METHOD AND ARRANGEMENT FOR GENERATING A CONTROL SIGNAL

DE502022004126D1Active Publication Date: 2025-06-26SIEMENS MOBILITY GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502022004126
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-16
Publication Date
2025-06-26
Estimated Expiration
2042-06-16

AI Technical Summary

Technical Problem

Existing methods for generating control signals to manage data telegram transmission and storage lack reliability in detecting errors, thereby compromising security.

Method used

A method involving the formation of backup data and a backup appendix, which are then evaluated to generate a control signal based on their correlation, ensuring high security levels by reliably verifying data integrity.

Benefits of technology

This method provides a secure verification of data integrity and reliably detects errors in the process sequence, achieving high security levels in data transmission and storage.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to methods and arrangements for generating control signals with which, for example, the transmission of a data telegram can be enabled or blocked and / or the storage of data can be enabled or blocked.

[0002] European patent EP 3 659 317 B1 discloses a method for generating a control signal that can be used to prevent the transmission of a data telegram. The patent describes in detail a method for providing a secure telegram with a payload part containing payload data and a check data part, the check data part representing uncorrupted original payload data. The original payload data is stored in a secure software environment. A payload copy of the original payload data is stored outside the secure software environment. The check data part containing original check data is generated in the secure software environment or outside the secure software environment, and a check data copy of the original check data is stored outside the secure software environment if the check data part was generated in the secure software environment.A copy of the payload data copy is compared in the secure software environment with the original payload data and / or a representation of the original payload data, and / or a copy of the test data copy is compared in the secure software environment with the original test data and / or the representation of the original test data. The telegram is only provided with the payload data copy as payload data and the test data portion once the comparison has shown that the copy of the payload data copy corresponds to the original payload data and / or the copy of the test data copy corresponds to the original test data.

[0003] Document WO 03 / 047937 A1 describes a method for controlling a safety-critical railway operating process. The required program is divided into system software and railway-specific software. External commands and messages relating to the control are captured and transmitted via the system software running in one or more safe signaling computers, depending on the respective railway operating conditions, to commercial computers where the actual process control takes place.

[0004] The document WO 2014 / 090530 A1 relates to an arrangement comprising an actuator, at least one transmitting device for transmitting control telegrams, each of which contains a predefined control command for the actuator or itself represents the predefined control command, at least two receiving devices for receiving the control telegrams and generating a control signal for the actuator, and a decision device which connects the receiving devices to the actuator and which allows the actuator to implement the control signals of the receiving devices by means of an enable signal only if the control signal is present from all receiving devices or from at least a predefined minimum number of receiving devices.

[0005] Document DE 10 2018 203072 A1 relates to a method for transmitting a message from a transmitting device to a receiving device. A telegram generated by the transmitting device, which includes the message and check data formed with the message, is transmitted to a transmitting-side access protection device. The transmitting-side access protection device modifies the telegram and then transmits it via a connection to a receiving-side access protection device.

[0006] The invention is based on the object of specifying another method for generating a control signal with which errors when transmitting a data telegram in the process chain can be detected particularly reliably and thus particularly high levels of security can be achieved.

[0007] This object is achieved according to the invention by a method having the features according to claim 1; advantageous embodiments of the method according to the invention are specified in subclaims.

[0008] According to the invention, backup data is formed using original user data and / or test data based on the original user data, a backup appendix is ​​generated and added to the backup data to form extended backup data, the extended backup data is evaluated, and the control signal is generated depending on whether the backup appendix contained in the extended backup data correlates with the backup data contained in the extended backup data, the above-mentioned steps being carried out in one or more secure sections of a computer system.

[0009] A significant advantage of the method according to the invention is that the inclusion of extended backup data or the consideration of the backup appendix enables a particularly secure verification of the integrity of the original payload data and / or the test data and allows any errors in the process sequence to be reliably detected.

