Attestation
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2024-07-16
- Publication Date
- 2026-04-22
AI Technical Summary
Many devices in technical systems lack the necessary functionalities for attestation, which is crucial for enhancing cybersecurity and ensuring device integrity, especially in the absence of a protected execution environment or trusted components.
A method where a device management unit implements a 'Root of Trust for Measurement' and 'Root of Trust for Reporting' to create attestation information, using an attestation unit that is part of or connected to the device management unit, allowing for secure configuration management and attestation without requiring these trusted components within the device itself.
This approach simplifies attestation and enhances cybersecurity by providing reliable, tamper-proof confirmation of device configuration, even for devices without protected execution environments, thereby improving the overall security and reliability of the system.
Smart Images

Figure EP2024070161_23012025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Attestation
[0003] The invention relates to a method and a device for providing attestation information.
[0004] In a technical system, such as a production plant, a railway signal box or a smart home system, several individual devices are connected to one another via data technology in order to jointly carry out a task, such as the manufacture of a product, securing a section of railway or monitoring a room in a private house.
[0005] Figure 1 shows an example of a technical system with a large number of devices ANE, PLI, PL2, S1, ..., S4 (see respective boxes). These devices are connected to one another via data technology to exchange information such as instructions or measured values (see connections between the boxes). The devices S1, ..., S4 are measuring sensors which record temperature, speed or nitrogen oxide concentration and pass the data on to the programmable control units PLI, PL2 connected to them. The programmable control units are in turn connected via data technology to a higher-level control unit ANE which controls several programmable control units, for example in a production system.Furthermore, further units can be connected to the control unit and the programmable control units, such as a device management unit DMU, which provides a configuration of a respective device, such as an operating system, security settings or parameterizations.
[0006] On the one hand, digitalization using such a technical system offers the opportunity to solve a wide variety of tasks. On the other hand, cyber attacks, for example caused by viruses or malware, can disrupt the functionality of individual devices or the entire system and thus cause immense economic damage. Several methods are known that can improve the security of devices and / or an entire technical system. IT and ICT-based systems (IT: Information Technology, ICT: Information and Communication Technology) are increasingly using attestation to provide tamper-proof confirmation of a cryptographically protected confirmation, for example of a device integrity state, loaded software or a technical implementation of key storage.Well-known procedures include, for example, the Play Integrity Attestation procedure of the Android operating system, which allows an app to prove that it was installed via the Google Play Store and matches the version provided in the Play Store. Other well-known procedures are Microsoft Azure Attestation and the TCG DICE Attestation for small IoT devices (TCG: Trusted Computing Group; DICE: Device Identifier Composition Engine).
[0007] However, devices that want to issue such an attestation require, on the one hand, a "Root of Trust for Reporting" (RTR), a security element with an attestation key to create the actual attestation, and, on the other hand, a measuring unit as the "Root of Trust for Measurement" (RTM), which reliably determines the information to be attested. On some devices, e.g. on PCs, this can be done using a Trusted Platform Module TPM as the "Root of Trust for Reporting" and an associated "Root of Trust for Measurement" module. Many devices in existing technical systems do not have any functionality with which the attestation can be carried out.
[0008] A published patent application US 2016 / 013948 Al presents methods, devices and systems for registering devices in a network.
[0009] In a paper by Niemi et al., “Platform Attestation in Consumer Devices" , 2023 33RD CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT ) , FRUCT; 24 May 2023 (2023-05-24) ; pp. 198-209 ; XP034356509 ; DOI: 10.23919 / FRUCT58615.2023.10142995, an overview of the state of the art for platform attestation in the industry is presented.
[0010] There is therefore a need to provide methods and devices that simplify or improve the attestation for a device and thus contribute to increasing cybersecurity when the device is used, for example, in the technical system.
[0011] This problem is solved by the independent patent claims. Further developments of the invention can be found in the dependent claims.
[0012] The invention relates to a method for providing attestation information relating to configuration information of a device, wherein a current configuration of the device is managed by a device management unit using the configuration information, wherein the attestation information is created on the basis of the configuration information by an attestation unit which is assigned to the device management unit.
[0013] The creation of attestation information by the attestation unit assigned to the device management unit is advantageous because, regardless of whether the attestation information can be created by the device or not, cybersecurity can be increased when accessing the device, such as controlling the device or exchanging data. This also demonstrates the advantage that the use of the device management unit together with the attestation unit simplifies the creation and provision of attestation information.
