Method for configuring and / or updating software of target components of a safety-critical system by means of a central authorization unit, and safety-critical system having an authorization unit

EP4630916A1Pending Publication Date: 2025-10-15HITACHI RAIL GTS DEUTSCHLAND GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023821964
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-09
Filing Date
2023-12-08
Publication Date
2025-10-15

AI Technical Summary

Technical Problem

Existing methods for updating software in safety-critical systems, such as railway signaling systems, are not scalable and require human intervention, as they do not support automatic state transitions for permanently authorizable target components, which are essential for maintaining compliance with safety levels like SIL4.

Method used

A method that utilizes a central authorization unit to manage and automate the state transitions of permanently authorizable target components during software updates, ensuring secure communication and integrity checks, allowing for remote updates without requiring new authorizations upon restart, thereby enabling the system to transition automatically between operational and maintenance states.

Benefits of technology

This method allows for secure, automated, and scalable software updates of safety-critical systems, reducing the need for human intervention and ensuring that all target components are properly updated and authorized, maintaining the required safety levels like SIL4.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a method for updating software of target components of a safety-critical system (SYS), wherein the safety-critical system (SYS) comprises a maintenance management component (MDM), a central authorization unit (A) and a permanently authorizable target component (TC-A, TC-B, TC-C), and wherein the starting system configuration comprises a first combination of target components and the target system configuration comprises a second combination of target components, the method comprising the following method steps: a) an external maintenance instance (M) requests an update of the system configuration; b) the authorization unit (A) switches from the "inactive" state to the "update" state; c) the permanently authorizable target components (TC-A, TC-B, TC-C) are informed of the update to be carried out; d) the authorization unit (A) performs a system integrity pre-check and triggers a first state change and a version check of the permanently authorizable target components (TC-A, TC-B, TC-C); e) the permanently authorizable target components (TC-A, TC-B, TC-C) perform a version check and, if necessary, a version update and report the result to the authorization unit (A); f) the authorization unit (A) perform a system integrity check and triggers a second state change of the permanently authorizable target components (TC-A, TC-B, TC-C) if the system integrity check was successful; g) the authorization unit (A) switches from the "update" state to the "inactive" state.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method for setting up and / or updating software of target components of a safety-critical system using a central authorization unit and safety-critical system with authorization unit

[0002] Background of the invention

[0003] The invention relates to a method for setting up and / or updating software of target components of a safety-critical system from a start system configuration to a target system configuration, wherein the safety-critical system comprises a maintenance management component, a central authorization unit, and at least one permanently authorizable target component, and wherein the start system configuration comprises a first combination of target components and the target system configuration comprises a second combination of target components. The invention also relates to a safety-critical system comprising a maintenance management component and at least one permanently authorizable target component that does not require new authorization for its restart. Software on system components, e.g., signaling devices in a railway signaling system, must be installed or updated for various reasons (e.g.,Bug fixes, security patches, new software versions, configuration changes). Since system components may be physically distributed, it is advantageous to perform updates using a remote update function that enables distributed system components to be updated over the network from a central location. A system configuration includes, in particular, information about which permanently authorizable target components are involved and their version requirements. During the system configuration, the composition of the system components (combination of target components) and / or the version requirements for the individual target components can change. Target components are referred to below as system components that are part of a system configuration (startup and / or target system configuration) and are therefore involved in the update.

[0004] EULYNX [EULYNX] discloses a method for modular testing of distributed components of safety-relevant systems. In particular, the method known from [EULYNX] allows field elements (e.g., switches, axle counters, signals, etc.) to request authorization from an interlocking system. To verify data integrity, checksums are exchanged between the relevant applications via SCI interfaces. The method known from [EULYNX] is implemented during operation and describes only the format of the SCI messages and the existence of the checksums, but not how exactly the checksums are formed, nor whether and how they map configuration data, the operating system, or the application software. It is only suitable for updating the software of "connection-bound authorizable target components," i.e., target components that must always request new authorization upon restart, e.g., from a higher-level target component.Updating permanently authorizable target components is not possible with the method known from [EULYNX] while maintaining the safety level SIL4 (CENELEC SIL4) required for safety-critical systems. Instead, the permanently authorizable target components must be updated individually and checked by maintenance personnel. The specification only includes the configuration data of the currently controlled target component. Therefore, adjustments are necessary to check a different target component. This is the object of the invention.

[0005] The object of the invention is to propose a method for updating with which the required state transitions of the individual target components are carried out largely automatically.

