Monitoring system for checking a system integrity at a subsequent stage

EP4591195A1Pending Publication Date: 2025-07-30SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023813579
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-16
Filing Date
2023-11-15
Publication Date
2025-07-30

AI Technical Summary

Technical Problem

Existing systems for monitoring the integrity of dynamically reconfigurable automation systems, such as those in Industry 4.0, face challenges in allowing flexible adaptation while ensuring system integrity, as traditional security approaches restrict changes and are not suitable for dynamically reconfigurable systems.

Method used

A monitoring system that records configuration changes and checks their admissibility using change information, employing a smart contract or AI-based algorithms to determine if changes are permissible, ensuring system integrity by preventing inadmissible changes before they occur, and providing a rollback mechanism to earlier configurations if issues arise.

Benefits of technology

This approach ensures the integrity of reconfigurable systems by allowing necessary changes while maintaining system reliability, enabling flexible adaptation and rapid recovery to functional states, thus enhancing the resilience of cyber-physical systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000025_0000
    Figure 00000025_0000
  • Figure 00000026_0000
    Figure 00000026_0000
  • Figure 000026
    Figure 000026
Patent Text Reader

Abstract

The invention relates to a monitoring system (1) for checking an integrity of a reconfigurable system (2), wherein the reconfigurable system (2) comprises a plurality of components (21), the monitoring system (1) comprising: - a receiving unit, designed to receive a plurality of datasets, wherein each dataset (23) of the plurality of datasets originates from one of the components (21) of the plurality of components of the reconfigurable system (2), wherein each dataset (23) of the plurality of datasets describes at least one performed configuration change on a particular component (21) of the plurality of components of the reconfigurable system (2) by way of change information, wherein the change information indicates a type of the at least one performed configuration change in each case, - a checking unit, designed to check an admissibility of the particular performed configuration change on the basis of the change information, and an output unit, designed to take a result of the checking as a basis for providing an output. The invention also relates to a superordinate system and an associated method.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Monitoring system for downstream testing of system integrity

[0003] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.

[0004] BACKGROUND OF THE INVENTION

[0005] Field of the invention

[0006] The present invention relates to a monitoring system for checking the integrity of a reconfigurable system. The invention also relates to a higher-level system and a corresponding method.

[0007] Description of the state of the art

[0008] Flexible production, especially within the context of Industry 4.0, should enable the rapid adaptation of automation solutions, especially automation functions, to changing conditions. This should also be made possible through increasing digitalization using open computing platforms for the implementation of virtualized automation functions. The adaptation of existing automation functions and the introduction of new automation functions should be faster in the future.

[0009] Automation systems are therefore subject to regular changes. As a consequence, preventing changes to ensure integrity is not a sensible approach to protecting the integrity of the automation system and its components, as this would also prevent any changes to the automation functions. Intrusion detection systems (IDS) are known to detect attacks. These can analyze the configuration on hosts (HIDS, host-based intrusion detection system) or network communication (NIDS, network-based intrusion detection system). An IDS can generally identify a change in behavior (anomaly-based IDS) or a known attack pattern (signature-based IDS) as an attack.

[0010] There are known solutions for File Integrity Monitoring (FIM) that detect changes to a file system.

[0011] In the case of distributed ledgers (blockchain), it is known that a program code (smart contract) determines whether a transaction is permissible, i.e. whether, in the abstract, a certain change to the state managed in the distributed ledger is permissible.

[0012] By Rainer Falk, Steffen Fries, "System Integrity Monitoring for Industrial Cyber-Physical Systems", International Journal on Advances in Security, vol. 11, no. 1 & 2, year 2018, http: / / www.iariajournals.org / security. This system is known for its integrity monitoring. It is also known to determine the integrity of the cyber-physical system (CPS) in the real, physical world using so-called "trusted sensors." These provide trustworthy physical measurement data that can be used for cross-comparison with the process image available in an automation system of the CPS.

[0013] From Rainer Falk, Steffen, Fries, "Enhancing the Resilience of Cyber-Physical Systems by Protecting the Physical-World Interface", International Journal on Advances in Security, vol 13 no 1 & 2, year 2020, http: / / www.iaria ournals.org / security it is known that in a dynamically reconfigured cyber-physical system its integrity monitoring system must also be adapted to the current configuration (reference policy) (see section IV. C "Policy Adaptation for Dynamically Reconfigurable CPS”) .

[0014] Operating systems such as Microsoft Windows have restore points. If a Windows system is malfunctioning, a user or administrator can revert to an earlier, functional configuration.