[0010] The examination of whether there is a correlation or correspondence between the backup appendix and the backup data.the backup attachment and the backup data match in terms of content - this test is also called a correlation test below - is preferably carried out depending on how the backup data and the backup attachment were created: For example, if the backup data contained in the extended backup data is unencrypted and the backup attachment was created by encrypting the backup data, the correlation test can be carried out by encrypting the backup data again - using the same encryption method with which the backup attachment was created, or a different encryption method that delivers the same result in the event of no errors - and comparing the encrypted backup data and the backup attachment, and concluding that there is a correlation if the encrypted backup data and the backup attachment are identical.

[0011] It is advantageous if the backup data contains the original payload data and / or the test data and the control signal is generated depending on whether the backup appendix contained in the extended backup data correlates with (or corresponds to, i.e. matches the content of) the original payload data contained in the backup data and / or the test data contained in the backup data.

[0012] According to the invention, it is also provided that a telegram generation module forms an intermediate telegram with the extended security data, which intermediate telegram comprises a payload section and a security section, wherein the security data is added to the payload section as payload data content and the security attachment is added to the security section, the intermediate telegram is forwarded to a telegram reception module, the telegram reception module receives the intermediate telegram generated by the telegram generation module and evaluates the extended security data contained therein, and the telegram reception module generates the control signal depending on whether the payload data content and the security attachment correspond, wherein the telegram generation module and the telegram reception module are integrated in the above-mentioned secure section(s) of the computer system.The steps provided according to the invention of generating an intermediate telegram, receiving the intermediate telegram and evaluating the intermediate telegram allow errors in the process chain to be detected particularly reliably and thus particularly high safety levels to be achieved.

[0013] According to the invention, it is also provided that the telegram receiving module generates a data telegram-related enable signal which enables transmission of a data telegram if the payload data content and the security attachment correspond, and generates a data telegram-related blocking signal which blocks transmission of the data telegram if the payload data content and the security attachment do not correspond.

[0014] The check whether there is a correlation or correspondence between the security attachment and the payload content.the backup attachment and the payload content match in terms of content - this test is also referred to as payload correlation test below - is preferably carried out depending on how the payload content and the backup attachment were created: For example, if the backup data in the payload content is unencrypted and the backup attachment was created by encrypting the payload content, the payload correlation test can be carried out by encrypting the payload content again using the same encryption method used to create the backup attachment, or using a different encryption method that delivers the same result if the backup attachment is error-free, and comparing the encrypted payload content and the backup attachment, and concluding that there is a correlation if the encrypted payload content and the backup attachment are identical.

[0015] The last described process variant can be implemented in a simple and therefore particularly advantageous manner, for example, using the PROFIsafe telegram standard available in the SIMATIC Safety System from SIEMENS, so that the programming effort required to carry out the described process is minimized.

[0016] The telegram generation module is preferably formed by a flexible F-Link telegram transmission device of the SIMATIC Safety System from SIEMENS.

[0017] The telegram reception module is preferably formed by a flexible F-Link telegram reception device of the SIMATIC Safety System from SIEMENS.

[0018] The backup data added to the payload section may advantageously be the original payload data and / or the test data based on the original payload data as such.

[0019] It is also advantageous if the telegram receiving module generates a memory data-related enable signal as a control signal or as a further control signal, which enables storage of data if the payload data content and the backup attachment correspond, and / or generates a memory data-related blocking signal, which blocks storage of data if the payload data content and the backup attachment do not correspond.

[0020] Furthermore, it is considered advantageous if the telegram generation module generates the security attachment with reference payload data that is present in the secure section or one of the secure sections and differs from the original payload data and has been generated separately from the original payload data, but in the error-free case is identical to the original payload data in terms of data content, and / or with reference check data based on the reference payload data and adds this reference data-related security attachment to the security section.

[0021] The telegram receiving module generates the control signal or at least one of the control signals preferably depending on whether the payload content based on the original data and the reference data-related backup attachment correspond.