[0006] Description of the invention

[0007] This object is achieved according to the invention by a method according to patent claim 1 and a safety-critical system according to patent claim 14.

[0008] The method according to the invention comprises the following method steps: a) an external maintenance instance requests an update of the system configuration; b) the authorization unit changes from the "inactive" state to the "update" state; c) the permanently authorizable target components are informed of the update to be performed; d) the authorization unit performs a system integrity pre-check and triggers a first state change and a version check of the permanently authorizable target components; e) the permanently authorizable target components perform a version check and, if necessary (i.e., if necessary), a version update and report the result to the authorization unit; f) the authorization unit performs a system integrity check and triggers a second state change of the permanently authorizable target components if the system integrity check was successful;g) the authorization unit changes from the "updating" state to the "inactive" state;

[0009] In the method according to the invention, secure communication takes place between the permanently authorizable target components and a central control authority, namely the authorization unit, which controls and monitors the update process of the permanently authorizable target components. The request for updating the system configuration in step a) is preferably made to the maintenance management component (outside the authorization unit) and is then transmitted internally to the authorization unit. In this case, the maintenance management component informs the authorization unit about the target system configuration. However, it is also possible for the request to be made directly to the authorization unit.

[0010] In step c), the permanently authorizable target components are informed about the target system configuration, in particular about which permanently authorizable target components are involved in the target system configuration, so that later, preferably, only those permanently authorizable target components that are part of the target system configuration need to load data from the data store. The information to the permanently authorizable target components can be sent directly from the authorization unit, but preferably from the authorization unit via the maintenance management component. In the latter case, the maintenance management component acts as a proxy between the authorization unit and the permanently authorizable target components.

[0011] "Permanently authorizable target components" are configured to enter safety-critical active operation (operational state) without requiring new authorization after an explicitly granted authorization, particularly after a reboot. In contrast, "connection-bound authorizable target components" receive their authorization for safety-critical active operation as soon as they are started and establish a connection to a component authorized by configuration, which then reissues authorization each time. This authorization expires upon termination of the connection, particularly upon reboot. The authorization unit communicates with permanently authorizable target components.

[0012] Both the first combination of target components and the second combination of target components each comprise at least one of the permanently authorizable target components. The start and target component combinations can be identical, have an intersection, or comprise completely different permanently authorizable target components. As a rule, the start and target component combinations differ from one another, so that the start system configuration contains permanently authorizable target components that are not required in the target system configuration, and vice versa. During maintenance, the authorization unit communicates with the permanently authorizable target components, preferably via the maintenance management component as a proxy; however, the authorization unit is not required during operation. Accordingly, according to the invention, the authorization unit is only active during the maintenance process, not during operation.In order to prevent an inconsistent system in the event that one or more permanently authorizable target components do not perform the update and return to the "operational" state at a later runtime, the authorization unit must ensure the availability of all permanently authorizable target components for the next update process before granting a new operating authorization. To this end, the authorization unit controls the regular, safe state transition between operation and non-operation of the permanently authorizable target components and thus of the safety-critical system before and after the installation of the update (update).The authorization unit ensures that the permanently authorized target components have been properly updated according to the specifications of the target system configuration, are in the correct state, and, depending on the specifications of the target system configuration, re-authorize, retain, or relinquish their authorization. The method according to the invention allows the required state transitions to be automated at a high level of security, limiting human intervention to the bare minimum. The method according to the invention is thus scalable to a large number of system components.

[0013] In a particularly preferred variant of the method according to the invention, the external maintenance instance stores information on the target system configuration in a data repository before requesting the update in step a). The target components can then load the data required for the update from the data repository. Preferably, the required data is loaded before the first state change (state change to the "Maintenance" state) of the permanently authorizable target components.

[0014] Preferably, the authorization unit requests a secure confirmation of the update request from the external maintenance instance before transitioning to the "Update" state (step b)). The authorization unit's state transition to the "Update" state only occurs after the secure confirmation has been received from the external maintenance instance. This ensures that falsification of transmitted information is excluded. This secure confirmation is preferably provided by the maintenance management component. The confirmation should, in particular, contain: information regarding the action to be performed (update), start and target configuration, identification of the authorization unit, and timestamp.

[0015] In a particularly preferred variant of the method according to the invention, the authorization unit analyzes the target system configuration. Typically, both the start and the target configuration are analyzed. In special cases, there is no known start configuration (e.g., in the case of an initial system add-on), an analysis of the target configuration is sufficient, provided the external maintenance unit has assured the authorization unit that it is an initial system add-on. For the analysis, the authorization unit queries the data from the data storage. This preferably occurs before the first state change of the permanently authorizable target components is triggered.