[0015] The object of the invention is to provide a solution for improved protection of the system integrity of dynamically reconfigurable systems, in particular automation systems and industrial systems.

[0016] SUMMARY OF THE INVENTION

[0017] The invention is based on the features of the independent claims. Advantageous developments and refinements are the subject of the dependent claims. Embodiments, possible applications, and advantages of the invention will become apparent from the following description and the drawings.

[0018] The invention relates to a monitoring system for checking the integrity of a reconfigurable system, wherein the reconfigurable system has a plurality of components, the monitoring system comprising: a receiving unit, designed to receive a plurality of data records, wherein each data record of the plurality of data records originates from one of the components of the plurality of components of the reconfigurable system, wherein each data record of the plurality of data records describes at least one configuration change that has occurred in each case in a component of the plurality of components of the reconfigurable system by means of change information, wherein the change information in each case indicates a type of the at least one configuration change that has occurred, a checking unit, designed to check the admissibility of the respective configuration change that has occurred based on the change information, by checking the admissibility,to check whether the type of at least one configuration change that has been made is permissible and / or plausible, and an output unit designed to provide an output depending on the result of the check.

[0019] The admissibility check is not based on comparing the actual configuration with a fixed, specified target configuration, but on checking whether the configuration changes made are permissible and / or plausible.

[0020] The type of at least one configuration change that occurred describes a type of configuration change that occurred to at least one component of the plurality of components of the reconfigurable system. The type of change specifies how the configuration was changed. In addition, the type of change specifies, in particular, which functional category of the configuration was changed. A functional category of the configuration includes, in particular, security functions, network functions, control functions, communication functions, management functions, and / or identification functions.

[0021] A positive result from the admissibility check of the respective configuration change means that a configuration change made to one of the components of the majority of components in the reconfigurable system is permissible. This means that the respective component is intact. If all components of the majority of components are intact, it is concluded that the entire reconfigurable system is intact. The output unit is designed to provide the output depending on the integrity of the respective components and / or the reconfigurable system. A negative result from the admissibility check of the respective configuration change means that a configuration change made to one of the components of the majority of components in the reconfigurable system is impermissible. This means that the respective component is not intact.If at least one of the plurality of components lacks integrity, it is concluded that the entire reconfigurable system lacks integrity. The output unit is configured to provide the output depending on the lack of integrity of the respective components and / or the reconfigurable system.

[0022] The reconfigurable system is designed in particular as a cyber-physical system (CPS).

[0023] For the purposes of the invention, "plurality" refers to the plural. For the purposes of the invention, "plurality" is not to be understood as a larger proportion of a specific number. For the purposes of the invention, "plurality" means, in particular, at least 3, preferably more than 10, particularly preferably more than 50 or more than 100. This applies to both the plurality of components and the plurality of data sets.

[0024] The majority of components of the reconfigurable system are designed to provide the majority of data sets. To protect know-how, the majority of data sets are each privacy-protected, particularly through anonymization, pseudonymization, the use of verifiable credentials / verifiable presentations, or through privacy-protecting cryptographic methods such as homomorphic encryption or secure multiparty computation.

[0025] Each data record of the plurality of data records is created and provided, in particular, by the affected component itself, by an additional component associated with the affected component, or by an app of the affected component. An additional component or app can repeatedly determine the configuration of a component, in particular via OPC UA or NETCONF, and cryptographically confirm the determined changes against previously determined configurations. When monitoring configuration changes on a component itself, it may be possible toAdditional information must be determined and confirmed, in particular what led to the configuration change, in particular which authentication credential and / or which communication protocol and / or which device interface was used for a configuration change (identifier or authentication credential / certificate for remote access, in particular via HTTPS, NETCONF / TLS, NETCONF / ssh, OPC UA).

[0026] The confirmation of integrity is particularly privacy-protected to protect know-how, in particular through anonymization, pseudonymization, through the use of verifiable credentials / verifiable presentations, or through privacy-protecting cryptographic methods such as homomorphic encryption or secure multiparty computation.

[0027] With regard to a reconfigurable system, especially a cyber-physical system, the plant operator, several machine manufacturers of the production machines used, several device manufacturers of the automation components used, an integrator, an IT department, or an IoT cloud provider have a legitimate interest in system integrity monitoring. However, they are each only responsible for a sub-area (AOR). Therefore, it is further proposed to filter the majority of data records according to different areas of responsibility and make them available to a respective AOR monitoring system for review. An AOR monitoring system, in turn, confirms whether the reviewed changes are permissible from the respective responsibility perspective.