[0022] The check as to whether there is a correlation or correspondence between the payload content based on the original data and the reference data-related backup attachment, or whether the backup attachment and the payload content match in terms of content, is preferably carried out depending on how the payload content and the backup attachment were created: For example, if the payload content based on the original data is unencrypted and the reference data-related backup attachment is encrypted, the reference data-related backup attachment can first be decrypted and the unencrypted payload content can be compared with the decrypted backup attachment in terms of content and a correlation can be concluded if the unencrypted payload content and the decrypted backup attachment are identical.Alternatively, the payload content can be encrypted using the same encryption method used to create the backup attachment, or using a different encryption method that produces the same result in the absence of errors, and the encrypted payload content and the encrypted backup attachment can be compared and a correlation can be concluded if the encrypted payload content and the encrypted backup attachment are identical.

[0023] In a first variant considered to be particularly advantageous, it is provided that the telegram generation module adds the original payload data and the check data to the payload data section of the intermediate telegram and forms the security appendix by applying a security function by applying the security function to the reference payload data and the reference check data.

[0024] In a second variant considered to be particularly advantageous, it is provided that the telegram generation module adds the original payload data, but not the check data, to the payload data section of the intermediate telegram and forms the security appendix by applying a security function by applying the security function to the reference payload data.

[0025] In a third variant considered to be particularly advantageous, it is provided that the telegram generation module adds the test data, but not the original payload data, to the payload data section of the intermediate telegram and forms the security appendix by applying a security function by applying the security function to the reference test data.

[0026] In all method variants, it can advantageously be provided that the security appendix is ​​generated with reference payload data that is present in the secure section or in one of the secure sections and differs from the original payload data and was generated separately from the original payload data, but in the error-free case is identical to the original payload data in terms of data content, and / or with reference check data based on the reference payload data, and the control signal is generated depending on whether the payload data content based on the original data and the reference data-related security appendix correspond.

[0027] The application of the security function preferably also includes at least the formation of a cyclic redundancy code which is added to the security appendix.

[0028] The described method steps will preferably be carried out exclusively in one or more sections of a computer system that are secured by software programming and / or hardware security.

[0029] It is advantageous if the method steps listed above are divided into at least two independently operating software sections. In particular, it is advantageous if the telegram generation module and the telegram reception module are assigned to different, secure software sections.

[0030] With regard to the data telegram whose transmission is enabled by the enable signal or blocked by the blocking signal, it is considered advantageous if it is completed in a non-secure section of the computer system, wherein the original payload data and / or the reference payload data are added to a payload data section of the data telegram, and wherein the check data and / or the reference check data are added to the security section of the data telegram.

[0031] The invention also relates to a computer system. According to the invention, the computer system is programmed in such a way that it can execute a method as described above.

[0032] With regard to the advantages of the computer system according to the invention and its advantageous embodiments, reference is made to the above statements in connection with the method according to the invention and its advantageous embodiments.

[0033] The computer system may comprise two or more computer units between which the process steps of the process are divided and which execute the process steps jointly.

[0034] The invention also relates to a railway component, in particular a rail vehicle or a railway track facility. According to the invention, the railway component comprises a computer system as described above or is capable of executing a method according to the invention as described above.

[0035] Regarding the advantages of the railway component and its advantageous embodiments, reference is made to the above explanations in connection with the method according to the invention and its advantageous embodiments. The invention is explained in more detail below using exemplary embodiments; Figure 1 shows an embodiment of an arrangement which is suitable for carrying out a method according to the invention, Figure 2 shows a further embodiment of an arrangement which is suitable for carrying out a method according to the invention, Figure 3 shows a computer system in which the estimation device according to Figure 2 is implemented and which accordingly the estimator according to Figure 2 4-6 further embodiments of computer systems according to the invention, and Figure 7 an embodiment of a rail vehicle according to the invention and a railway track device according to the invention, each of which is provided with a computer system as shown in the Figures 3 to 6 shown.

[0036] For the sake of clarity, the same reference numerals are used in the figures for identical or comparable components.

[0037] The Figure 1shows an embodiment of an arrangement suitable for carrying out a method according to the invention.