[0016] The permanently authorizable target components can, after being informed in step c) about the update to be carried out, submit a request to the authorization unit to enter an update phase.

[0017] Preferably, the version check and the first state change of the permanently authorizable target components in step d) are triggered after the system integrity pre-check by transmitting a confirmation of entry into the update phase from the authorization unit to the permanently authorizable target components, whereby the permanently authorizable target components change from their current state to the "Maintenance" state.

[0018] The system integrity pre-check preferably checks whether all permanently authorizable target components of the starting system configuration have submitted a request to the authorization unit to enter an update phase.

[0019] With the request to enter the update phase, the permanently authorizable target components preferably transmit their current state. The authorization unit confirms the initiation of the update phase to the target components if the system integrity pre-check is successful, i.e., generally, if all permanently authorizable target components of the start configuration have transmitted the request to enter the update phase to the authorization unit. This general rule can be deviated from under certain specified conditions, for example, with assurance from the external maintenance instance, so that the authorization unit in particular can be explicitly assured that a permanently authorizable target component has been manually and permanently decommissioned or placed in the "maintenance" state.Alternatively, any condition for initiating the maintenance phase by the authorization unit can be omitted, so that each request is answered directly. This, however, opens up the possibility that individual permanently authorizable target components may already enter the maintenance phase while others are still in active operation (or could potentially be). During the first state change of the permanently authorizable target components, permanently authorizable target components that are part of the starting system configuration (first target component combination) change from the "operational" operating state to the "maintenance" state; permanently authorizable target components that are not part of the starting system configuration change from the "inactive" state to the "maintenance" state.

[0020] In order for the maintenance management component to be up to date with regard to the status of the permanently authorizable target components, it is advantageous if the authorization unit, after receiving the requests to enter an update phase, informs the maintenance management component about the current status and the currently installed software version of the permanently authorizable target components.

[0021] When updating the permanently authorizable target components in step e), those permanently authorizable target components that are part of the target system configuration install the data required for the update and can request the authorization unit to terminate the update phase. To ensure that those permanently authorizable target components that are not part of the target system configuration are actually out of service, it is advantageous for them to assure the authorization unit that they are out of service. They can also request the authorization unit to terminate the update phase.During the system integrity check in step f), the authorization unit checks whether all permanently authorizable target components of the start and target system configuration are in the "maintenance" or "inactive" state before permanently authorizing the permanently authorizable target components involved in the target system configuration to operate the new target system configuration. More specifically, the authorization unit checks that none of the permanently authorizable target components are in the potential operating state (i.e., temporarily out of service but permanently authorized, so that, in the event of an uncoordinated restart, active operation starts in an outdated system configuration) or in the actual operating state "operational." Preferably, the authorization unit checks that all permanently authorizable target components involved in the start or target system configuration are in the "maintenance" state.

[0022] The second state change of the permanently authorizable target components in step f) is triggered preferably after the system integrity check by a confirmation of the completion of the update phase by the authorization unit. Confirmation of the exit permanently authorizes the permanently authorizable target components of the target configuration and allows them to change to the "operational" state (second state change). Upon confirmation of the exit, authorization is revoked for the target components not included in the target system configuration; they change from the "maintenance" state to the "inactive" state, in which the active operation of the permanently authorizable target components is stopped.

[0023] The authorization unit can, preferably by changing to the "inactive" state in step g), inform the maintenance management component about the current state of the permanently authorizable target components.

[0024] To this end, the authorization unit preferably creates a status report on the status of all permanently authorizable target components, which is transmitted (preferably via the maintenance management component) to the external maintenance instance. The status report aggregates the status information of all permanently authorizable target components. The status report indicates whether the system is operational (integral). Based on this aggregated status report, the external maintenance instance can decide whether and in which system configuration the safety-critical system is available. The target system configuration preferably remains stored in a long-term memory of the authorization unit during maintenance-free periods, at least until the next update. This allows the authorization unit to be activated only during maintenance.

[0025] The method according to the invention can be used particularly advantageously in railway signaling systems as safety-critical systems. The permanently authorizable target components then include, for example, a signal box and / or a radio block center (RBC) and / or an on-board unit (OBU).

[0026] The safety-critical system according to the invention comprises a maintenance management component, at least one permanently authorizable target component that does not require new authorization for its restart, and an authorization unit logically separated from the maintenance management component. According to the invention, the authorization unit is configured to automate state changes of the permanently authorizable target components before and after a software update. Furthermore, the authorization unit is configured to communicate with the permanently authorizable target components via SMI+ interfaces and to perform a version integrity check of the permanently authorizable target components.

