Secure backup method
Patent Information
- Application Number
- EP2024718047
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-04-28
- Filing Date
- 2024-03-27
- Publication Date
- 2026-01-21
AI Technical Summary
Industrial machine downtimes are prolonged due to the difficulty in replacing defective machine control components with software and configuration data that is cryptographically tied to specific hardware, leading to compromised security and potential arbitrary cloning of components.
A method where digital information assigned to a first hardware component is cryptographically bound to a second hardware component, allowing secure reassignment to a new first hardware component while maintaining security and preventing cloning, by using cryptographic binding and secure key management.
Minimizes downtime and enhances security by ensuring that backup images can only be restored to the original system, preventing unauthorized cloning and maintaining tamper-proof integrity of digital information.
Smart Images

Figure EP2024058327_31102024_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Secure backup procedure
[0003] The invention relates to a method for replacing a first hardware component of a technical system. Furthermore, the invention relates to a technical system having at least one first hardware component and at least one second hardware component. Furthermore, the invention relates to a control system for a technical system, in particular a manufacturing or processing system.
[0004] Since downtimes of industrial machines (e.g., machine tools, automation systems) are generally very expensive and therefore must be kept as short as possible, the replacement of a defective component in a machine control system should be as quick and uncomplicated as possible. To achieve this, it is particularly important to ensure that the software and configuration are at the same level as before the component was replaced. To achieve this, backup images of the individual software components (program binaries, configuration data, etc.) are created and restored when a replacement part is needed.
[0005] Such a recovery becomes more difficult, however, if the software running on the components or the data stored by the components are cryptographically bound to the specific hardware. The created backup images can then only be restored on the respective components on which they were originally created. As a consequence, increased security for backup images is currently being dispensed with, i.e., the binding in the backup is removed, which, for example, allows for arbitrary cloning of components.
[0006] RAID systems are well known and are primarily used for redundant data storage in order to ensure a different level of fail-safe protection depending on the specific configuration (https: / / de.wikipedia.org / wiki / RAID).
[0007] Trusted Platform Modules (TPMs) are known for their ability to copy keys from one hierarchy to another. The second hierarchy can be either on the same TPM or on a different TPM. This process is called "duplication" in TPM 2.0, and "migration" in TPM 1.2. The primary uses are for creating backups and deploying a key on multiple devices.
[0008] AMD SEV memory encryption technology (RAM) is known to allow snapshots of virtual machines running on a host to be created or virtual machines to be migrated live between hosts. However, to maintain memory encryption, the target hardware must be known in advance in both cases (see 1.3.3 Snapshot and Migrate: https: / / www.amd.com / system / files / TechDocs / 55766_SEV-KM_API_Specification.pdf).
[0009] US 2016 / 0162418 A1 discloses a recovery method for encryption keys for hard disks.
[0010] It is therefore an object of the present invention to be able to create backup images of components of a technical system such as an industrial machine in such a way that they are cryptographically linked to the technical system and can only be restored there in the event of a spare part being needed, but the components of the technical system, for example those of the machine control system, can nevertheless be replaced.
[0011] This object is achieved by a method for exchanging a first hardware component of a technical system, wherein digital information is assigned to the first hardware component, with the features of claim 1 . In addition, the object is achieved by a technical system with at least one first hardware component and at least one second hardware component with the features of claim 11 . Furthermore, the object is achieved by a control system for a technical system, in particular a production or process plant, according to claim 12 . Advantageous further developments arise from the dependent claims .
[0012] The method according to the invention for replacing a first hardware component of a technical system, wherein digital information is assigned to the first hardware component, comprises the following method steps: a) cryptographically binding the digital information to a second hardware component of the technical system, b) replacing the first hardware component with a new first hardware component, c) re-assigning the digital information to the first hardware component using the cryptographic binding of the digital information to the second hardware component.
[0013] The technical system can be a technical plant from the process industry, such as a chemical, pharmaceutical, petrochemical plant or a plant from the food and beverages industry. This also includes any technical plant from the production industry, plants in which, for example, cars or goods of all kinds are produced. Technical plants that are suitable for carrying out the method according to the invention can also come from the field of energy generation. Wind turbines, solar systems, power plants for energy generation or other machines are also covered by the term technical system. It is assumed that the technical system comprises at least two hardware components. Digital information is assigned to the first hardware component.In its broadest sense, digital information is information that is coded in a binary format and stored in a data memory. The digital information can preferably be a configuration of the first hardware component or a sequential program to be processed by the first hardware component. The information is assigned to the first hardware unit. This means that it relates to the first hardware unit itself or to the operation of the first hardware unit in the technical system.
