Methods for determining the safe integrity of the functions of a distributed system

A method for determining safety integrity in distributed systems by analyzing metadata and classifying functions for independence addresses the limitations of existing methods, enabling safer and more efficient operation by recognizing dependencies and allowing for dynamic reconfiguration.

JP2026525333APending Publication Date: 2026-07-29ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
ROBERT BOSCH GMBH
Filing Date
2024-05-07
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Existing methods for determining safety integrity in distributed systems, particularly those with dynamic configurations, are limited in their ability to analyze all possible combinations of redundant function executions and cannot account for changes due to software updates, leading to potential safety risks.

Method used

A method that involves providing metadata for components, analyzing their impact based on homogeneity, classifying functions for independence, and determining safety integrity through a central data processing unit, with optional steps for protecting metadata and reconfiguring the system as needed.

Benefits of technology

Enables dynamic determination of safety integrity in distributed systems, allowing early recognition of dependencies and correlations, facilitating safer operations by initiating mitigation measures and reducing data exchange, thus enhancing safety and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026525333000001_ABST
    Figure 2026525333000001_ABST
Patent Text Reader

Abstract

The present invention relates to a method (100) for determining the safety integrity of a function (2) of a distributed system (1), comprising the following steps: - A step of providing (101) at least one specification for at least one characteristic of a component (9) of a distributed system (1), and providing this at least one specification for at least one characteristic as metadata for the component (9), wherein the component (9) participates in the execution of a function (2) of the distributed system (1), - A step in which the metadata of at least one further component (9') is analyzed (102) taking into consideration the metadata of component (9), and based on this analysis, the influence between component (9) and at least one further component (9') is determined, wherein this influence is determined based on the homogeneity of at least one specification of component (9) and at least one specification of at least one further component (9'), and at least one further component (9') participates in the execution of the function (2) of the distributed system (1), - A method (100) comprising the step of classifying (103) the functions (2) of a distributed system (1) based on the determined impacts, wherein at least one class is specialized in the independence of the functions (2) of the distributed system (1), and the safety integrity of the functions (2) of the distributed system (1) is determined based on this classification. Furthermore, the present invention relates to computer programs, devices, and memory media for this purpose.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , ,

[0001] The present invention relates to a method for determining the safety integrity of functions in a distributed system. Furthermore, the present invention relates to a computer program, an apparatus, and a memory medium for this purpose.

Background Art

[0002] Vehicles have various applications. These applications are networked, among other things, at least partially with external systems such as, for example, cloud or edge systems. This networking can be such that safety-critical functions and calculations are also transferred from the vehicle to the cloud or the edge.

[0003] In order to achieve the safety integrity of a safety-critical system by means of functional redundancy, it may be necessary to prove sufficient independence of all paths of the functions executed by the vehicle's applications. A method for this could be, for example, dependent failure analysis (DFA) based on fault tree analysis (FTA). Regarding static redundant architectures, the application of DFA is in particular the state of the art and can be carried out during the design phase via available tools. In contrast, in a distributed system that is only configured during operation depending on the circumstances, this method can be limited because, for example, all possible combinations of redundant function executions or function calculations cannot be determined and analyzed in advance. Moreover, in a distributed system, individual elements can change over time, for example due to software updates, and therefore, depending on the circumstances, a corresponding analysis may have to be carried out again before the system can be classified as safe or released.

Summary of the Invention

[0004] The present invention relates to a method having the features of claim 1, a computer program having the features of claim 8, an apparatus having the features of claim 9, and a computer-readable memory medium having the features of claim 10. Further features and details of the present invention are evident from the respective dependent claims, the description of the invention, and the drawings. In this regard, features and details described in relation to the method according to the present invention also apply, of course, to the computer program, the apparatus, and the computer-readable memory medium according to the present invention, and vice versa, and therefore, with respect to the disclosures of these individual embodiments of the invention, they are always or can be related to each other.

[0005] The present invention relates, in particular, to a method for determining the safe integrity of the functions of a distributed system, comprising the following steps: - A step in which the component provides at least one specification for at least one characteristic of a component of a distributed system, and provides this at least one specification for at least one characteristic as metadata for the component, the component participates in performing the functions of the distributed system, - A step in which, taking into consideration the metadata of a component, the metadata of at least one further component is analyzed, and based on this analysis, the impact between the component and at least one further component is determined, and this impact is determined based on the homogeneity of at least one specification of the component and at least one specification of the at least one further component, and at least one further component participates in performing the function of the distributed system, - A method comprising the step of classifying the functions of a distributed system based on the determined impacts, wherein at least one class is specialized in the independence of the functions of the distributed system, and the safety integrity of the functions of the distributed system is determined based on this classification.