[0014] A further advantage is that the procedure does not have any undesirable impact on the functionality of the device because the attestation information is created by the attestation unit assigned to the device management unit.
[0015] In this invention, the device management unit implements a "Root of Trust for Measurement" to determine configuration information of the device, as well as a "Root of Trust for Reporting" to confirm the determined configuration information in a cryptographically protected manner, i.e., to form the attestation information. This means that the device itself does not have to include these trusted components, but rather the attestation unit, which is part of the device management unit or is connected to it. This has the advantage that a device attestation can also be formed in a trustworthy manner for devices that do not themselves require a protected execution environment (TEE) for the trustworthy, tamper-proof determination of the information to be attested and for forming the attestation.The configuration information to be attested can be provided by the device management unit, for example via a device measurement protocol such as OMA DM (OMA: Open Mobile Alliance; DM: Device Management), SNMP (SNMP: Simple Network Management Protocol), OPC UA (OPC: Open Platform Communications, UA: Unified Architecture) NETCONF (NETCONF: Network Configuration Protocol) or RESTCONF (RESTCONF: Representational State Transfer Configuration Protocol).
[0016] The device is designed, for example, as an Industrial IoT device (IoT: Internet of Things) in the form of a control unit, a Remote IoT device (I: Input; O: Output), PLC (PLC: Programmable Logic Controller), or as an Industrial TSN Network Switch (TSN: Time-Sensitive Networking).
[0017] Attestation information is understood to be information determined from the device's configuration information and, if applicable, other information, which is cryptographically protected with the help of a security element that uses an attestation key to generate a cryptographic checksum, in particular a digital signature. The security element is designed, for example, as a TPM (TPM: Trusted Platform Module), as a crypto controller, as an ARM TrustZone or as an SGX enclave (SGX: Software Guard Extensions). The attestation information can be in the form of a digital certificate (authentication certificate, attribute certificate), as a verifiable credential, as a signed JSON Web Token or as signed XML data.
[0018] In the context of this description, the term “assigned” means that the attestation unit is part of the device management unit or that the attestation unit is an independent unit that is connected to the device management unit in terms of data technology or communication, with which the device management unit can exchange information in order to initiate the creation of the attestation information and to receive this information from the attestation unit.
[0019] The current configuration of the device includes, among other things, the configuration parameters preset by the configuration information.
[0020] In this description, the device management unit is understood to be a unit that manages the device's configuration information. The device is configured by the device management unit based on the configuration information. Since the configuration information can change over time, for example due to different products being manufactured or due to changed security requirements, the device management unit can configure the device multiple times over time. In addition, the device management unit can also change the configuration information independently. Such device management units are known, for example, under the names Enterprise Mobile Device Manager, Unified Endpoint Management and Common Device Management for industrial devices.According to a development of the method, the attestation information comprises at least one of the following information: the configuration of the device is managed by the device management unit; an actual state of the configuration of the device; a target state of the configuration of the device; a validity period of the configuration information; a type of authentication of the device to the device management unit and / or of the device management unit to the device; unique identification information of the device, in particular its serial number or its MAC address; local configuration settings of the device;.
[0021] Permanently integrated or detachably connected hardware components of the device; an indication of a production order and / or a production step for which the attestation information (ATI) is valid; an indication of a result of a security self-test.
[0022] The advantage here is that one or more of the latter information can help to increase security when accessing the device, such as controlling the device or exchanging data.
