevant commands through the filter.

[0039] According to at least one embodiment, the second interface module is configured exclusively to perform the operations described here. In particular, the second interface module is configured only to forward the parts of a command known to it, possibly to change the communication protocol of the command or the command part, and / or to recode the command or the command part. In particular, the software of the second interface module is not commercial software. Particularly preferably, the software of the second interface module is not third-party software, in particular not COTS software (COTS = commercial off-the-shelf). This allows for particularly easy software selection, which is advantageous in terms of complete traceability.

[0040] According to at least one embodiment, the first interface module is a microcontroller or an FPGA (Field Programmable Gate Array). Alternatively or additionally, the second interface module is also a microcontroller or an FPGA.

[0041] According to at least one embodiment, the output interface is configured to output a command based on the first protocol. In the second interface module, a protocol break to the first protocol preferably occurs again. Alternatively, it is also conceivable for a protocol break to a third protocol different from the first protocol to occur in the second interface module, and for the output interface to be configured to output a command based on this third protocol.

[0042] According to at least one embodiment, the input interface is a serial interface. The output interface is configured, for example, to output a serial command. The command transmission between the first interface module and the second interface module is parallel.

[0043] Furthermore, an arrangement is specified. The arrangement comprises a filter described here. Furthermore, the arrangement comprises a technical system, in particular a safety-critical technical system. The input interface is configured for signaling connection to a remote interrogation unit. The output interface is signaling-connected to the technical system.

[0044] According to at least one embodiment, the technical installation is a rail transport installation or a control device for a rail transport installation. In particular, the rail transport installation is a railway installation. For example, the technical installation is a signal box computer of a railway signal box or a control center computer of a railway control center.

[0045] Furthermore, a method for operating an arrangement is specified. The method is configured to operate an arrangement described here. All features disclosed in connection with the arrangement are therefore also disclosed for the method, and vice versa.

[0046] The procedure includes the following steps: Signaling a remote interrogation unit to the input interface of the arrangement, sending a command based on a first protocol from the remote interrogation unit to the input interface and from there to the first interface module, forwarding the command with a protocol break from the first interface module to the second interface module, forwarding only those parts of the command from the second interface module to the output interface that are stored in the second interface module, forwarding the parts of the command from the output interface to the technical system.

[0047] A command transfer from the first interface module to the second interface module takes place in parallel, whereby the interface modules for parallel command transmission each comprise n ports and at least one port of the second interface module is not connected to the standard port of the first interface module.

[0048] The remote interrogation unit can be, for example, a computer, especially a laptop, or a smartphone or tablet PC. The signal connection between the remote interrogation unit and the filter is established, for example, via a wireless or wired internet connection.

[0049] During the procedure, the remote interrogation unit is assigned to a different security zone than the technical system and the filter, for example. The filter and the technical system are preferably assigned to the same security zone. For example, the remote interrogation unit is assigned to a Category 3 network according to EN 50159, while the technical system, and preferably also the filter, are assigned to a Category 2 network according to EN 50159.

[0050] If the first and / or second interface module comprises a programming interface for reprogramming the respective software running on it, the programming interfaces are preferably accessible exclusively from the security zone assigned to the filter.

[0051] The above-mentioned properties, features, and advantages of the invention and the manner in which they are achieved are further explained by the following description of the exemplary embodiments of the invention in conjunction with the corresponding figures. Identical, similar, or similarly acting elements are provided with the same reference numerals in the figures. The figures and the relative sizes of the elements shown in the figures are not to scale. Rather, individual elements may be exaggerated for clarity and / or clarity.

[0052] They show: Figures 1, 2 and 8 show various embodiments of the filter, Figure 3 shows an embodiment of the arrangement, Figures 4 to 7 show various positions in embodiments for operating an arrangement.

[0053] Figure 1shows a first embodiment of a filter 1. The filter 1 comprises an input interface S1 for receiving a command based on a first protocol. The input interface S1 is, for example, a serial USB or Ethernet interface. The filter 1 further comprises an output interface S2 for outputting a command. For example, the output interface S2 is configured to output a command based on the same first protocol as the input interface S1. In particular, the output interface S2 is, for example, a serial USB or Ethernet interface.