[0006] Safety integrity can generally be understood as the effectiveness of a distributed system's functionality under the required conditions. Safety integrity can also represent the certainty of a distributed system's functionality. A distributed system could be, for example, a mobile robot, a cloud-connected vehicle, or a cyber-physical system. A distributed system can include various components, such as hardware, software, or data. A distributed system may further have at least one orchestrator, which employs, for example, software components and / or hardware components and corresponding data to perform the functions of the distributed system. An orchestrator can generally provide automated configuration, management, and coordination of the functions of the distributed system. An orchestrator can be formed as a software module and can generate at least one copy as a component for the execution of its functions, each of which employs the software components and / or hardware components and corresponding data in redundant execution. Characteristics, in the case of a software component, could be, for example, a software library, and the specifications for this could be the specific software library used by the software component. Therefore, homogeneity exists, in particular, when a component and at least one further component share the same software library. Further classes within the classification framework could be, for example, "sufficiently independent," "not sufficiently independent," and / or "independent but optimizable." Metadata is generally structured data that contains information about the characteristics of other data. Examples of metadata for a book might be author name, edition, year of publication, publisher, and ISBN, while metadata for a computer file might be, for example, file name, access rights, and last modified date. It is advantageous that the metadata for each component of a distributed system is available during the runtime of the distributed system and can be transferred along the path between components of the distributed system.Therefore, this method offers the advantage that, while the distributed system is running, the dynamic configuration of the distributed system for performing functions can be determined with sufficient independence. Furthermore, it is advantageous that the impact can be recognized at an early stage.

[0007] Within the framework of the present invention, the distributed system may also be a cyber-physical system and may have a hierarchical structure having at least two levels, in which case the component and at least one further component each reside at one of these at least two levels. In this case, it is preferable that the component and at least one further component each reside at the same level of the at least two levels. A cyber-physical system means, among other things, a complex of informational and software-technical components with mechanical and electronic parts that communicate over a data infrastructure such as the Internet. The top level may represent, for example, the entire distributed system, and the further levels may represent, for example, the functions, i.e., services, of the distributed system. It is further conceivable that security integrity decisions are made for individual levels based on metadata, in which case it is preferable that the component and at least one further component reside at the same level. It may be advantageous if security integrity is determined in a cascading manner for each level, and the results of each are then transferred to the next higher level.

[0008] This method optionally involves the following steps, namely - Steps to protect metadata via certificates and / or public key infrastructure and / or distributed ledger technology and / or checksums. It also includes.

[0009] The protection of metadata is advantageous because it allows for the proof of metadata integrity. Compressed and / or selected metadata can also be protected as described above. Optionally, the effects of dependencies and / or correlations between components of a distributed system and at least one further component are determined, and the method is as follows: - A step to determine the criticality of dependencies and / or correlations between a component and at least one further component, taking into account at least one boundary condition of the component and / or at least one further component. It may also be intended to include the following.

[0010] Criticality is, in particular, a relativization of how critical dependencies and / or correlations are to the functional independence of a distributed system. For this purpose, a range can be defined that indicates whether dependencies and / or correlations are critical or not. Dependencies may exist, for example, when two components have the same hardware. Correlations may exist when correlated data or models may contain a common deficiency. Boundary conditions may be determined, for example, by further characteristics of the components or may be considered separately. For example, the spatial arrangement of components may be considered as a boundary condition. Determining criticality has the advantage of allowing for a more detailed analysis of metadata.

[0011] Optionally, this method involves the following steps, namely - A step of transmitting metadata of a component and at least one further component to a central data processing unit, and allowing the central data processing unit to determine the safe integrity of the distributed system's functionality. It is also possible that this may include even more.

[0012] In this case, the central data processing unit may be part of a distributed system. A centralized decision on the safety and integrity of the distributed system's functions can be advantageous because it allows for a collective analysis of the impact of all components used for the function at any given time.