[0028] From this, an overall Cyber ​​Physical System (CPS) picture is determined which indicates from the perspective of which AOR areas of responsibility the integrity of the system is given. This information is provided in particular to a production planning system or a production data management system. Production planning for further production processes or the release of manufactured products or downstream tests on the manufactured products can be carried out depending on whether the CPS used for this purpose or the CPS areas used for this purpose, in particular production machines, are or were in a permissible state. The information can also be passed on to a CPS component management system, in particular a unified device management system (common device management), in order to initiate a rollback of configuration changes that are not recognized as permissible.

[0029] In summary, one idea of ​​the invention is a monitoring system, in particular an integrity monitoring system, for industrial automation systems that records the majority of data records and thus the change information of the majority of components. The monitoring system checks the admissibility of changes to the majority of components of the reconfigurable system.

[0030] One aspect of the invention thus consists in a monitoring system that reliably records configuration changes that have occurred and subsequently verifies the type of configuration changes using program code, in particular a smart contract. "Subsequently" means that the configuration changes have already been made at the time of the verification.

[0031] Thus, an integrity monitoring system for a reconfigurable system is proposed that permits configuration changes. Unlike known integrity monitoring tools (File Integrity Monitoring (FIM), Intrusion Detection System (IDS)), it does not detect changes as inadmissible before they are implemented, but rather monitors and validates the nature of the observable changes. In abstract terms, this can be understood as a type of distributed ledger ("blockchain"), in which transactions (here: configuration changes of the reconfigurable system) are first recorded in a transaction database. Only subsequently is it checked whether these transactions, which are already present in the database (because they were recorded first), are permissible according to a smart contract.

[0032] This results in the advantage for a Cyber ​​Physical System (CPS) that is under distributed control (Distributed Ledger, Blockchain) that recovery points make it possible to return to an earlier, still functional configuration state of the CPS in the event of problems or unauthorized manipulation.

[0033] A conventional security approach is access control, which tightly controls access so that only permitted actions can be performed. Another conventional approach is to detect deviations from a reference state defined as integral (established or learned) as tampering. Such conventional security approaches assume a fixed configuration. The disadvantage is that they are therefore not suitable if configuration changes are to be made regularly in order to flexibly adapt a production system to different requirements. If set up restrictively, such security approaches would hinder flexible configuration adaptation or reconfiguration of industrial automation and control systems (generally: Industrial IoT or Cyber-Physical Systems). They are therefore only useful for static industrial systems.However, for systems that are intended to be dynamically reconfigurable, extensive changes must be permitted.

[0034] In the present application, however, a complementary security approach is proposed to reliably record the configuration changes made and subsequently verify the admissibility of the changes. In a further development of the invention, the reconfigurable system is designed as: a cyber-physical system and / or an Internet of Things system and / or an industrial system and / or an automation system and / or a manufacturing system and / or a control system and / or a robot and / or a production machine and / or a driverless transport system.

[0035] In a further development of the invention, the receiving unit is additionally designed to retrieve the plurality of data records.

[0036] The majority of data records can be retrieved, in particular, from a database by the receiving unit. The majority of data records and thus the change information of the majority of components are stored, in particular, in a database (also referred to as a CPS Component Configuration Change Database), in particular in a relational database, in an object database, or in a distributed transaction database (also referred to as a distributed ledger and / or blockchain). A history of the changes made to the majority of components of the reconfigurable system is thus available.

[0037] In a further development of the invention, the plurality of data records each has cryptographic protection.

[0038] This has the advantage that the majority of data records are protected against manipulation and thus valid change information is assumed. In a further development of the invention, the change information provides:

[0039] - A time and / or

[0040] - a starting point and / or

[0041] - a time limit and / or

[0042] - an initiator and / or

[0043] - a location of initiation of at least one configuration change.

[0044] The initiator of at least one configuration change can also be described as the executor of at least one configuration change.

[0045] According to the invention, the monitoring system checks the admissibility of the configuration changes made to the majority of the components of the reconfigurable system. In addition to the type of at least one configuration change made, it is possible to evaluate when and / or by whom and / or at what location each change was made to a respective component of the reconfigurable system. This has the advantage that additional information is included to check admissibility and the result of the check is more reliable. The admissibility of a single configuration change can be checked. Likewise, the admissibility of a sequence of multiple configuration changes can be checked.