[0027] The maintenance management component alone (i.e., without the authorization unit) is not capable of securely transferring information from external sources into the safety-critical system. While the maintenance management component is a non-safe component (SILO or lower), the authorization unit meets safety level SIL4.

[0028] Unlike conventional SMI interfaces, SMI+ interfaces allow the transmission of commands with integrity assurance that meet the SIL4 level. Specifically, this is an SMI interface that has been enhanced with a version integrity check. In principle, other interfaces can also be used, as long as they are configured to transmit commands with integrity assurance. Communication between the authorization unit and the target components includes, in particular, initiating a version check of the permanently authorizable target components and receiving feedback from the permanently authorizable target components regarding the version control results.

[0029] In a particularly preferred variant of the method according to the invention, the maintenance management component acts as a communication interface between the permanently authorizable target components and the authorization unit, on the one hand, and / or between the external maintenance instance and the authorization unit, on the other. Although the authorization unit and the maintenance management component are logically separated from one another, the authorization unit is largely transparent from the perspective of the permanently authorizable target components with regard to communication on lower protocol layers, so that in this preferred variant, the maintenance management component serves as a communication partner for the target components (via the SMI protocol). The maintenance management component, in turn, forwards safety-critical maintenance requests ('+' portion of the SMI+ interface) from the permanently authorizable target components to the authorization unit.

[0030] In a particularly preferred embodiment of the safety-critical system according to the invention, the authorization unit also forms a secure communication interface to an external maintenance entity. The authorization unit thus serves as a proxy between the external maintenance entity and target components of the safety-critical system. It is configured to verify the information received from the external maintenance entity and thus forms a secure endpoint for the information transmitted by the external maintenance entity.

[0031] Preferably, the authorization unit is configured such that it is inactive during operation of the safety-critical system and can be activated to set up and / or update software of target components of the safety-critical system.

[0032] To ensure that the system configuration is available as the initial system configuration during the next update, it is advantageous for the authorization unit to include long-term memory that stores the overall system state during maintenance-free periods. The authorization unit is preferably a software component based on a hardware platform, both of which have a safety level of SIL4. The hardware platform is independent of the software component, so it could be hardware that is already present in the system and does not need to be purchased separately.

[0033] In addition to the permanently authorizable target components, the safety-critical system according to the invention can also comprise at least one connection-bound authorizable target component that can communicate with one of the permanently authorized target components. Connection-bound authorizable target components receive their authorization upon each restart (depending on the connection setup). The authorization is only valid during the specific connection. The permanently authorizable target components can be configured to communicate with at least one of the connection-bound authorizable target components via an interface (e.g., an SCInat interface). The connection-bound authorizable target components are subordinate to the permanently authorizable target components and receive their authorization from the permanently authorizable target components.To do this, the permanently authorizable target components control the state transitions of the connection-bound authorizable target components.

[0034] Preferably, the safety-critical system according to the invention is configured to carry out the previously described method according to the invention.

[0035] Further advantages of the invention will become apparent from the description and the drawings. Likewise, the above-mentioned and further-described features can be used individually or in combination in any desired manner. The embodiments shown and described are not intended to be exhaustive, but rather are exemplary in nature for describing the invention.

[0036] Detailed description of the invention and drawing

[0037] Fig. 1 shows the schematic structure of a safety-critical system according to the invention and an external maintenance instance. Fig. 2 shows the essential process steps of the method according to the invention.

[0038] Fig. 3 shows the detailed sequence of a particularly preferred variant of the method according to the invention with the communication participants involved.

[0039] Fig. 1 shows a safety-critical system SYS with several physically and logically separated (distributed) permanently authorizable target components TC-A, TC-B, TC-C. The safety-critical system SYS according to the invention can further comprise connection-bound authorizable target components TC-S. The connection-bound authorizable target components TC-S are subordinate to a permanently authorizable target component (here: TC-A). The target components TC-A, TC-B, TC-C, TC-S have access to their component-specific configuration data D. The safety-critical system SYS according to the invention further comprises a maintenance management component MDM and an authorization unit A. The authorization unit A is the core component of the invention. It is only active during maintenance times but has access to a persistent memory MEM to store the overall system state (current system configuration) during maintenance-free periods.The persistent memory MEM can be integrated into the authorization unit A. The authorization unit A is a platform-based software component logically separated from the maintenance management component MDM, which communicates with the permanently authorizable target components TC-A, TC-B, and TC-C.