[0014] The first hardware component is to be replaced within the scope of the method according to the invention because it is defective, for example. The digital information that was assigned to the old first hardware unit is then to be assigned to the new first hardware component. For this purpose, the digital information was previously cryptographically bound to a second hardware component of the technical system. This ensures that the digital information is tamper-proof because the cryptographic binding between the digital information and the second hardware unit is not affected by the replacement of the first hardware unit. This cryptographic binding can now be used when re-assigning the digital information to the (new) first hardware unit.The downtime of the technical system is kept to a minimum and the cryptographic binding to the second hardware unit makes it difficult to clone the first hardware component at will.
[0015] It is self-evident that the second hardware component can have a cryptographic binding to the first hardware component (or to one or more further hardware components) in an analogous manner, which can prove to be comparably advantageous when replacing the second hardware component.
[0016] The digital information is generated by a backup process from digital information of identical content assigned to the first hardware component. In this context, this is also referred to as a backup of the digital information of identical content assigned to the first hardware component. The process is therefore as follows:
[0017] Creating a backup of digital information assigned to the first hardware component Cryptographically binding the digital information previously generated by the backup method (backup) to a second hardware component of the technical system Replacing the first hardware component with a new first hardware component
[0018] Re-assigning the digital information (backup) previously generated by the security method to the first hardware component using the cryptographic binding of the digital information (backup) to the second hardware component.
[0019] The digital information or the backup of the digital information generated by the backup process can be stored in a memory of the second hardware component. However, it is also possible to store the digital information or the backup of the digital information generated by the backup process in another memory within the technical system or outside the technical system in a cloud-based environment.
[0020] Within the scope of a preferred development of the invention, the digital information (or the backup of the digital information) is cryptographically bound to the second hardware component by encrypting (preferably with additional integrity protection) the digital information itself or a memory in which the digital information is stored. Alternatively, the digital information can be cryptographically bound to the second hardware component using a digital signature or a MAC (Message Authentication Code).
[0021] Preferably, the memory in which the digital information with the same content is stored is implemented on the first hardware component, and the memory in which the digital information generated by the security method (i.e. the backup) is stored is implemented on the second hardware component, wherein the cryptographic binding of the digital information generated by the security method to the second hardware component is carried out by keys specific to the respective hardware component.
[0022] The communication channel used to exchange information between the first hardware component and the second hardware component is preferably also protected by a cryptographic method (not necessarily of the same type) in order to be able to counteract attempted attacks.
[0023] Advantageously, the cryptographic binding of the digital information generated by the security method to the second hardware component is carried out by keys specific to the respective hardware component, wherein the key specific to the second hardware unit is used to bind the digital information generated by the security method (i.e. to the backup) of the first hardware unit to the second hardware unit.
[0024] Additionally, the digital information (or the backup) can be cryptographically bound to a third hardware component of the technical system, with the digital information being reassigned to the first hardware component after the first hardware component has been replaced using the cryptographic binding of the digital information to the second hardware component and to the third hardware component. By binding to two additional hardware components, security can be further increased without having to significantly increase the effort required.
[0025] Generally speaking, the digital information can be cryptographically bound to m further hardware components of the technical system, where m is a natural number greater than one, and the digital information can be re-assigned to the first hardware component after the first hardware component has been replaced using the cryptographic binding of the digital information to a subset of the m further hardware components that can be defined for a technical system. The digital information (or the backup) can each be completely bound to the second hardware components, which further increases security. For resource reasons, it is also advantageous if only a specific part of the digital information or its backups is bound to the further hardware component.A specific portion of the digital information can be assigned to each additional hardware component. Known methods can be used to reassign the distributed information to the replaced first hardware component. In particular, not all m additional hardware components need to be used. Only a portion of the m additional hardware components may be sufficient to realize the reassignment of the digital information or the backup.
[0026] The previously formulated object is also achieved by a technical system having at least one first hardware component and at least one second hardware component, wherein digital information is assigned to the first hardware component, and wherein digital information generated by a security method and having substantially the same content as the digital information has a cryptographic link to the second hardware component of the technical system, such that when the first hardware component is replaced by a new first hardware component, the digital information is re-assigned to the first hardware component using the cryptographic link of the digital information to the second hardware component.
[0027] The technical system preferably has a security authority, in particular a certification authority and / or a registration authority within the framework of a public-private key infrastructure.
[0028] The object is also achieved by a control system for a technical system, in particular a manufacturing or process system or an engine as a technical system, which control system comprises at least one operator station server as a first hardware component and at least one automation device as a second hardware component, wherein the technical system is designed as explained above.