[0046] In a further development of the invention, the type of at least one configuration change that has occurred includes:

[0047] - a safety-related change and / or

[0048] - a changed network configuration and / or

[0049] - a change to an industrial project and / or

[0050] - installing an update. In a further development of the invention, the testing unit is designed to test the change information of a first configuration change of a first component of the plurality of components in conjunction with the change information of a second configuration change of a second component of the plurality of components.

[0051] According to the invention, the at least one configuration change of a component is already recognizable as inadmissible in itself, but its effect on the reconfigurable system, in particular inconsistencies between the components and a further configuration change, is also recognizable and can be assessed as inadmissible. Thus, the testing unit is particularly designed to check whether the components have been consistently reconfigured, especially during a setup phase of a production run.

[0052] In addition, it is checked whether changes to the components that may have an impact on the entire reconfigurable system, especially changes to the network configuration, are consistent in content and are implemented in a consistent manner. This makes it possible to determine whether identical or similar changes are applied to multiple components within a defined period of time.

[0053] In addition, the testing unit is specifically designed to check whether configuration changes serve different purposes and / or are divided into different change processes. Inconsistencies in these criteria, in particular, indicate an inadmissible configuration.

[0054] In a further development of the invention, the testing unit is designed to use a program code, in particular a smart contract and / or an algorithm based on artificial intelligence and / or at least one security policy to check the admissibility.

[0055] The validation of configuration changes is therefore primarily carried out by a smart contract, i.e., generally by a program code. This checks against definable criteria to determine whether a configuration change to the CPS is permissible.

[0056] Alternatively or additionally, the admissibility of configuration changes is checked by an algorithm based on artificial intelligence, i.e. AI-based, in particular by training permissible configuration changes in a training phase based on criteria and by detecting impermissible changes in the productive phase and, if necessary, prohibiting them, i.e. recognizing them as impermissible.

[0057] In a further development of the invention, the test unit is designed:

[0058] - an effect of at least one configuration change and / or

[0059] - a changed input behavior and / or output behavior of the majority of components due to the at least one configuration change, in particular a functional change, a performance change and / or a change in the real-time behavior and / or

[0060] - to consider the purpose of at least one configuration change to check its admissibility.

[0061] It is therefore further proposed to determine the input behavior and / or output behavior of the majority of components with respect to the majority of data records. This can be determined directly at input / output interfaces or on a data bus. Changes in input behavior and / or output behavior can be detected even if there are unintended, unforeseen indirect effects on some automation functions. Therefore, both the input / output behavior of the CPS or the components contained therein are monitored, as are the configuration changes made to CPS components. This information is used, in particular, to determine which configuration change led to undesired input / output behavior.In particular, an additional cross-comparison of the recorded configuration changes of the CPS components and the input / output behavior of CPS automation / control functions is used to identify which changes may have led to inadmissible CPS behavior. Subsequently, a rollback to a correctly functioning version is performed automatically.

[0062] In a further development of the invention, the test unit is also designed

[0063] - an assessment of the integrity of the respective component of the plurality of components and / or

[0064] - to create an assessment of the integrity of the reconfigurable system based on the change information.

[0065] According to this embodiment, the monitoring system classifies components of the plurality of components and / or the reconfigurable system not only as integer or non-integer, but also provides an integrity rating, particularly in the form of a trustworthiness measure. A higher rating means a higher probability of integrity. A comparatively low rating means a lower probability of integrity. In addition, the rating includes, in particular, information about which configuration change or combination of changes, particularly as a reference to the change(s), led to the lower integrity rating.

[0066] The rating and / or the trustworthiness measure can be determined for the reconfigurable system as a whole. Likewise, multiple trustworthiness measures can be determined for different sub-areas of the reconfigurable system. The sub-areas can be fixed, but preferably the sub-areas are determined dynamically, each with a uniform trustworthiness measure.

[0067] In a further development of the invention, the output is as:

[0068] - an integrity confirmation and / or

[0069] - a cryptographically protected integrity confirmation and / or

[0070] - an integrity assessment and / or

[0071] - a warning message and / or

[0072] - a warning signal and / or

[0073] - an alarm and / or

[0074] - a production stop order was issued.

[0075] If the change is identified as invalid, a corresponding output is generated. Alternatively or additionally, an alarm is triggered or a production stop is initiated.

[0076] If the changes are recognized as permissible, a cryptographically protected integrity confirmation, in particular an integrity attestation, is optionally created, which confirms that the reconfigurable system is currently or has been in a permissible, integrity state within a defined period of time. According to this embodiment, the integrity confirmation is created and output by the output unit. Alternatively or additionally, an integrity confirmation, also referred to as an integrity attestation, is created and output in particular by a downstream integrity confirmation unit, in particular a CPS system integrity attestor. In the case of a downstream integrity confirmation unit, this receives the result of the admissibility check, which is created by the check unit.