[0054] The filter 1 further comprises a first interface module K1 and a second interface module K2. The interface modules K1, K2 are, for example, microcontrollers or FPGAs. The first interface module K1 is signal-connected to the input interface S1 and the second interface module K2. The second interface module K2 is signal-connected to the first interface module K1 and the output interface S2. The first interface module K1 is, for example, configured exclusively to forward a command received from the input interface S1 to the second interface module K2, breaking the protocol. The command transmission from the first interface module K1 to the second interface module K2 is in parallel in this case.The second interface module K2 is, for example, exclusively configured to forward those parts of the command coming from the first interface module K1, with another protocol break, which are stored in the second interface module K2, for example in an internal memory of the second interface module K2.

[0055] In the Figure 1 The first and second interface modules each have four ports A1, A2, A3, and A4 for parallel command transmission. Each port Ai of the second interface module K1 is electrically connected to the standard port Ai of the first interface module K1 via a cable. This means that the first ports A1 are connected to each other, the second ports A2 are connected to each other, the third ports A3 are connected to each other, and the fourth ports A4 are connected to each other.

[0056] In the first embodiment of the Figure 1 The first interface module K1 and the second interface module K2 are not reprogrammable. This means that the software on the first interface module K1 and the second interface module K2 cannot be changed or reprogrammed.

[0057] In the Figure 2 A second embodiment of the filter 1 is shown. Unlike in the Figure 1 The second interface module K2 now includes a programming interface PS, via which the second interface module K2 can be reprogrammed. However, the programming interface PS is not signal-connected to either the input interface S1 or the first interface module K1, so reprogramming the second interface module K2 via the input interface S1 is not possible.

[0058] In the Figure 3An embodiment of an arrangement 10 is shown. The arrangement 10 comprises, for example, the filter 1 from the Figure 1 and a safety-critical technical installation 2. In this case, the safety-critical technical installation 2 is the signal box of a railway system. The output interface S2 of filter 1 is connected to the technical installation 2 for signaling purposes. The input interface S1 of filter 1 is connectable to a remote interrogation unit 3, in this case in the form of a laptop.

[0059] In the Figure 4 is a position in a method of operating an arrangement, for example the arrangement 10 of the Figure 3 , shown. For better presentation, the safety-critical technical system 2 is now shown in simplified form as a dashed box. In the position of the Figure 4The remote interrogation unit 3 is signal-connected to the input interface S1 and sends a command C to the input interface S1 based on a first protocol P1. The command C is forwarded to the first interface module K1. The command transmission from the remote interrogation unit 3 to the input interface S1 is serial.

[0060] In the Figure 5 A subsequent step of the process is shown, in which the command C is forwarded from the first interface module K1 to the second interface module K2, breaking the protocol. The first interface module K1 performs a protocol break from the first protocol P1 to a second protocol P2. The command forwarding from the first interface module K1 to the second interface module K2 is parallel here.

[0061] In the Figure 6Another step in the process is shown. The second interface module K2 has forwarded the known parts of command C to the output interface S2, from where they are forwarded to the safety-critical system 2. In this case, the second interface module K2 has again broken the protocol from the second protocol P2 to a third protocol P3. The third protocol P3 can be identical to the first protocol P1.

[0062] In the Figure 7 A further position in the method is shown, in which the arrangement 10 further comprises a data diode 4 connected in parallel to the filter 1. The data diode 4 enables unidirectional data transmission from the technical system 2 to the remote interrogation unit 3. The data diode 4 preferably blocks any transmission of data in the opposite direction, i.e., from the remote interrogation unit 3 toward the technical system 2.

[0063] If a permissible command is transmitted to the technical system 2 via the filter 1, the requested data can then be transmitted to the remote interrogation unit 3 via the data diode 4.