[0040] However, communication between the permanently authorized target components TC-A, TC-B, TC-C, and the authorization unit A takes place via secure SMI+ interfaces, which enable secure transmission of data and commands. Communication can be mediated by the maintenance management component MDM. The maintenance management component MDM can also communicate directly with the target components TC-A, TC-B, TC-C, and TC-S via standard interfaces (not shown) and can forward additional messages to the authorization unit A for further processing via the secure SMI+ interfaces.

[0041] The permanently authorizable target components TC-A, TC-B, and TC-C receive their authorization from authorization unit A during system maintenance. They retain their authorization until their authorization is revoked or until they relinquish it with a state change to "Maintenance." The connection-bound authorizable target components TC-S, on the other hand, receive their authorization from their parent permanently authorizable target component TC-A when establishing a connection to their parent permanently authorizable target component TC-A. Communication between the permanently authorizable target components TC-A, TC-B, and TC-C and the connection-bound authorizable target components TC_S can take place via standardized SCInat interfaces. The authorization of the connection-bound authorizable target components TC-S expires as soon as the connection to their parent permanently authorizable target component TC-A is disconnected.

[0042] The authorization unit A is preferably also configured to act as a secure interface between an external maintenance entity M and the safety-critical system SYS. This ensures that the external maintenance entity M can communicate securely with the safety-critical system SYS. The external maintenance entity M can be a human maintenance person or a maintenance computer system.

[0043] In order to update the safety-critical system SYS with its distributed, permanently authorizable target components TC-A, TC-B, TC-C while maintaining a high safety level (preferably SIL4), a process is required that defines the required state transitions before the update from the system operation in the starting system configuration to the non-operational state (first state change "operational" "maintenance") and after the update from the non-operational state to operation in the target system configuration (second state change "maintenance"). "operational") under specified conditions. According to the invention, the authorization unit A controls these state transitions of the permanently authorizable target components.

[0044] Fig. 2 shows the essential steps of the method according to the invention, which fulfills the above-mentioned conditions: The update is triggered by an update request from an external maintenance instance (step a). This can be an update of a starting system configuration that is already in operation or an initial setup of a target configuration. In the latter case, a "starting system configuration" is assumed that does not include any permanently authorizable target components (all permanently authorizable target components TC-A, TC-B, TC-C are then in the "inactive" state). Authorization unit A is informed of the target system configuration.

[0045] To initiate the update, the authorization unit changes from the "inactive" state to the "update" state in step b). The maintenance management component informs the target components that can be permanently authorized at the first and second target component combination about the update to be performed (step c).

[0046] In step d), the authorization unit triggers a first state change and a version check of the permanently authorizable target components, whereupon the permanently authorizable target components perform the version check, perform a version update if necessary, and report the result of the version check and / or the version update to the authorization unit (step e)).

[0047] After authorization unit A has successfully performed a system integrity check, authorization unit A triggers a second state change of the permanently authorizable target components in step f). The permanently authorizable target components TC-A, TC-B, and TC-C change to the "operational" or "inactive" state, depending on whether they are involved in the target system configuration or not.

[0048] After completion of the update (including the state change), the authorization unit changes from the "update" state to the "inactive" state (step g)).

[0049] In Fig. 3, the method according to the invention of a particularly preferred variant is shown in detail using the example of a start configuration which comprises the permanently authorizable target components TC-A, TC-B (first target component combination) and a target system configuration which comprises the permanently authorizable target components TC-A, TC-C (second target component combination).

[0050] The external maintenance instance M stores the configuration data of the target system configuration in a data storage REP of the safety-critical system SYS and initially submits the update request (step a) from Fig. 2) to the maintenance management component MDM. The update request is forwarded by the maintenance management component MDM to the authorization unit A. In particular, information regarding the target system configuration is transmitted, in particular information regarding which permanently authorizable target components TC-A, TC-C are required for the target system configuration, which version of which permanently authorizable target components TC-A, TC-C is required, etc.

[0051] To ensure that no errors occurred during the transmission of the update request, the authorization unit A can request confirmation from the external maintenance instance M. The information received from the authorization unit A is then reflected back to the external maintenance instance, requesting confirmation of the accuracy of the information. This ensures that the authorization unit has the correct information.

[0052] The authorization unit A preferably performs the state change from "inactive" to "maintenance" (step b) from Fig. 2) only if it has received a corresponding secure confirmation from the external maintenance instance M.