[0038] The arrangement comprises an application module 10, with which original payload data ND is generated. The original payload data ND is preferably control data or control commands, such as driving or braking commands for a rail vehicle.

[0039] Downstream of the application module 10 is a check module 20, which forms check data PD with the original payload data ND. The check data PD can be formed, for example, by encoding the original payload data ND and include a cyclic redundancy code such as a CRC code.

[0040] A telegram generation module 30 is connected to the application module 10 and the test module 20. The telegram generation module 30 forms an intermediate telegram ZTG, which includes a user data section A1 and a security section A2. The telegram generation module 30 is preferably formed by a flexible F-Link telegram transmission device of the SIMATIC Safety System from SIEMENS.

[0041] Backup data SD is inserted into the payload section A1 of the intermediate telegram ZTG as payload content. The backup data SD can be formed solely from the original payload data ND and, for example, be identical to it; alternatively, the backup data SD can be formed solely from the check data PD and, for example, be identical to the check data PD. It is also possible for the backup data SD to include both the original payload data ND and the check data PD.

[0042] In addition, the telegram generation module 30 generates a security attachment SA, which it inserts into the security section A2 of the intermediate telegram ZTG. The security attachment SA and the security data SD together form extended security data ESD, which—as explained—are placed in different sections of the intermediate telegram ZTG.

[0043] A telegram reception module 40, to which the intermediate telegram ZTG is forwarded, is arranged downstream of the telegram generation module 30. The telegram reception module 40 receives the intermediate telegram ZTG generated by the telegram generation module 30 and evaluates the extended safety data ESD contained therein. The telegram reception module 40 is preferably formed by a flexible F-Link telegram reception device of the SIMATIC Safety System from SIEMENS.

[0044] On the output side, the telegram receiving module 40 generates a control signal in the form of a data telegram-related enable signal FS1, which enables transmission of a data telegram, and / or a control signal in the form of a storage data-related enable signal FS2, which enables storage of data if the payload data content of the intermediate telegram ZTG and the security appendix SA located in the security section A2 of the intermediate telegram ZTG correspond in content (or correlate, i.e., match each other in content).

[0045] If the payload data content and the security attachment SA do not correspond, the telegram receiving module 40 generates a data telegram-related blocking signal BS1, which blocks transmission of the data telegram DTG, and / or a storage data-related blocking signal BS2, which blocks storage of data.

[0046] The Figure 2 shows an advantageous further development of the arrangement according to Figure 1. The order according to Figure 2 additionally comprises a data telegram transmission device 50, which serves to generate and transmit a data telegram DTG. The transmission of the data telegram DTG is enabled with the enable signal FS1 or blocked with the blocking signal BS1.

[0047] The data telegram transmitting device 50 forms the data telegram DTG, for example, by adding the original payload data ND to a payload data section of the data telegram DTG.

[0048] The Figure 3 shows an embodiment of a computer system 100 according to the invention, which has the arrangement according to Figure 2 The computer system 100 comprises a computing device 101 and a memory 102.

[0049] The computing device 101 may be formed by a single computing unit or alternatively by several computing units, which may be arranged close to one another or separately from one another.

[0050] The memory 102 may be formed by a single memory unit or alternatively by multiple memory units that may be arranged close to one another or separated from one another.

[0051] In the memory 102 there is an application software module M10, which forms the application module 10 when executed by the computing device 101, a test software module M20, which forms the test module 20 when executed by the computing device 101, a telegram generation software module M30, which forms the telegram generation module 30 when executed by the computing device 101, a telegram reception software module M40, which forms the telegram reception module 40 when executed by the computing device 101, and a data telegram software module M50, which forms the data telegram transmission device 50 when executed by the computing device 101.

[0052] The application software module M10, the test software module M20 and the telegram generation software module M30 are arranged in a section 121 of the computer system 100 that is classified as safe according to a specified safety standard and carry out their process steps in compliance with the specified safety standard.