[0023] The information that the device configuration is managed by the device management unit is particularly advantageous. This allows a communication partner, such as the communication device, to conclude that the device is maintained more reliably than if no device management unit is used. This information therefore indicates increased security in the interaction between a communication device and the device. In addition, the communication device can also make explicit requests to the device management unit via the device in order to specifically query additional information that is not available, for example, in the attestation information. The attestation information advantageously includes an actual state of the device configuration.The device can transmit its current configuration to the device management unit at pre-determined times, which makes this available when the attestation information is created. In addition, the attestation information can also contain a target state of the device’s configuration, which corresponds, for example, to the configuration information managed in the device management unit. The actual state or the target state enables the communication device to detect deviations in the configuration and from this to determine whether the device can be used, for example, for future use in the production of a product. In addition, detected deviations can be used to prompt the device management unit to update the configuration information and transmit this to the device.For example, the target configuration specifies a target filter policy of a network communication filter (packet filter, firewall) of the device. If the actual state shows that no filter policy or a different filter policy is set up on the device, the communication device or the device management unit can instruct the device to update the filter policy, or the communication device can block or restrict data transmission with the device. Furthermore, a target state of the configuration can specify which deviations a drill or milling head is permitted to have so that the product can be produced without errors. If the actual state shows that the deviation of the drill, e.g. due to wear, is greater than the target state, the communication device or the device management unit can instruct the device to replace the drill automatically. This information can therefore also be used to ensure the security of the device.of the system can be increased because a potential error in the manufacture of a product can be detected early and actively rectified. The information on the validity period of the configuration information has the advantage that an outdated configuration of the device can be detected based on the validity period. This means that the communication device can stop controlling the device and / or exchanging data with the device if the current configuration is detected as outdated. This is advantageous, for example, if the outdated configuration does not include security-relevant updates to the device, such as regular password updates. This information can be implemented, for example, using a validity time window or a counter value (epoch counter). This information therefore contributes to increasing the cybersecurity of the device or the system.
[0024] The information about a type of authentication of the device to the device management unit and / or the device management unit to the device has the advantage that with weak authentication, the risk of manipulation of configuration information with which the device is to be configured can be higher than with strong authentication. Thus, the communication device that, for example, wants the device to run a security-critical application can prevent the application from running if weak authentication is detected. This increases the cybersecurity of the device or of an application implemented with the device.
[0025] Further information that the attestation information can include is the device's unique identification information, in particular its serial number or MAC address. Particularly advantageous for this type of information is device information that does not change during operation, i.e., fixed configuration properties. This information can be used to detect, from one piece of attestation information to another, that the device may have been tampered with. This information can therefore contribute to increasing the cybersecurity of the device, a system, and / or an application implemented by the device.
[0026] The attestation information preferably also includes local configuration settings of the device, such as a user password, or characteristics of the user password (e.g. length and / or the inclusion of lowercase / uppercase letters, numbers, special characters, etc.). Local configuration settings in the attestation information have the advantage that an assessment of the trustworthiness of the device can determine whether local settings may reduce the trustworthiness. For example, a user password that is too short shows that the cybersecurity of the device and possibly of several devices connected to the device may be reduced.
[0027] Furthermore, it is also desirable to include information about permanently integrated or detachably connected hardware components of the device in the attestation information. For example, it can be detected that a USB stick (USB: Universal Serial Bus) has been plugged into the device, which could weaken or violate the integrity of the device. Even the replacement of a hardware component that is permanently connected to the device, such as a memory or input / output unit, can be an indicator of a violation of the device's integrity when checking the attestation information and thus indicate a weakening of the device's cybersecurity.
[0028] It is also advantageous to specify a production order and / or a production step for which the attestation information is valid. This facilitates the assessment of the attestation information for a communication device because it simplifies the assignment of the configuration information to the production order or production step. This also increases the security of the device, as potential confusion between the production order or production step and the configuration information can be avoided.
[0029] Furthermore, providing information about the result of a device's security self-test can also increase the device's cybersecurity. Specifying whether a security self-test passed or failed in the attestation information can be used to improve the assessment of whether a device is still intact. Thus, this specific information contributes to improving the cybersecurity of the device and also of an entire system.
[0030] In a preferred embodiment of the invention, the attestation information is generated at the time of a change in the device's configuration information. This is advantageous because current attestation information is always available to be retrieved by the communication device. Furthermore, not only is the current availability of the attestation information improved, but delays in retrieving the attestation information are also avoided, since it does not have to be generated first.
[0031] In a preferred development of the invention, the attestation information is generated after a time of a change to the configuration information of the device, wherein the time is selected such that the device is in a sleep state or a maintenance state. In addition to configuration information of the device, the attestation information can also contain current information of the device, such as a new IP address (IP: Internet Protocol) or errors that have occurred in the device. The respective current information can be used by the communication device when deciding whether the device can be used, for example, to produce a product or to transmit critical production data, depending on errors detected in the device.For example, the detected error could indicate a phishing attempt, a defective security element or memory chip, or an intrusion attempt to compromise the device's cybersecurity. Thus, the communication device can exclude the device from further consideration for product production if such errors are detected.