[0013] According to one advantageous modification of the present invention, the method is as follows: - Steps to initiate action based on the results of classifying the functions of the distributed system. It may also be intended to include the following.

[0014] The measure could be to reconfigure at least one part of the distributed system, for example, using other components of the distributed system. In particular, if there is a class dedicated to the functional independence of the distributed system, then the measure of not taking any action is also conceivable.

[0015] Within the framework of the present invention, this method involves the following steps, namely - A step in which metadata is compressed and / or selected, and in this regard, the compression and / or selection of metadata is carried out with regard to the integrity of the functional data, based on a check of the functional data of the component and / or at least one further component. It is even more conceivable that this may include further elements.

[0016] Metadata compression and / or selection may shorten metadata by removing or replacing parts of it with compressed alternatives. For example, if sufficient integrity of the functional data is confirmed during the functional data check for each component, at least one specification about the characteristics of each component may be removed. This has the advantage of potentially reducing transmission time between components with less data load. Functional data integrity may be determined by a lack of shared elements, such as a common hardware model or commonly used sensors.

[0017] Within the framework of this invention, the analysis of metadata is performed in the following steps, namely - A step of dynamically reconfiguring the paths used for the functions of the distributed system and / or implementing a redundant architecture for the distributed system, preferably further creating at least one fault tree and / or at least one failure mode impact analysis network and / or at least one causal graph based on the dynamic reconfiguration and / or redundant architecture. It may be advantageous if it includes [this].

[0018] Dynamic reconstruction offers the advantage of enabling more precise and flexible decisions regarding the safety and integrity of the functions of distributed systems. The method according to the present invention can be used in vehicles. For example, a distributed system may be a vehicle connected to the cloud. The vehicle may be formed as, for example, an automobile and / or a passenger car and / or an autonomous vehicle. The vehicle may have, for example, a vehicle mechanism and / or a driver assistance system for providing autonomous driving capabilities. The vehicle mechanism may be manufactured to automatically control and / or accelerate and / or brake and / or steer the vehicle at least in part.

[0019] Similarly, the object of the present invention is a computer program, in particular a computer program product, that includes instructions causing a computer to execute the method according to the present invention when the computer program is executed by the computer. Thus, the computer program according to the present invention inevitably comes with the same advantages as those described in detail in relation to the method according to the present invention.

[0020] Similarly, the object of the present invention is a device for data processing adapted to perform the method according to the present invention. For example, the device could be a computer running a computer program according to the present invention. The computer may have at least one processor for running the computer program. A non-volatile data memory may also be provided, in which the computer program can be stored, and from which the computer program can be read by the processor for execution.

[0021] Similarly, the subject of the present invention can be a computer-readable memory medium having a computer program according to the present invention and / or containing instructions for causing a computer to execute the method according to the present invention when executed by the computer. The memory medium is formed, for example, as a data memory such as a hard disk and / or non-volatile memory and / or memory card. The memory medium can be incorporated, for example, into a computer.

[0022] Moreover, the method according to the present invention can also be implemented as a method implemented on a computer. Further advantages, features, and details of the present invention will become apparent from the following description, in which exemplary embodiments of the present invention are described in detail with reference to the drawings. In this regard, the features mentioned in the claims and the description can each individually or in any combination form the essence of the present invention.

Brief Description of the Drawings

[0023] [Figure 1] It is a diagram schematically visualizing a method, a central data processing device, a device, a memory medium, and a computer program based on an exemplary embodiment of the present invention. [Figure 2] It is a schematic diagram of a distributed system based on an exemplary embodiment of the present invention. [Figure 3] It is a schematic diagram of a method for determining measures based on an exemplary embodiment of the present invention.

Modes for Carrying Out the Invention

[0024] In FIG. 1, a method 100, a central data processing device 30, a device 10, a memory medium 15, and a computer program 20 based on an exemplary embodiment of the present invention are schematically shown. Based on an exemplary embodiment shown in Figure 1, a method 100 for determining the safety integrity of function 2 of distributed system 1 includes the following steps. In the first step 101, at least one specification for at least one characteristic of component 9 of distributed system 1 is provided, thereby providing at least one specification for this at least one characteristic as metadata for component 9. In this case, component 9 is participating in the execution of function 2 of distributed system 1. In the second step 102, the influence between component 9 and at least one further component 9' is determined based on the analysis of the metadata for component 9, preferably by analyzing the metadata for at least one further component 9', which also preferably participates in the execution of function 2 of distributed system 1. In this case, the influence is determined based at least on the homogeneity between at least one specification of component 9 and at least one specification of the at least one further component 9'. In the third step 103, the safety integrity of function 2 of distributed system 1 is determined based on the classification of function 2 of distributed system 1, which may be classified based on the determined influence. In this regard, it is preferable that at least one class is specialized for the independence of function 2 of distributed system 1.