[0053] The telegram reception software module M40 is preferably arranged in another section 122 of the computer system 100 which is separate in terms of software and is also classified as secure according to the specified security standard and also carries out its method steps in compliance with the specified security standard.

[0054] In contrast to the other modules M10, M20, M30, and M40 mentioned above, the data telegram software module M50 is located in a section 123 of the computer system 100 that is not classified as secure according to the aforementioned security standard. The completion of the data telegram DTG and its transmission therefore take place in a hardware and / or software-insecure environment.

[0055] Furthermore, the above statements apply in connection with the Figures 1 to 2 in the embodiment according to Figure 3 accordingly.

[0056] The Figure 4 shows an advantageous extension of the embodiment according to Figure 3 .

[0057] The order according to Figure 4additionally comprises a reference application software module M110, which, when executed by the computing device 101, forms a reference application module 110 and generates reference payload data RND. The reference payload data RND differs from the original payload data ND of the application module 10 only formally (e.g., through coding or a different data format); however, in terms of content, they are identical to the original payload data ND in the absence of errors. If the original payload data ND, for example, is control data or control commands such as driving and / or braking commands for a rail vehicle, the reference payload data RND defines the same control data and the same control commands as the original payload data ND.

[0058] Downstream of the reference application module 110 is a reference check software module M120, which, when executed by the computing device 101, forms a reference check module 120 and generates reference check data RPD using the reference payload data RND. The reference check data RPD can be formed, for example, by coding and include a cyclic redundancy code such as a CRC code.

[0059] In the embodiment according to Figure 4 The telegram generation module 30 inserts the original payload data ND and the check data PD as backup data or as payload content into the payload section A1 of the intermediate telegram ZTG; alternatively, it can first apply a backup function to the original payload data ND and the check data PD and then insert the data saved in this way into the payload section A1 of the intermediate telegram ZTG.

[0060] Since the telegram generation module 30 is also connected on the input side to the reference application module 110 and the reference check module 120, it can form the security appendix SA for the intermediate telegram ZTG with the reference payload data RND and the reference check data RPD. For example, the telegram generation module 30 can insert the reference payload data RND and the reference check data RPD as such as the security appendix SA into the security section A2 of the intermediate telegram ZTG; alternatively, it can first apply a security function to the reference payload data RND and the reference check data RPD and then insert the data secured in this way as the security appendix SA into the security section A2 of the intermediate telegram ZTG.

[0061] The telegram receiving module 40 receives the intermediate telegram ZTG and checks whether the payload content based on the original data, which here is based on both the original payload ND and the check data PD, corresponds to the reference data-related security appendix SA, which here is based on both the reference payload RND and the reference check data RPD.

[0062] The check as to whether there is a correlation or correspondence between the payload content based on the original data and the reference data-related backup attachment SA, or whether the backup attachment SA and the payload content match in terms of content, is preferably carried out depending on how the payload content and the backup attachment SA were created: For example, if the payload content based on the original data is unencrypted and the reference data-related backup attachment SA is encrypted, the reference data-related backup attachment SA can first be decrypted and the unencrypted payload content can be compared with the decrypted backup attachment in terms of content, and a correlation can be concluded if the unencrypted payload content and the decrypted backup attachment are identical.Alternatively, the payload content can be encrypted using the same encryption method used to create the backup attachment SA, or using a different encryption method that produces the same result in the absence of errors, and the encrypted payload content can be compared with the encrypted backup attachment SA and a correlation can be concluded if the encrypted payload content and the encrypted backup attachment are identical.

[0063] If the payload content of the intermediate telegram ZTG and the security appendix SA located in the security section correspond, the data telegram-related enable signal FS1 and / or the memory data-related enable signal FS2 are generated; otherwise, the data telegram-related blocking signal BS1 and / or the memory data-related blocking signal BS2 are generated.

[0064] Furthermore, the above explanations apply in connection with the Figures 1 to 3 for the embodiment according to Figure 4 accordingly.