[0064] Figure 8 shows a third embodiment of the filter 1. The embodiment is similar to that of Figure 1, only now the A connections of the second interface module are no longer all connected to the standard A connections of the first interface module K1. In this case, the fourth connection A4 of the second interface module K2 is not connected at all to a connection A of the first interface module K1. The second connection A2 of the second interface module K2 is not connected to the second connection A2 of the first interface module K1, as would be the standard case, but to the third connection A3. Instead, the third connection A3 of the second interface module K2 is connected to the second connection A2 of the first interface module K1. In this respect, the electrical lines of these two connection pairs are crossed.

[0065] Although the invention has been illustrated and described in detail using exemplary embodiments, the invention is not limited to the disclosed embodiments and the specific feature combinations explained therein. Further variations of the invention may be obtained by a person skilled in the art without departing from the scope of the claimed invention. List of reference symbols

[0066] 1Filter 2Technical system 3Remote interrogation unit 4Data diode S1Input interface S2Output interface K1First interface module K2Second interface module P1First protocol P2Second protocol P3Third protocol PSProgramming interface CCommand A1...nConnection

Claims

1. Filter (1), comprising: - an input interface (S1) for receiving a command on the basis of a first protocol (P1), - an output interface (S2) for outputting a command, - a first interface module (K1), - a second interface module (K2), wherein - the first interface module (K1) is connected to the input interface (S1) and the second interface module (K2) for signalling purposes, - the second interface module (K2) is connected to the output interface (S2) and the first interface module (K1) for signalling purposes, - the first interface module (K1) is configured to forward the command received via the input interface (S1) to the second interface module (K2) with a break in protocol, - the second interface module (K2) is configured to only forward those parts of the command coming from the first interface module (K1), which are stored in the second interface module (K2), to the output interface (S2), - a piece of software of the second interface module (S2) cannot be modified via the input interface (S1), characterised in that a command transfer from the first interface module (K1) to the second interface module (K2) is parallel, wherein - the interface modules (K1, K2) each comprise n connections (A1..n) for the parallel command transfer, - at least one connection (Ai) of the second interface module (K2) is not connected to the connection (Ai) of the first interface module (K1) which is associated by default.

2. Filter (1) according to claim 1, wherein the first interface module (K1) is exclusively configured to forward the command received via the input interface (S1) to the second interface module (K2) with a break in protocol.

3. Filter (1) according to claim 1 or 2, wherein the software of the second interface module (K2) cannot be modified.

4. Filter (1) according to one of the preceding claims, wherein the second interface module (K2) is configured to recode the command coming from the first interface module (K1).

5. Filter (1) according to one of the preceding claims, wherein the second interface module (K2) is exclusively configured to carry out the operations specified in the preceding claims.

6. Filter (1) according to one of the preceding claims, wherein the first (K1) and the second (K2) interface module are a microcontroller or an FPGA in each case.

7. Filter (1) according to one of the preceding claims, wherein the output interface (S2) is configured to output a command on the basis of the first protocol (P1).

8. Filter (1) according to one of the preceding claims, wherein the input interface (S1) is a serial interface.

9. Arrangement (10) with - a technical installation (2), - a filter (1) according to one of the preceding claims, wherein - the input interface (S1) is configured to connect to a remote query unit (3) for signalling purposes, - the output interface (S2) is connected to the technical installation (2) for signalling purposes.

10. Arrangement (10) according to claim 9, wherein the technical installation (2) is a rail traffic installation.

11. Method for operating an arrangement (10) according to claim 9 or 10, comprising the steps: - connecting a remote query unit (3) to the input interface (S1) of the arrangement (10) for signalling purposes, - sending a command (C) on the basis of a first protocol (P1) from the remote query unit (3) to the input interface (S1), and from there to the first interface module (K1), - forwarding the command (C) from the first interface module (K1) to the second interface module (K2) with a break in protocol, - forwarding only those parts of the command (C), which are stored in the second interface module (K2), from the second interface module (K2) to the output interface (S2), - forwarding the parts of the command (C) from the output interface (S2) to the technical installation (2), characterised in that a command transfer from the first interface module (K1) to the second interface module (K2) takes place in parallel, wherein - the interface modules (K1, K2) each comprise n connections (A1..n) for the parallel command transfer, - at least one connection (Ai) of the second interface module (K2) is not connected to the connection (Ai) of the first interface module (K1) which is associated by default.