[0077] The invention further comprises a higher-level system comprising: a monitoring system according to one of the preceding claims and a reconfigurable system, wherein the reconfigurable system has the plurality of components.

[0078] The plurality of components is configured to provide the plurality of data sets. The components are configured, in particular, as automation components. For this purpose, a unit for detecting configuration changes and, in particular, for cryptographically confirming the detected configuration changes is provided on the components.

[0079] In a further development of the invention, the higher-level system also comprises:

[0080] - a database designed to provide the majority of data sets and / or

[0081] - an attestation, trained to create an integrity attestation depending on the issue.

[0082] The invention also includes a method for checking the integrity of a reconfigurable system, the reconfigurable system having a plurality of components, comprising the steps of: receiving a plurality of data records, each data record of the plurality of data records originating from one of the components of the plurality of components of the reconfigurable system, each data record of the plurality of data records describing at least one configuration change made to a respective component of the plurality of components of the reconfigurable system by means of change information, the change information specifying a type of the at least one configuration change made, checking the admissibility of the respective configuration change made using the change information, and outputting an output depending on a result of the check.

[0083] A further development of the invention relates to a method according to the invention for checking the integrity of a reconfigurable system by means of a monitoring system according to the invention.

[0084] BRIEF DESCRIPTION OF THE DRAWINGS

[0085] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawings.

[0086] It shows

[0087] Fig. 1 is a schematic representation of a higher-level system comprising, among other things, a monitoring system according to the invention and

[0088] Fig. 2 shows a flow diagram of the method according to the invention. DETAILED DESCRIPTION OF THE INVENTION

[0089] Fig. 1 shows a higher-level system comprising: a monitoring system 1 according to the invention, divided into two monitoring systems 1 for different sub-areas of a reconfigurable system 2, the reconfigurable system 2, wherein the reconfigurable system 2 has the plurality of components 21, the plurality of components 21 is connected to a database 3 via a gateway 22 and a network 5, the database 3 is designed to provide the plurality of data records 23 to the monitoring systems 1 (stored over time t) and to receive the plurality of data records 23 from the reconfigurable system 2, wherein each data record of the plurality of data records 23 describes at least one configuration change that has occurred to a respective component 21 of the plurality of components 21 of the reconfigurable system 2 by means of change information, wherein the change information in each case indicates a type of the at least one configuration change that has occurred,and an attestation 4, designed to create an integrity attestation 41 depending on an output of the monitoring system 1.,

[0090] Fig. 1 thus shows in particular an implementation example with three CPS components 21 in an automation network 2. In addition, two system integrity monitoring units 1 for two different areas of responsibility are shown. An area of ​​responsibility can, for example, be given by a subset of the CPS components 21 and / or by the type, i.e. the functional category, of configuration changes made. The proposed monitoring system 1, also integrity monitoring system 1, can be understood as a type of distributed ledger (blockchain) in which a smart contract checks the admissibility of a sequence of transactions recorded in the data records 23. However, the configuration changes have already been made and the corresponding transactions are already stored in the database 3. Unlike in a known blockchain / distributed ledger, their admissibility is only checked downstream.In this case, multiple verifications can be performed according to the different areas of responsibility, i.e., through multiple "smart contracts." A verification result is provided.

[0091] From the result of the check, an integrity attestation 41 is optionally determined by an attestation 4 to indicate whether the configuration changes already made were permissible according to the transactions stored in the database 3 or whether this was not the case. The integrity attestation 41 can, in particular, specify which functional areas, in particular for which production machines or which production lines (area of ​​responsibility) of the reconfigurable system 2, the configuration changes applied to the functional areas were permissible.

[0092] Fig. 2 shows a method for checking the integrity of a reconfigurable system 2, wherein the reconfigurable system 2 has a plurality of components, comprising the steps:

[0093] Step S1: receiving a plurality of data records, wherein each data record 23 of the plurality of data records originates from one of the components 21 of the plurality of components of the reconfigurable system 2, wherein each data record 23 of the plurality of data records describes at least one configuration change that has occurred in each case on a component 21 of the plurality of components of the reconfigurable system by means of change information, wherein the change information in each case indicates a type of the at least one configuration change that has occurred, - Step S2: checking the admissibility of the respective configuration change that has occurred based on the change information, wherein the checking comprises checking whether the type of the at least one configuration change that has occurred is permissible and / or plausible, and - Step S3: outputting an output depending on a result of the checking.