[0032] However, retrieving the current information from the device can impair its functionality because, for example, real-time capability is temporarily not guaranteed as a result of the retrieval. It is therefore advantageous if the current information is retrieved at times when the device is in maintenance or idle mode. It is therefore advantageous if the attestation information is generated after a time when the configuration information of the device has been changed, with the time being chosen such that the device is in idle or maintenance mode. To determine these times, the device itself can be queried, for example via an OPC UA protocol, or a production planning system that manages information on current and planned production processes can be queried.This allows security checks, such as device integrity checks based on device management addressing, to be performed during these operational phases, where they do not impact production processes. Furthermore, the integrity check can be performed upstream of the release or initiation of a planned production process.
[0033] In a preferred development of the invention, the attestation information can contain information about how it was generated. This makes it possible to recognise, for example, that an attestation has been created by a device management system based on the device configuration information present in the device management system, i.e. that the attestation is attestation information according to the invention in accordance with the present patent specification. This makes it possible to differentiate it from conventional attestation known from the prior art. Furthermore, the information about how the attestation information was generated can have the advantage that the communication device which requests the attestation information and evaluates it if necessary can support different formats or codings of the attestation information. This development therefore increases flexibility on the one hand, as different formats or codings can be used.Encodings can be used to create the attestation information. Furthermore, this development also increases security when using the method according to the invention, since compromised formats or encodings can be excluded from the future creation of the attestation information, thus ensuring secure creation of the attestation information in the future.
[0034] In a preferred development of the invention, the attestation information can comprise device-specific attestation information, wherein the device-specific attestation information is generated by the device itself. This development has the advantage that, for example, device-specific information which is not part of the configuration information can be provided securely by the device itself as device-specific attestation information. This increases cybersecurity when using the device because, on the one hand, device-specific information is provided in the form of device-specific attestation information, and, on the other hand, the attestation information is formed by two units, i.e., by the device itself and the attestation unit, thus making manipulation of the attestation information more difficult.
[0035] In a preferred development of the invention, the generation of the attestation information comprises a check as to whether authentication of the device with respect to the device management unit has been successful, wherein the attestation information comprises the result of this check. The authentication of the device with respect to the device management unit ensures that information can be exchanged securely between the device and the device management unit. If the check shows that authentication was not successful, the communication device can decide that the device is not secure enough for further use, for example in production. This development therefore ensures that the attestation information additionally contains information which further develops an assessment for secure use of the device.
[0036] In a preferred development of the invention, the providing further comprises receiving a request message from a communication device for providing the attestation information and delivering the attestation information to the communication device by means of a response message. This procedure is advantageous because the communication device can send a request message to the device for providing the attestation information, even if the device itself only partially supports this functionality or does not support it at all. In particular, the request message addressed to the device can be forwarded by the device to the device management unit or redirected to the device management unit without being delivered to the device. This ensures that the request message is received and processed either by the device itself or by the device management unit.This further development also demonstrates the advantage of ensuring a uniform approach, regardless of whether the device itself supports the generation or provision of attestation information or not. This simplifies communication with the communication device, as the device receives the attestation information regardless of its functionality.
[0037] To simplify communication if the device cannot generate any or only partial attestation information itself, the device management unit can filter the request message from the data traffic between the device and the communication device. This further offers the advantage of reducing the latency between the request message and the response message.
[0038] The invention is characterized in that a reliable, tamper-proof confirmation is available in the form of attestation information, which indicates that a specific device is actually managed by a device management system, i.e. that company specifications are implemented on this device. A device managed by a device management system can also be referred to as a managed device. This information can be evaluated by a communication partner such as the communication device during an authorization check. In addition, a device attestation in the form of attestation information, which provides integrity information about a device, can be created by the device manager unit on behalf of the device. This means that a device integrity attestation can also be created for devices that do not themselves support attestation.This also allows support for devices that cannot implement an attestation themselves, or cannot implement it with sufficient trustworthiness. Furthermore, a uniform attestation can be created for devices that create different attestation types (e.g., different formats, different content, different semantics).
[0039] The invention also relates to a device for carrying out a method according to at least one of the above method steps, in which individual steps of the method can be implemented and carried out by means of one or more modules. These modules can be realized in software, hardware or a combination of software and hardware for carrying out the method. For example, one or more modules can have a processor which is connected to a memory unit and an input and / or output unit. Individual or all method steps can be stored as machine-readable code in the memory unit and can be read one after the other in the processor and processed by it to carry out the method.