[0053] The maintenance management component MDM also informs the permanently authorizable target components TC-A, TC-B, and TC-C about the target system configuration (step c) in Fig. 2). The permanently authorizable target components TC-A, TC-B, and TC-C check whether they are involved in the target system configuration and, if they are involved in the target configuration, download the corresponding data (particularly concerning the required software version) from the REP data repository. Preferably, only the permanently authorizable target components TC-A and TC-C involved in the target system configuration download data from the REP data repository. However, the permanently authorizable target component TC-B, which is not involved in the target system configuration, must at least establish that it is not involved in the target system configuration, e.g., by finding no entry for its identification in the REP data repository.Preferably, only the permanently authorizable target components TC-A, TC-B, TC-C (i.e. the system components involved in the start and / or target system configuration) are informed about the target configuration and thus triggered to provide information about their current status. However, it is also conceivable that all system components are informed and the current status of all system components is queried. Authorization unit A carries out an analysis of the target configuration. In doing so, it accesses the data stored in the data storage REP. In this way, authorization unit A can compare whether the target state (start or target system configurations in the data storage) and the actual state (actual message requesting the transition to the maintenance state from the start system configuration (request to enter the maintenance phase) orin the operational state in the target system configuration (request to exit the maintenance phase)) of the permanently authorizable target components TC-A, TC-B, TC-C at runtime).

[0054] Before the permanently authorizable target components TC-A, TC-B, and TC-C start their version check, they request from the authorization unit whether the first state change may be performed (request to enter the maintenance phase). The permanently authorizable target components TC-A, TC-B, and TC-C report their respective current state to authorization unit A. Before the permanently authorizable target components TC-A, TC-B, and TC-C are confirmed to enter the maintenance phase, authorization unit A performs a system integration pre-check, which preferably checks whether all permanently authorizable target components of the starting system configuration TC-A, TC-B have submitted a request to the authorization unit to enter an update phase.

[0055] For the permanently authorizable target components TC-A, TC-B involved in the start system configuration, the first state change means that the "operational" state is to be terminated. Terminating the "operational" state is a safety-critical process. Authorization unit A carries out this process in a regulated manner (potentially configurable via a rule set) by confirming entry into the maintenance phase to the permanently authorizable target components TC-A, TC-B, TC-C. By confirming entry into the maintenance phase, the authorization unit triggers the first state change of the permanently authorizable target components TC-A, TC-B, TC-C to the "maintenance" state (step d) of Fig. 2).

[0056] Preferably, authorization unit A informs the maintenance management component MDM (and thus also the external maintenance instance M) about the progress of the process, in particular about the decision to initiate the state transition of the permanently authorizable target components TC-A, TC-B, TC-C (status message). Since there may be permanently authorizable target components that unexpectedly do not request the state transition, which is a necessary prerequisite for triggering the synchronous state transition according to the rules, authorization unit A must also report their state as part of the status message so that the external maintenance unit can take any manual measures to resolve this irregular state. The individual statuses of the permanently authorizable target components TC-A, TC-B, TC-C can, in principle, also be queried via standardized interfaces (SMI).

[0057] After the first state change, the data previously loaded from the data storage REP is installed (step e) from Fig. 2) and the permanently authorizable target components TC-A, TC-B, TC-C request the exit from the maintenance phase from the authorization unit A.

[0058] The authorization unit then performs a system integrity check (step f) of Fig. 2). It checks whether all permanently authorizable target components TC-A, TC-B, and TC-C involved in the start and target configuration are in the "maintenance" or "inactive" state and whether the version specified by the target system configuration is installed.

[0059] If the system integrity check shows that all requirements are met, authorization unit A triggers a second state change of the permanently authorizable target components TC-A, TC-B, and TC-C by confirming exit from the maintenance phase. The permanently authorizable target components TC-A and TC-C involved in the target system configuration change to the "operational" state, and the permanently authorizable target component TC-B, which is not involved in the target system configuration, changes to the "inactive" state.

[0060] After confirming the exit from the maintenance phase to all permanently authorizable target components TC-A, TC-B, TC-C, the authorization unit A informs the maintenance management component MDM about the current states of the permanently authorizable target components TC-A, TC-B, TC-C and changes to the "inactive" state (step g) in Fig. 2). The maintenance management component MDM receives an aggregated status report from the authorization unit A containing status information about all permanently authorizable target components, which it can then forward to the external maintenance instance M as part of an update confirmation.