[0025] Figure 2, in particular, illustrates one possible embodiment of the distributed system 1. The distributed system 1 provides various functions 2, which in turn have access to various orchestrators 3. These orchestrators 3 can create copies 4 for the execution of a particular function 2, and these copies 4 determine, for example, which software 5, hardware 6, or data 7 will be used to execute this function 2. Each copy 4 may perform the same function 2 to provide redundancy. Safety integrity may be determined at the level of the copies 4, in which case each component 9 is, for example, various hardware modules 6. In addition, safety integrity may be determined at the level of the entire distributed system 1. It may be advantageous if safety integrity is determined cascadingly at each level, with the results of each being passed on to the next higher level.

[0026] Figure 3 shows a schematic diagram of a method 200 for determining an action based on an exemplary embodiment of the present invention. In this regard, in the first step 201, one function 2 is selected, and this function 2 should be performed with defined redundancy. Thus, for each redundancy, a replica 4 can be generated in the second step 202, which replica 4 employs various components 9 such as hardware 6 and software 5. In the third step 203, the calculation result of the replica 4, including the metadata of each component 9 of the replica 4, may be received by, for example, a central data processing device 30. Subsequently, in the fourth step 204, preferably the metadata of each component 9 of the replica 4 is checked with regard to critical dependencies and / or correlations. If no critical dependencies and / or correlations exist (path "N" for "No"), the calculation result may then be returned in step 206. If critical dependencies and / or correlations are found in step 204, according to the first option, a new replica 4 may be generated that uses, for example, other components 9 (path "Y1" for "Yes1"). According to the second option (path "Y2" for "Yes2"), an error message may be output within the frame of step 205.

[0027] One aspect of the present invention may involve determining or providing metadata regarding the potential critical impacts between components 9, particularly redundant components 9, within a dynamically networked distributed system 1 of functions 2, i.e., the potential for dependencies or correlations.

[0028] Critical dependencies could be common software 5, common hardware 6, or common data 7, which may include, for example, common systematic errors or stochastic errors in the sense of the ISO 26262 standard.

[0029] Correlation is a relationship between correlated data or models that may encompass common deficiencies, for example, in the sense of the standard ISO 21448. This metadata can be used during runtime, for example by orchestrator 3 or a security monitoring device, to recognize critical dependencies or correlations for the security integrity of function 2 to be executed by distributed system 1, and to initiate necessary actions, particularly mitigation measures. Simultaneously, independence checks 8 are preferably performed in a cascaded manner (see Figure 2). That is, if parts of the function chain are sufficiently independent, this determined metadata can be explicitly passed on, for example, via a protected certificate, and does not need to be checked again in the receiving system. If details about component 9 are needed for further checking at a higher level, these details can be encoded, for example, using hash values.

[0030] The advantages of the present invention may include the following: Specifically, by applying the present invention, dynamic configurations, such as those assumed within a distributed system 1, can be determined in operation with respect to sufficient independence, and therefore advantageously made safer. Further enhanced safety through mitigation may be provided. Early recognition of dependencies allows measures, particularly mitigation measures, to be initiated at a relatively low functional level to achieve the required independence anyway, or by safely reacting (e.g., transitioning to a safe state) at the level of the safety-critical system that requested the calculation. Further leakage of details of component 9 at lower levels is prevented, particularly by cascading the check results to the next level. In addition, this may reduce the amount of data that must be exchanged between components 9 or levels. This may enable simple and efficient (vertical and horizontal) scaling of this method.