[0029] In this context, a control system is understood to be a computer-aided, technical system that includes functionalities for displaying, operating, and managing the technical plant. The control system can also include sensors for determining measured values as well as various actuators. In addition, the control system can include so-called process- or production-related components that are used to control the actuators or sensors. In addition, the control system can, among other things, have means for visualizing the process plant and for engineering. The control system can optionally also include additional computing units for more complex controls and systems for data storage and processing.
[0030] The control system can additionally have at least one operator station client which can be used by the operator for operating and monitoring the technical system, wherein the operator station server is designed to generate the corresponding visualization information and to transmit it to the operator station client.
[0031] An "operator station server" is understood here to be a server that centrally records data from an operating and monitoring system and usually alarm and measured value archives from a (process) control system of a technical plant and makes them available to users. The operator station server usually establishes a communication connection to the automation systems of the technical plant and forwards data from the technical plant to so-called clients, which are used to operate and monitor the operation of the individual functional elements of the technical plant. The operator station server can have client functions in order to access the data (archives, messages, tags, variables) of other operator station servers. This means that images of the operation of the technical plant on the operator station server can be combined with variables from other operator station servers (server-server communication).The operator station server can be, but is not limited to, a S IMATIC PCS 7 Industrial Workstation Server from S IEMENS.
[0032] The above-described properties, features, and advantages of this invention, as well as the manner in which they are achieved, will become clearer and more readily understood in connection with the following description of exemplary embodiments, which are explained in more detail in connection with the drawings. FIG. 1 shows a first and a second hardware component according to a first aspect in a schematic representation;
[0033] FIG 2 shows the first and second hardware components according to a second aspect in a schematic representation; and
[0034] FIG 3 shows the first hardware component and a plurality of further hardware components in a schematic representation.
[0035] FIG 1 schematically shows an operator station server 1 as a first hardware component and an automation device 2 as a second hardware component of a control system 3 as a technical system for a technical plant. The control system 3 comprises, in addition to the operator station server 1 and the automation device 2, an operator station client 4, by means of which an operator can access the control system for the purpose of operating and monitoring the technical plant. The operator station server 1 and the operator station client 4 are connected to one another via a terminal bus 5 and optionally to other components of the control system 3 (not shown), such as an archive server.
[0036] Configuration data 6 which is relevant for operation of the operator station server 1 in the control system 3 is stored on the operator station server 1 as digital information. In a first step 1, the configuration data 6 of the operator station server 1 is duplicated using a known backup method and transmitted to a memory 7 of the automation device 2 and stored there as a digital backup 7a. The backup 7a of the configuration data 6 of the operator station server 1 is cryptographically linked to the automation device 2. This is done by encrypting the data memory 7 using a hardware trust anchor 8 of the automation device 2.
[0037] Analogously, in a second step II, digital information 9 of the automation device 2 is duplicated using a known backup method and transmitted to a memory 10 of the operator station server 1, where it is stored as a digital backup 10a. The backup 10a of the digital information 9 of the automation device 2 is cryptographically linked to the operator station server 1. This is achieved by encrypting the data memory 10 using a hardware trust anchor 11 of the operator station server 1.
[0038] The transmission channel K between the operator station server 1 and the automation device 2 is cryptographically secured to prevent tampering. A TLS-based communication method, for example, can be used for this purpose.
[0039] Due to a failure of the operator station server 1, this is subsequently replaced. The process steps explained below are shown schematically in FIG 2. The new operator station server 12 only has its factory settings and does not have the configuration data 6 relevant for its operation in the control system. Therefore, the backup 7a is transferred from the memory 7 of the automation device 2 to the new operator station server 12 and assigned to the operator station server 12. The backup 7a is decrypted using the hardware trust anchor 8 of the automation device 2. In this case, the backup 10a of the automation device 2 was in the memory 10 of the old operator station server 1 and must be created again. However, it is also possible that the backups 7a, 10a are stored, for example, in a cloud-based environment.
[0040] In one variant, to calculate the signature, not the complete backup image 7a of the configuration data 6 is transmitted to the automation device 2 as the second hardware component, but only a hash value of it. The calculated signature is transferred to the memory in which the backup image 7a is stored (which does not necessarily have to be the memory 7 of the automation device 2).
[0041] FIG 3 shows the division of the configuration data 6 into three sub-packets 6a, 6b, 6c. The first sub-packet 6a is stored as a backup 16a in a memory 16 of a third hardware component 13. The second sub-packet 6b is stored as a backup 17a in a memory 17 of a fourth hardware component 14, and the third sub-packet 6c is stored as a backup 18a in a memory 18 of a fifth hardware component 15. This can be achieved, as is known from RAID systems (e.g., RAID 5), with a defined pattern and additional checksums. This has the advantage that, depending on the configuration, a certain number of the additional hardware components present
[0042] 13 , 14 , 15 is required to restore the configuration file 6 from the backup parts 16a, 16b, 16c for a replaced Operator Station Server 1 .