[0061] The status report includes the summarized status information of all permanently authorizable target components TC-A, TC-B, and TC-C. The statuses of the permanently authorizable target components TC-A, TC-B, and TC-C therefore no longer need to be queried individually. To ensure that the target components TC-B that are no longer participating in the target system configuration have actually ceased their active operation and are in the "inactive" state, the status report preferably also includes status information of the target components TC-B that are no longer participating in the target system configuration.

[0062] In addition, the target system configuration is permanently stored as the new current system configuration for the next update in the persistent memory MEM of the authorization unit A.

[0063] Based on the status report, the external maintenance authority can decide whether the safety-critical system should be put back into operation (if the states of all permanently authorizable target components TC-A, TC-B, TC-C correspond to the target configuration or deviations from it are assessed as non-critical) or whether the safety-critical system should remain out of operation if, for example, critical deviations are detected.

[0064] The method according to the invention can be integrated into the existing solution for checking connection-bound authorizable target components (as known, for example, from [EULYNX]).

[0065] The authorization unit forms a secure external interface and centrally coordinates the state transitions of the permanently authorizable target components. It assumes overall control for updating the permanently authorizable target components, triggers their state transitions, version checks, and updates, collects information regarding the state and version of the permanently authorizable target components, and creates an aggregated status report. The authorization unit checks whether all permanently authorizable target components are in the target state, thus ensuring the functional safety of the safety-critical system. The inventive use of the authorization unit thus enables a controlled update of a safety-critical system at a high level of security.With the inventive integration of the authorization unit, a structure is provided that controls the regular, secure state transition between operation and non-operation of the safety-critical system before and after the installation of the update.

[0066] List of reference symbols

[0067] D component-specific configuration data

[0068] A authorization unit

[0069] M external maintenance instance

[0070] MDM maintenance management component

[0071] MEM persistent storage

[0072] REP data storage for system configuration

[0073] TC-A permanently authorizable target component (included in start and target system configuration)

[0074] TC-B permanently authorizable target component (included in start but not in

[0075] Target system configuration)

[0076] TC-C permanently authorizable target component (included in target but not in launch system configuration)

[0077] TC-S connection-bound authorizable target component

[0078] SCInat standardized interface

[0079] SMI+ interface

[0080] SYS safety-critical system

[0081] Literature list

[0082] [EULYNX] EULYNX Baseline Set 3 Release 6 https: / / eulynx.eu / index.php / documents / published-documents / open- availability / baseline-set- 3 / 261-20201002-eulynx-baseline-set-3- cover-document-6a / file

Claims

Patent claims Method for setting up and / or updating software of target components of a safety-critical system (SYS) from a start system configuration to a target system configuration, wherein the safety-critical system (SYS) comprises a maintenance management component (MDM), a central authorization unit (A) and at least one permanently authorizable target component (TC-A, TC-B, TC-C), wherein the start system configuration comprises a first combination of target components (TC-A, TC-B) and the target system configuration comprises a second combination of target components (TC-A, TC-C), with the following method steps: a) an external maintenance instance (M) requests an update of the system configuration; b) the authorization unit (A) changes from the "inactive" state to the "update" state; c) the permanently authorizable target components (TC-A, TC-B, TC-C) are informed of the update to be carried out;d) the authorization unit (A) performs a system integrity pre-check and triggers a first state change and a version check of the permanently authorizable target components (TC-A, TC-B, TC-C); e) the permanently authorizable target components (TC-A, TC-B, TC-C) perform a version check and, if necessary, a version update and report the result to the authorization unit (A); f) the authorization unit (A) performs a system integrity check and triggers a second state change of the permanently authorizable target components (TC-A, TC-B, TC-C) if the system integrity check was successful; g) the authorization unit (A) changes from the "updating" state to the "inactive" state. Method according to claim 1, characterized in that, before requesting the update in step a), the external maintenance instance (M) stores information on the target system configuration in a data storage (REP), and that the target components (TC-A, TC-B, TC-C) load the data required for the update from the data storage (REP). Method according to one of the preceding claims, characterized in that, before changing to the "update" state (step b)), the authorization unit (A) requests a secure confirmation of the update request from the external maintenance instance (M), and that the change of the state of the authorization unit (A) to the "update" state only occurs if the secure confirmation has been received from the external maintenance instance (M).Method according to one of the preceding claims, characterized in that the authorization unit (A) analyses the target system configuration, preferably the start and target configuration. Method according to one of the preceding claims, characterized in that the permanently authorizable target components (TC-A, TC-B, TC-C), after being informed in step c) about the update to be carried out, submit a request to the authorization unit (A) to enter an update phase, and in that the version check and the first state change of the permanently authorizable target components (TC-A, TC-B, TC-C) in step d) after the system integrity preliminary check by transmitting a confirmation of entry into the update phase from the authorization unit (A) to the permanently-. authorizable target components (TC-A, TC-B, TC-C) are triggered, whereby the permanently authorizable target components (TC-A, TC-B, TC-C) change from their current state to the "Maintenance" state.