[0094] Although the invention has been illustrated and described in detail by the embodiments, the invention is not limited by the disclosed examples and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.

Claims

Patent claims 1. Monitoring system (1) for checking the integrity of a reconfigurable system (2), wherein the reconfigurable system (2) has a plurality of components (21), the monitoring system (1) comprising: a receiving unit, designed to receive a plurality of data records, wherein each data record (23) of the plurality of data records originates from one of the components (21) of the plurality of components of the reconfigurable system (2), wherein each data record (23) of the plurality of data records describes at least one configuration change that has occurred to a respective component (21) of the plurality of components of the reconfigurable system (2) by means of change information, wherein the change information in each case indicates a type of the at least one configuration change that has occurred, a checking unit, designed to check the admissibility of the respective configuration change that has occurred based on the change information, by checking the admissibility,to check whether the type of at least one configuration change that has been made is permissible and / or plausible, and an output unit designed to provide an output depending on the result of the check.

2. Monitoring system (1) according to claim 1, wherein the reconfigurable system (2) is designed as: a cyber-physical system and / or an Internet of Things system and / or an industrial system and / or an automation system and / or a manufacturing system and / or a control system and / or a robot and / or a production machine and / or a driverless transport system.

3. Monitoring system (1) according to one of the preceding claims, wherein the receiving unit is additionally designed to retrieve the plurality of data sets.

4. Monitoring system (1) according to one of the preceding claims, wherein the plurality of data records each have cryptographic protection.

5. Monitoring system (1) according to one of the preceding claims, wherein the change information: - A time and / or - a starting point and / or - a time limit and / or - an initiator and / or - a location of an initiation of at least one configuration change that has occurred.

6. Monitoring system (1) according to one of the preceding claims, wherein the type of at least one configuration change that has occurred: - a safety-related change and / or - a changed network configuration and / or - a change to an industrial project and / or - includes installing an update.

7. Monitoring system (1) according to one of the preceding claims, wherein the test unit is designed to process the change information of a first configuration change of a first component (21) of the plurality of components in connection with the change information of a second configuration change of a second component (21) of the plurality of components.

8. Monitoring system (1) according to one of the preceding claims, wherein the test unit is designed - a program code, in particular smart contract and / or - an algorithm based on artificial intelligence and / or - use at least one security policy to check admissibility.

9. Monitoring system (1) according to one of the preceding claims, wherein the test unit is designed - an effect of at least one configuration change and / or - a changed input behavior and / or output behavior of the majority of components due to the at least one configuration change, in particular a functional change, a performance change and / or a change in the real-time behavior and / or - to consider the purpose of at least one configuration change to check its admissibility.

10. Monitoring system (1) according to one of the preceding claims, wherein the test unit is further designed - an assessment of the integrity of the respective component (21) of the plurality of components and / or - to create an assessment of the integrity of the reconfigurable system (2) based on the change information.

11. Monitoring system (1) according to one of the preceding claims, wherein the output is: - an integrity confirmation and / or - a cryptographically protected integrity confirmation and / or - an integrity assessment and / or - a warning message and / or - a warning signal and / or - an alarm and / or - a production stop command is formed.

12. A higher-level system comprising: a monitoring system (1) according to one of the preceding claims and a reconfigurable system (2), wherein the reconfigurable system (2) has the plurality of components.

13. The higher-level system of claim 12, further comprising: - a database (3) designed to provide the plurality of data sets and / or - an attestation (4) designed to create an integrity attestation (41) depending on the output.

14. A method for checking the integrity of a reconfigurable system (2), wherein the reconfigurable system (2) has a plurality of components, comprising the steps of: receiving (S1) a plurality of data records, wherein each data record (23) of the plurality of data records originates from one of the components (21) of the plurality of components of the reconfigurable system (2), wherein each data record (23) of the plurality of data records describes at least one configuration change made to a respective component (21) of the plurality of components of the reconfigurable system by means of change information, wherein the change information indicates a type of the at least one configuration change that has taken place, checking (S2) a permissibility of the respective configuration change that has taken place based on the change information, wherein the checking comprises checking whether the type of the at least one configuration change that has taken place is permissible and / or plausible, and outputting (S3) an output depending on a result of the checking.

15. A method for checking the integrity of a reconfigurable system (2) according to claim 14 by a monitoring system (1) according to one of claims 1 to 11.