[0043] The configuration data 6 can be divided either by the operator station server 1 itself and distributed among the other hardware components 13, 14, 15, or by a central backup component (not shown). The final backup image can be stored in the form of individual parts 16a, 16b, 16c on the respective hardware components 13,
[0044] 14, 15 (as shown in FIG. 3). However, it is also possible to create a Manifest that describes the distribution among the individual components. The combined image can, in turn, be stored locally outside the machine, in a backend system, or in the cloud.
[0045] Although the invention has been illustrated and described in detail by the preferred embodiment, the invention is not limited by the disclosed examples and other variations can be derived therefrom by those skilled in the art without departing from the scope of the invention, which is defined by the claims in conjunction with the description.
Claims
Patent claims 1. Method for replacing a first hardware component (1, 12) of a technical system, wherein digital information (6, 7a) is assigned to the first hardware component (1), the method comprising: a) generating digital information with the same content from the digital information (6, 7a) assigned to the first hardware component (1) using a security method; b) cryptographically binding the digital information (6, 7a) generated in step a) to a second hardware component (2) of the technical system, c) replacing the first hardware component (1) with a new first hardware component (12), d) assigning the digital information (6, 7a) generated in step a) to the new first hardware component (12) using the cryptographic binding of the digital information (6, 7a) generated in step a) to the second hardware component (2).
2. Method according to claim 1, wherein the digital information (6, 7a) comprises a configuration of the first hardware component (1, 12) or a sequence program to be processed by the first hardware component (1, 12).
3. Method according to one of the preceding claims, in which the digital information (6, 7a) is stored in a memory (7) of the second hardware component (2).
4. Method according to one of claims 1 to 2, wherein the digital information (6, 7a) is stored outside the second hardware component (2) in the technical system, most preferably in a cloud-based environment outside the technical system.
5. Method according to one of the preceding claims, in which the cryptographic binding of the digital information (6, 7a) to the second hardware component (2) is carried out by encrypting a memory (7) in which the digital information (6, 7a) is stored.
6. Method according to 5, in which the memory (10) in which the digital information (6, 7a) with the same content is stored is implemented on the first hardware component (1, 12), and the memory (7) in which the digital information (6, 7a) generated by the security method is stored is implemented on the second hardware component (2), wherein the cryptographic binding of the digital information (6, 7a) generated by the security method to the second hardware component (2) is carried out by keys (8, 11) specific to the respective hardware component (1, 12).
7. Method according to one of the preceding claims, in which a communication channel (K) between the first hardware component (1, 12) and the second hardware component (2) is protected by a cryptographic method.
8. Method according to one of the preceding claims, in which the cryptographic binding of the digital information (6, 7a) generated by the security method to the second hardware component (2) is carried out by keys (8, 11) specific for the respective hardware component (1, 12), wherein the key (8) specific for the second hardware component (2) is bound to the digital information (6, 7a) generated by the security method.
9. Method according to one of the preceding claims, in which a cryptographic binding of the digital information (6, 7a) to a third hardware component (13) of the technical system is additionally carried out, and wherein the renewed assignment The digital information (6, 7a) is transferred to the first hardware component (1, 12) after replacing the first hardware component (1, 12) using the cryptographic binding of the digital information (6, 7a) to the second hardware component (2) and to the third hardware component (13).
10. The method according to one of claims 1 to 8, wherein additionally a cryptographic binding of the digital information to m further hardware components (13, 14, 15) of the technical system takes place, where m represents a natural number greater than one, and wherein the re-assignment of the digital information (6, 7a) to the first hardware component (1, 12) after the replacement of the first hardware component (1, 12) takes place using the cryptographic binding of the digital information (6, 7a) to a part of the m further hardware components (13, 14, 15).
11. Technical system with at least one first hardware component (1, 12) and at least one second hardware component (2), wherein digital information (6, 7a) is assigned to the first hardware component (1), and wherein digital information (6, 9, 7a, 10a) generated by a security method and having substantially the same content as the digital information (6, 7a) has a cryptographic link to the second hardware component (2) of the technical system, such that when the first hardware component (1) is replaced by a new first hardware component (12), the digital information (6, 7a) is re-assigned to the new first hardware component (12) using the cryptographic link of the digital information (6, 7a) to the second hardware component (2).
12. Control system (3) for a technical plant, in particular a manufacturing or processing plant, which control system (3) we- at least one operator station server as the first hardware component (1, 12) and at least one automation device as the second hardware component (2), wherein the control system is designed as a technical system according to claim 11.