[0031] The following discusses possible root causes of dependencies and correlations, which may be covered within the exchanged metadata. For network nodes, a common cloud, hyperscaler, or software stack could be a root cause. For software, a common software module or library, manufacturer, version, configuration, or hyperparameters could be a root cause. For hardware, a common hardware type (e.g., memory), manufacturer, version, or spatial location (e.g., server) could be a root cause. More specific to the spatial location of hardware, electromagnetic interference, humidity, and overheating may be factors. A further factor in the case of hardware, is voltage supply. For data, root causes could be a common database, sensor modality, common sensor, common input signal, common version, spatial location, or field of view. For applied machine learning models, root causes could be a common database, the presence of a digital twin, a common manufacturer, a common (probabilistic) algorithm, or a common AI module (even different versions).

[0032] The format for providing metadata may be, for example, explicit information within the message, i.e., in the data exchanged between components 9, or the metadata may be provided coded, for example, by a hash or MAC.

[0033] The aggregation of metadata (sometimes cascaded) is described in more detail below. Even within a multi-level networked system consisting of branched trees, metadata can be transmitted in an appropriate form along the chain of components to verify whether important dependencies exist regarding data processing functions and / or data processing systems.

[0034] Metadata may be transmitted in the following exemplary forms, depending on latency requirements, communication resources, and the desired data protection. Participant metadata can be stored in a particularly protected central data processing unit 30 (preferably a backend service) where significant impacts can be examined. Here, for example, methods for PSI (Private Common Set), MPC-based methods, or a cleanroom based on a Trusted Execution Environment (TEE) can be used, which are particularly known in the current technology. In this case, individual elements are preferably received from the central data processing unit 30, and in some cases, only feedback is provided on whether there are any impacts to consider in the case of the desired combination, particularly in the case of a safety composition.

[0035] Alternatively, the metadata can be passed on only as hashes, and these hashes can be evaluated. For example, by assigning hash functions to software libraries, the higher-level component 9 can check whether redundant components 9 result in a common hash function, thereby identifying the impact.

[0036] A decentralized embodiment can use security methods such as a "confidential common set" to exchange metadata among participants, i.e., component 9, thereby identifying shared impacts without the direct external disclosure of all internal system details, which may contain information that should, in some cases, be kept secret.

[0037] To minimize latency, metadata can be compressed or selected, and for this purpose, it is checked which functional data has already been examined with a high diagnostic coverage rate by previous data processing, and therefore already enjoys a reasonably high level of integrity, and preferably does not need to be examined further. It is preferable that functional data that was previously primarily "passed through" and whose final integrity check has not yet been performed is associated with metadata that is important to this functional data, and it is even more preferable that only this metadata is transferred within the chain.

[0038] Metadata can be protected, for example, through certificates, PKI, ledgers, or checksums. The evaluation of metadata can be performed, for example, by a simple check of the (critical) common parts of the metadata provided by the "redundant" function 2. More detailed checks may include a dynamic reconstruction of the functional paths used at any given time or a redundant architecture, for example, by utilizing a standard system model for modular representation (MBSE system model) or by evaluating additional metadata regarding functional relationships. More detailed checks may further include the dynamic creation of a fault tree based on this architecture and checking for critical common parts, for example, via cut sets. In addition or alternatively, part of the detailed checks may be the dynamic creation of an FMEA network based on this architecture and checking for critical common parts, for example, via string comparisons. In addition or alternatively, part of the detailed checks may be the dynamic creation of a causal graph based on this architecture and checking for critical paths.

[0039] Possible goals of this evaluation could be the identification of common elements (in the sense of "same") and / or "common parts" (homogeneous redundancy, e.g., common hardware types, common software libraries). Furthermore, the subsequent determination of the criticality of commonality can be performed depending on the boundary conditions at the time, for example, if common hardware 6 exists but is spatially separated, or depending on the context at the time, for example, whether simultaneous failure or simply homogeneous distortion would result. For this purpose, important boundary condition and contextual information for the component 9 to be checked may be provided, for example, by the requesting system. The goal may also be to identify correlating factors, e.g., correlated data or sensors. In addition, the criticality of the correlation can be determined depending on the boundary conditions at the time or the context at the time. The evaluation can be performed during operation, over a defined time span, or continuously.

[0040] The resulting output can define various classes, e.g., "sufficiently independent," "not sufficiently independent," or "independent but optimizable." Measures, particularly mitigation measures, may, for example, in the case of orchestrator 3, be reconfiguration at a lower level, e.g., a request for another or further replication 4. At the system level, error responses, e.g., a transition to a safe state, may be activated. With respect to the "independent but optimizable" range, measures, particularly mitigation measures, may be reconfiguration by selecting paths with lower, no, or even negative correlations among the components 9 in the path.