[0065] The Figure 5 shows a further embodiment of a computer system 100 according to the invention, which is suitable for generating a control signal. In the computer system 100 according to Figure 5 the telegram generation module 30 inserts only the original payload data ND as payload content into the payload section A1 of the intermediate telegram ZTG; alternatively, it can first apply a backup function to the original payload data ND and then insert the data saved in this way into the payload section A1 of the intermediate telegram ZTG.

[0066] The telegram generation module 30 forms the security appendix SA only with the reference payload data RND, for example, by inserting it as such into the security section A2 of the intermediate telegram ZTG; alternatively, it can first apply a security function to the reference payload data RND and then insert the data secured in this way as the security appendix SA into the security section A2 of the intermediate telegram ZTG.

[0067] The telegram receiving module 40 receives the intermediate telegram ZTG and checks whether the payload content based on the original data, which here is based solely on the original payload ND, corresponds to the reference data-related backup appendix SA, which here is based solely on the reference payload RND.

[0068] Furthermore, the above explanations apply in connection with the Figures 1 to 4 for the embodiment according to Figure 5 accordingly.

[0069] The Figure 6shows a further embodiment of a computer system 100 according to the invention for generating a control signal.

[0070] For the computer system 100 according to Figure 6 the telegram generation module 30 inserts only the test data PD as payload into the payload section A1 of the intermediate telegram ZTG; alternatively, it can first apply a backup function to the test data PD and then insert the data saved in this way into the payload section A1 of the intermediate telegram ZTG.

[0071] The telegram generation module 30 forms the security appendix SA only with the reference check data RPD, for example, by inserting it as such into the security section A2 of the intermediate telegram ZTG; alternatively, it can first apply a security function to the reference check data RPD and then insert the data secured in this way as the security appendix SA into the security section A2 of the intermediate telegram ZTG.

[0072] The telegram receiving module 40 receives the intermediate telegram ZTG and checks whether the payload content based on the original data, which here is based solely on the check data PD, corresponds to the reference data-related backup appendix SA, which here is based solely on the reference check data RPD.

[0073] Furthermore, the above explanations apply in connection with the Figures 1 to 5 for the embodiment according to Figure 6 accordingly.

[0074] In the embodiments according to the Figures 4 to 6 it is advantageous if the data telegram transmitting device 50 adds the original payload data ND and / or the reference payload data RND to a payload section A1 of the data telegram DTG and adds the check data PD and / or the reference check data RPD to a security section A2 of the data telegram DTG, as exemplified by the Figure 6 shows. In the Figure 6For reasons of clarity, connecting lines that enable the transmission of the reference payload data RND, the test data PD and the reference test data RPD to the data telegram transmitting device 50 are missing.

[0075] The Figure 7 shows an embodiment of a rail vehicle 300 according to the invention and a railway track device 310 according to the invention, each of which is provided with a computer system 100, for example one such as that shown in the Figures 3 to 6 shown, and each capable of carrying out the method according to the invention.