6. Method according to one of the preceding claims, characterized in that the authorization unit (A) checks during the system integrity pre-check whether all permanently authorizable target components (TC-A, TC-B) of the starting system configuration have submitted a request to the authorization unit (A) to enter an update phase.

7. The method according to claim 5 or 6, characterized in that the authorization unit (A), after receiving the requests to enter an update phase, informs the maintenance management component (MDM) about the current status of the permanently authorizable target components (TC-A, TC-B, TC-C).

8. Method according to one of the preceding claims, characterized in that when updating the permanently authorizable target components (TC-A, TC-B, TC-C) in step e): those permanently authorizable target components (TC-A, TC-C) which are part of the target system configuration install the data required for the update and request the termination of the update phase from the authorization unit (A), and those permanently authorizable target components (TC-B) which are not part of the target system configuration assure the authorization unit (A) that they are out of service and request the termination of the update phase from the authorization unit (A).

9. Method according to one of the preceding claims, characterized in that the authorization unit (A) checks during the system integrity check in step f) whether all permanently authorizable target components (TC-A, TC-B, TC-C) of the start and target system configuration are in the state "Maintenance" or in the "inactive" state before they permanently authorize the permanently authorizable target components (TC-A, TC-C) involved in the target system configuration for operation of the new target system configuration. Experience according to one of the preceding claims, characterized in that the triggering of the second state change of the permanently authorizable target components (TC-A, TC-B, TC-C) in step f) occurs after the system integrity check by a confirmation for the termination of the update phase by the authorization unit (A), and that within the scope of the second state change, the permanently authorizable target components (TC-A, TC-C) included in the target system configuration change from the "maintenance" state to the "operational" state, and the target components (TC-B) not included in the target system configuration change from the "maintenance" state to the "inactive" state.Experience according to one of the preceding claims, characterized in that the authorization unit (A), preferably after its change to the "inactive" state in step g), informs the maintenance management component (MDM) about the current state of the permanently authorizable target components (TC-A, TC-B, TC-C). Method according to claim 11, characterized in that the authorization unit (A) creates a status report on the states of all permanently authorizable target components (TC-A, TC-B, TC-C) and that the status report is transmitted to the external maintenance instance (M). Method according to one of the preceding claims, characterized in that the target system configuration remains stored in a long-term memory (MEM) of the authorization unit (A) during maintenance-free times.

14. Experience according to one of the preceding claims, characterized in that the safety-critical system (SYS) is a railway signaling system.

15. A safety-critical system (SYS), comprising: a maintenance management component (MDM), at least one permanently authorizable target component (TC-A, TC-B, TC-C) which does not require a new authorization for its restart, characterized in that the safety-critical system (SYS) comprises an authorization unit (A) which is logically separate from the maintenance management component (MDM), wherein the authorization unit (A) is configured to automate state changes of the permanently authorizable target components (TC-A, TC-B, TC-C) before and after a software update and wherein the authorization unit (A) is configured to communicate with the permanently authorizable target components (TC-A, TC-B, TC-C) via interfaces (SMI+) and to carry out a version integrity check of the permanently authorizable target components (TC-A, TC-B, TC-C).

16. Safety-critical system according to claim 15, characterized in that the authorization unit (A) forms a secure communication interface to an external maintenance instance (M).

17. Safety-critical system according to claim 15 or 16, characterized in that the authorization unit (A) is configured such that it is inactive during operation of the safety-critical system (SYS) and can be activated to set up and / or update software of target components (TC-A, TC-B, TC-C) of the safety-critical system (SYS). Safety-critical system according to one of claims 15 to 17, characterized in that the authorization unit (A) comprises a long-term memory (MEM) that stores the overall state of the system during maintenance-free periods. Safety-critical system according to one of claims 15 to 18, characterized in that the authorization unit (A) is a software component based on a hardware platform, both having the safety level SIL4. Safety-critical system according to one of claims 15 to 19, characterized in that the safety-critical system (SYS) comprises at least one connection-bound, authorizable target component (TC-S) that communicates with one of the permanently authorized target components (TC-A). Safety-critical system according to one of claims 15 to 20, characterized in that the safety-critical system (SYS) is configured to execute the method according to one of claims 1 to 13.