[0041] The results can be evaluated using lookup tables, machine learning models, or probabilistic models (e.g., Bayesian networks), and may be performed locally, for example, in a vehicle, or centrally, for example, in the cloud or a central "safety node."

[0042] Possible extensions include not only application to homogeneous redundant computations, but also to heterogeneous redundant computations, for example, when a node or function 2, i.e., a service, is used for simultaneous computation of multiple hypotheses (each with other parameters, data, and model assumptions). Further possibilities include combination with component criticality analysis or additional use of Bayesian networks to assess the entire software stack.

[0043] The above description of these embodiments merely illustrates the present invention within the framework of examples. Of course, individual features of the embodiments can be freely combined with each other without departing from the framework of the present invention, as long as they are technically meaningful.

Claims

1. A method (100) for determining the safety integrity of a function (2) of a distributed system (1), comprising the following steps: - A step of providing (101) at least one specification for at least one characteristic of a component (9) of the distributed system (1), and providing the at least one specification for the at least one characteristic as metadata for the component (9), wherein the component (9) participates in the execution of the function (2) of the distributed system (1), - A step of analyzing (102) the metadata of at least one further component (9') with regard to the metadata of component (9), and determining the influence between component (9) and at least one further component (9') based on the analysis, wherein the influence is determined based on at least the homogeneity between the at least one specification of component (9) and the at least one specification of the at least one further component (9'), and the at least one further component (9') participates in the execution of the function (2) of the distributed system (1), - A step of classifying (103) the functions (2) of the distributed system (1) based on the determined impacts, wherein at least one class is specialized in the independence of the functions (2) of the distributed system (1), and the safety integrity of the functions (2) of the distributed system (1) is determined based on the classification. Method (100), including the method (100).

2. The distributed system (1) is a cyber-physical system and has a hierarchical structure having at least two levels, wherein the component (9) and the at least one further component (9') each exist in one of the at least two levels, and the method (100) optionally includes the following steps, i.e. - A step of protecting the metadata via certificates and / or public key infrastructure and / or distributed ledger technology and / or checksums. The method according to claim 1 (100), further comprising the above.

3. The effects of dependencies and / or correlations between the component (9) of the distributed system (1) and the at least one further component (9') have been determined, and the method (100) is the following steps, i.e. - A step of determining the criticality of the dependency and / or correlation between component (9) and the at least one further component (9'), taking into account at least one boundary condition of component (9) and / or the at least one further component (9'). The method according to claim 1 or 2 (100), further comprising the above.

4. The following steps, namely - Transmit the metadata of the component (9) and the at least one further component (9') to the central data processing unit (30), and the central data processing unit (30) determines the safety integrity of the function (2) of the distributed system (1). The method according to any one of claims 1 to 3, further comprising (100).

5. The following steps, namely - Steps to initiate action according to the result of the classification (103) of the function (2) of the distributed system (1) The method according to any one of claims 1 to 4, further comprising (100).

6. The following steps, namely - A step of compressing and / or selecting the metadata, wherein the compression and / or selection of the metadata is performed with regard to the integrity of the functional data, based on a check of the functional data of the component (9) and / or the at least one further component (9'). The method according to any one of claims 1 to 5, further comprising (100).

7. The analysis (102) of the metadata is carried out in the following steps, namely - A step of dynamically reconfiguring the paths used at any given time for the function (2) of the distributed system (1) and / or implementing a redundant architecture of the distributed system (1), preferably further creating at least one fault tree and / or at least one failure mode effects analysis network and / or at least one causal graph based on the dynamic reconfiguration and / or the redundant architecture. The method according to any one of claims 1 to 6, characterized by including (100).

8. A computer program (20) that includes an instruction causing a computer (10) to execute the method (100) according to any one of claims 1 to 7 when the computer (10) executes the computer program (20) by the computer (10).

9. Apparatus for data processing (10) adapted to perform the method (100) according to any one of claims 1 to 7.

10. A computer-readable memory medium (15) containing instructions that cause the computer (10) to perform the steps of the method (100) according to any one of claims 1 to 7 when executed by the computer (10).