[0076] The exemplary embodiments of methods and computing systems according to the invention explained above by way of example may - but do not have to - have one or more of the features, advantages or properties listed below: The exemplary embodiments can use the SIMATIC Safety System, which uses the PROFIsafe safe telegram standard. Telegram creation is preferably carried out in the form described above at the operating system level, involving a reference channel (hereinafter also referred to as the coded channel) to generate the safety attachment. Special drivers can be developed at the operating system level to implement telegram protocols from railway safety technology. The SIMATIC Safety System's flexible F-Link communication can ensure the safe generation and protected storage of data between two F-runtime groups. When a bit is output to a safe F-DO output module of the SIMATIC Safety System, the results of the original channel and the coded channel (reference channel) are preferably compared safely when evaluating the PROFIsafe telegram.The complete creation of the telegram (including security attachment) preferably takes place in the safe program area of ​​the SIMATIC Safety System. The created telegram is preferably transferred to an internal receive block using the SIMATIC internal communication function "Flexible F-Link" (F-Link). The safe send block of the F-Link preferably checks the channel participation of the coded program (i.e., the reference channel) when creating the telegram and preferably sends the result in an internally secured telegram. The receive function of the F-Link preferably checks the received telegram using the internal telegram security procedures (including F-Link CRC). The F-Link receive function provides the application with a safe status message. The status message of the receive function is preferably used as an enable for the complete provision of the send telegram to the standard program.In addition, the status message is preferably output as a safe bit via the two-channel safe output module. The release after the comparison or, in the event of an error, the blocking of the created telegram can be achieved in various ways (also using the safe output function). For this purpose, one or a combination of several of the following measures is possible: Program stop and thus forcing the safe state in the event of an error. Physical release / blocking of the transmitting module (e.g., de-energizing); for this procedure, it should be ensured that the communication module is safely blocked in good time before a potentially dangerous telegram is sent. By safely rereading the release bit; the finished telegram is preferably only transferred to the non-safe program section for forwarding to the communication processor after the release has been granted.Telegrams are preferably sent in the system's standard program. To achieve the security objective, it may be sufficient to check only part of the telegram (e.g., the security attachment) by sending it via F-Link and to make release dependent solely on this. It may be advantageous if the security attachment can be created in the standard program. The procedure described above is preferably applied only to the part of the telegram from which the payload is calculated (header and payload), but not to the security attachment. Between the process steps of F-Link transmission and F-Link reception evaluation, the security attachment is created using standard program tools, preferably from the header and payload secured by the F-Link process. It is preferably created using a single channel and is not secure, but based on secured data.As an alternative to F-Link, another method with comparable properties could also be used. Secure telegram generation is preferably achieved by ensuring that the coded program section (reference channel) participates in the channel during the creation of the user data using F-Link, thus ensuring correct creation before transmission. Implementing telegram protocols (e.g., in railway signaling technology) requires no intervention at the operating system level of a coded monoprocessor. The associated maintenance of the tool chain and system maintenance of the basic system can be eliminated. The SIMATIC internal communication function "Flexible F-Link" (F-Link) is preferably used, with the F-Link protocol preferably being checked using the F-Link CRC.

[0077] Finally, it should be mentioned that the features of all embodiments described above can be combined with each other in any way to form further other embodiments of the invention.

[0078] All features of subclaims can also be combined individually with each of the subordinate claims, either individually or in any combination with one or other subclaims, in order to obtain further other embodiments.

Claims

1. Method for creating a control signal, in which - security data (SD) is formed with original payload data (ND) and / or check data (PD) based on the original payload data (ND), - a security attachment (SA) is created and appended to the security data (SD) to form extended security data (ESD), - the extended security data (ESD) is evaluated, and - the control signal is created as a function of whether there is a correlation between the security attachment (SA) contained in the extended security data (ESD) and the security data (SD) contained in the extended security data (ESD), wherein the above-cited steps are carried out in one or several secure sections (121, 122) of a computing system (100), and wherein - a telegram creation module (30) with the extended security data (ESD) forms an intermediate telegram (ZTG) comprising a payload data section (A1) and a security section (A2), wherein the security data (SD) is appended as payload data content to the payload data section (A1) and the security attachment (SA) is appended to the security section (A2), - the intermediate telegram (ZTG) is forwarded to a telegram receive module (40), - the telegram receive module (40) receives the intermediate telegram (ZTG) created by the telegram creation module (30) and evaluates the extended security data (ESD) contained therein, and - the telegram receive module (40) creates the control signal as a function of whether there is a correspondence between the payload data content and the security attachment (SA), characterised in that - the telegram creation module (30) and the telegram receive module (40) are integrated in the afore-cited secure section(s) (121, 122) of the computing system (100), - the telegram receive module (40) creates as the control signal a data telegram-based release signal (FS1), which releases an emission of a data telegram (DTG) if there is a correspondence between the payload data content and the security attachment (SA), and - the telegram receive module (40) creates as the control signal a data telegram-based blocking signal (BS1), which blocks an emission of the data telegram (DTG) if there is no correspondence between the payload data content and the security attachment (SA).