[0040] The invention also relates to a method for using attestation information formed according to at least one of the preceding method steps, wherein a communication device controls communication with the device depending on a check of the attestation information using its own rules, in particular blocking, permitting, or restricting access by and / or to the device and / or data exchange with the device. Using the method for providing the attestation information ensures that the communication device can use the device securely, for example, in the context of product production.
[0041] The above methods can also be realized and implemented as computer-implemented methods.
[0042] The invention and its further developments are explained in more detail with the aid of drawings. In detail:
[0043] Fig. 1 Technical system with several devices (state of the art)
[0044] Fig. 2 Technical system with several devices where central certification is provided
[0045] Fig. 3 Textual representation of an attestation information
[0046] Elements with the same function and mode of operation are provided with the same reference symbols in the figures.
[0047] The following exemplary embodiments have, unless otherwise stated or already stated, at least one processor and / or a memory unit in order to implement or carry out the method. Furthermore, in particular a (relevant) person skilled in the art, with knowledge of the method claim(s), will of course be aware of all possibilities for realizing products or implementation possibilities customary in the prior art, so that a separate disclosure in the description is not required. In particular, these customary implementation variants known to the person skilled in the art can be implemented exclusively using hardware (components) or exclusively using software (components).Alternatively and / or additionally, the person skilled in the art can, within the scope of his or her expert knowledge, select any combination of hardware (components) and software (components) according to the invention in order to implement implementation variants according to the invention.
[0048] A combination of hardware (components) and software (components) according to the invention can occur in particular when a part of the effects according to the invention is preferably effected exclusively by special hardware (e.g. a processor in the form of an ASIC or FPGA) and / or another part is effected by the (processor- and / or memory-supported) software.
[0049] In particular, given the large number of different implementation possibilities, it is impossible, and also not expedient or necessary for understanding the invention, to list all of these implementation possibilities. Therefore, all of the following exemplary embodiments are intended merely to illustrate, by way of example, some possible implementations of the teachings of the invention.
[0050] Consequently, the features of the individual embodiments are not limited to the respective embodiment, but relate in particular to the invention in general. Accordingly, features of one embodiment can preferably also serve as features for another embodiment, in particular without this having to be explicitly stated in the respective embodiment.
[0051] Fig . 1 has already been explained in more detail in the introduction .
[0052] Fig. 2 shows a first embodiment of the invention. Before starting production of a product, a communication device KOG is to check whether a device GER of a production plant already has a current configuration KON that is required or expected for the production of the product. To do this, the communication device wants to obtain attested validity of the device's current configuration information. The current configuration information relates to two parameters with which the device can control, on the one hand, the speed and, on the other hand, the direction of a conveyor belt.
[0053] The device is managed by a device management unit GME . For this purpose, the device can communicate with the device management unit GME via a cryptographically secured data channel, via which the device management unit transmits a current configuration KON to the device in the form of configuration information KIN . The configuration information includes, for example, two parameters that are configured for a production process step . Furthermore, the configuration information can also include an update to the device's operating system software or security-relevant settings of the device . The device can inform the device management unit about unforeseen events , such as errors in the program run and received messages that are not understood by the device .
[0054] To determine the validity of the configuration information, the communication device sends a request message AFN over a network NET to the device GER . The network, for example a Local Area Network (LAN), connects devices / units connected to the network using data technology, for example, via an Internet Protocol (IP). The device receives the request message AFN . Since it cannot interpret the content of the request message, it forwards this message to its device management unit GME .
[0055] The device management unit GME understands the content of the request message and sends an attestation request message AAN to an attestation unit ATE assigned to it. The attestation unit ATE has access to the current configuration information KIN of the device and, with the help of its Trusted Platform Module TPM, creates attestation information ATI in the form of an attestation response message AWN, which, on the one hand, has a cryptographically protected data structure of the device's configuration information. On the other hand, the attestation response message AWN contains information that the device is managed by the device management unit. The device management unit GME receives the attestation response message AWN and forwards it to the communication device KOG in the form of a response message ANN.
[0056] The communication device KOG receives the response message ANN and can recognize from its content that the configuration information KIN, i.e. the current configuration KON, is already present in the device GER in such a way that the communication device KOG can carry out the production with the help of the device GER, for example triggered by a control command.