2. Method according to claim 1, characterised in that - the telegram receive module (40) creates as the control signal or as a further control signal a storage data-related release signal (FS2), which releases a storage of data if there is a correspondence between the payload data content and the security attachment (SA), and / or - the telegram receive module (40) creates as the control signal or as a further control signal a storage data-related blocking signal (BS2), which blocks a storage of data if there is no correspondence between the payload data content and the security attachment (SA).

3. Method according to one of the preceding claims, characterized in that - the telegram creation module (30) creates the security attachment (SA) with reference payload data (RND) which is present in the secure section (121, 122) or one of the secure sections (121, 122) and differs from the original payload data (ND) and was created separately from the original payload data (ND) but in the error-free case is identical to the original payload data (ND) in terms of data content, and / or with reference check data (RPD) based on the reference payload data (RND), and appends said reference data-based security attachment (SA) to the security section (A2), and - the telegram receive module (40) creates the control signal or at least one of the control signals as a function of whether there is a correspondence between the payload data content based on the original payload data (ND) and the reference data-based security attachment (SA).

4. Method according to claim 3, characterised in that the telegram creation module (30) appends the original payload data (ND) and the check data (PD) to the payload data section (A1) of the intermediate telegram (ZTG) and forms the security attachment (SA) by applying a security function, in that it applies the security function to the reference payload data (RND) and the reference check data (RPD).

5. Method according to claim 3, characterised in that the telegram creation module (30) appends the original payload data (ND), but not the check data (PD), to the payload data section (A1) of the intermediate telegram (ZTG) and forms the security attachment (SA) by applying a security function, in that it applies the security function to the reference payload data (RND).

6. Method according to claim 3, characterised in that the telegram creation module (30) appends the check data (PD), but not the original payload data (ND), to the payload data section (A1) of the intermediate telegram (ZTG) and forms the security attachment (SA) by applying a security function, in that it applies the security function to the reference check data (RPD).

7. Method according to one of the preceding claims, characterised in that - the security attachment (SA) is created with reference payload data (RND) which is present in the secure section (121, 122) or one of the secure sections (121, 122) and differs from the original payload data (ND) and was created separately from the original payload data (ND) but in the error-free case is identical to the original payload data (ND) in terms of data content, and / or with reference check data (RPD) based on the reference payload data (RND), and - the control signal is created as a function of whether there is a correspondence between the payload data content based on the original data and the reference data-based security attachment (SA).

8. Method according to one of the preceding claims, characterised in that the application of the security function also comprises at least the formation of a cyclic redundancy code, which is appended to the security attachment (SA).

9. Method according to one of the preceding claims, characterised in that the method steps are carried out exclusively in one or several sections (121, 122) of the computing system (100) which are secure as a result of software programming and / or hardware security.

10. Method according to one of the preceding claims, characterised in that the method steps listed in the above claims are distributed over at least two software sections (21, 22) which work securely and are independent of one another.

11. Method according to one of the preceding claims 1 to 10, characterised in that - the data telegram (DTG), the emission of which is released by the release signal (FS1) or blocked by the blocking signal (BS1), is completed in a non-secure section (123) of the computing system (100), - wherein the original payload data (ND) and / or the reference payload data (RND) is appended to a payload data section (A1) of the data telegram (DTG), and - wherein the check data (PD) and / or the reference check data (RPD) is appended to the security section (A2) of the data telegram (DTG).

12. Computing system (100), characterised in that - the computing system (100) is programmed such that it can carry out a method according to one of the preceding claims, - wherein at least the method steps listed in claims 1 to 10, insofar as they are carried out by the computing system (100), are carried out exclusively in one or several sections (121, 122) of the computing system (100) which are secure as a result of software programming and / or hardware security.

13. Railway engineering component, in particular rail vehicle (300) or railway trackside facility (310), characterised in that the railway engineering component has a computing system (100) according to claim 12 or can carry out a method in accordance with the invention according to one of the preceding claims 1 to 10.