[0057] Figure 3 shows a textual example of a possible structure of the attestation information ATI, also known as Managed Device Attestation. The attestation information comprises identification information ID1 (devicelD) for the device GER to which the attestation information refers. This can be, for example, a serial number ID2 (serialNumber) or a MAC address (not shown) of the device GER. The attestation information also comprises information about its temporal validity range ID3 (validFrom, validTo), which specifies when the attestation information is valid. This temporal validity range is defined in more detail with a respective time specification ID4 (time), for example date and time.The attestation information also contains an indication that the device is a managed device (“managed device”), see ID5, which can be positively confirmed by the acronym true ID6. In addition, the attestation information shows identification information ID7 for the device management server that manages this device (dmServer), information ID8 for the organizational unit (dmServerOrg), such as Siemens AG, which operates the device management server and therefore has control over the configuration of the device GER, and information ID9 for the device configuration policy (dmServerDevicePolicy) that is implemented on the device GER by the device management server. The attestation information is cryptographically protected by a cryptographic checksum ID10, in this case a digital signature (Signature).
[0058] List of reference symbols
[0059] NET network
[0060] ATE Attestation Unit
[0061] GME device management unit
[0062] KIN configuration information
[0063] KON current configuration
[0064] GER device
[0065] ATI Attestation Information
[0066] ATI first attestation information
[0067] AT2 second attestation information
[0068] AFN request message
[0069] AAN Attestation Request Message
[0070] ANN reply message
[0071] AWN attestation response message
[0072] KOG communication device
[0073] ZPT time (of generation of the attestation information)
[0074] GTI device-specific attestation information
Claims
Patent claims 1. A method for providing attestation information (ATI) relating to configuration information (KIN) of a device (GER), wherein a current configuration (KON) of the device (GER) is managed by a device management unit (GME) using the configuration information (KIN), the attestation information (ATI) is created on the basis of the configuration information (KIN) by an attestation unit (ATE) assigned to the device management unit (GME), the providing further comprises receiving a request message (AFN) from a communication device (KOG) for providing the attestation information (ATI) and delivering the attestation information (ATI) to the communication device (KOG) by means of a response message (ANN), and - the request message (AFN) addressed to the device (GER) is redirected to the device management unit (GME) without delivery to the device (GER), and / or - the request message (AFN) is filtered out from data traffic between the device (GER) and the communication device (KOG) by the device management unit (GME).
2. Method according to claim 1, wherein the attestation information (ATI) comprises at least one of the following information: the configuration of the device is managed by the device management unit; an actual state of the configuration of the device; a target state of the configuration of the device; a validity period of the configuration information (KIN); a type of authentication of the device to the device management unit and / or of the device management unit to the device; unique identification information of the device, in particular its serial number, its MAC address; local configuration settings of the device (GER); Permanently integrated or detachably connected hardware components of the device; an indication of a production order and / or a production step for which the attestation information (ATI) is valid; an indication of a result of a security self-test. 3 . Method according to one of the preceding claims, wherein the attestation information (ATI ) is generated at a time of a change in the configuration information (KIN) of the device (GER). 4 . Method according to one of the preceding claims, wherein the attestation information (ATI ) is generated after a time (ZPT ) of a change in the configuration information (KIN) of the device (GER), wherein the time (ZPT) is selected such that the device (GER) is in a rest state or a maintenance state. 5 . Method according to one of the preceding claims, wherein the attestation information (ATI ) contains an indication of its generation . 6 . Method according to one of the preceding claims, wherein the attestation information (ATI ) comprises device-specific attestation information (GTI ), wherein the device-specific attestation information is generated by the device itself.
7. Method according to one of the preceding claims, wherein the generation of the attestation information (ATI) comprises a check as to whether an authentication of the device (GER) with respect to the device management unit (GME) has been successful, wherein the attestation information (ATI) indicates the result of this check.
8. Device for carrying out a method according to one of claims 1 to 7, characterized in that individual steps of the method can be implemented and executed by means of one or more modules (MOD).
9. Method for using attestation information (ATI) formed according to one of claims 1 to 7, characterized in that a communication device (KOG) controls communication with the device (GER) depending on a check of the attestation information (ATI) with its own rules (REG), in particular blocks, allows or restricts access by and / or to the device (GER) and / or data exchange with the device (GER).