Control device, and program and method for managing input / output of data stored in memory unit of control device
The control device with encrypted data areas and authentication mechanisms ensures secure data transfer, protecting vendor interests and maintaining end-user productivity by preventing unauthorized copying and data leakage.
Patent Information
- Application Number
- JP2021035281
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-05
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2041-03-05
AI Technical Summary
Existing control devices do not adequately address the need to protect the interests of vendors while maintaining the productivity of end users, as they fail to manage copies of data related to control objects effectively.
Implementing a control device with a storage unit containing a first and second area, where a common key is stored, and using area management units to encrypt and authenticate data access, ensuring only authorized devices can decrypt and update the data.
This approach prevents data leakage and unauthorized copying, protecting vendor interests while allowing end users to maintain productivity by enabling secure data transfer between compatible devices.
Smart Images

Figure 0007679645000001 
Figure 0007679645000002 
Figure 0007679645000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a control device, and a program and method for managing input and output of data stored in a storage unit of the control device. [Background technology]
[0002] Conventionally, a control device that controls a controlled object (for example, a machine or equipment used at a production site) is known. For example, International Publication No. 2012 / 111117 (Patent Document 1) discloses a programmable logic controller including a master unit and one or more slave units. The master unit has an organization information table that manages IO numbers assigned to the slave units, and generates password distribution information from password division data obtained by dividing a password set in the master unit, using IO numbers assigned to the slave units. The slave units store the password distribution information sent from the master unit. The programmable logic controller can reduce the password management costs of a system administrator by preventing the leakage of password information. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2012 / 111117 Summary of the Invention [Problem to be solved by the invention]
[0004] The data related to the control object stored in the control device may include a user program (e.g., a control program for controlling the control object) created by a vendor that provides the control device to a user. If an end user who purchased a control device from a vendor is able to copy the user program stored in the control device to another control device and operate it, the vendor may lose an opportunity to further obtain the consideration for the other control device from the end user. Therefore, it is necessary for the vendor of the control device to prevent the copy of the data related to the control object stored in the control device from being used in the other control device. On the other hand, when a control device breaks down, the end user can replace the broken control device with another control device that operates normally by copying the data related to the control object stored in the control device to the other control device. Therefore, it is necessary for the end user to be able to use the copy of the data related to the control object stored in the control device in the other control device.
[0005] However, the programmable logic controller disclosed in Patent Document 1 does not take into consideration the need to manage copies of data related to the control object stored in the control device, from the standpoint of protecting the interests of the control device vendor and maintaining the productivity of the control device end user.
[0006] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to prevent a decline in productivity of end users of control devices while protecting the interests of control device vendors. [Means for solving the problem]
[0007] A control device according to an example of the present disclosure includes a storage unit, a first area management unit, and a second area management unit. The storage unit includes a first area and a second area in which a common key is stored. The first area management unit encrypts and outputs data stored in the first area using the common key. The second area management unit authenticates access to the second area from a device different from the control device using a first password. The first area management unit decrypts update data encrypted using the common key using the common key, and performs a first update using the decrypted update data. 1 Update the area.
[0008] According to this disclosure, by encrypting the data stored in the first area with a common key and outputting it, an end user can decrypt the data in another control device in which the common key is stored and replace the broken control device with the other control device, thereby preventing a decrease in productivity. Also, a control device vendor can limit devices that can copy the data stored in the first area of the control device to control devices produced by the vendor. This can protect the opportunity for the vendor to receive payment for the control device from the end user.
[0009] In the above disclosure, a second password may be stored in the first area, and the first area management unit may authenticate the update using the second password.
[0010] According to this disclosure, it is possible to prevent the first area from being illegally updated. In the above disclosure, the common key may have a value that is unique to a particular user associated with the control device.
[0011] According to this disclosure, the encrypted data in the first area is prevented from being decrypted in a control device produced for another end user, thereby preventing the end user's information assets contained in the first area from being leaked to other end users.
[0012] A program according to another example of the present disclosure manages input and output of data stored in a storage unit of a control device, the storage unit including a first area and a second area. When executed by a processor, the program authenticates access to the second area from a device different from the control device using a password, stores a common key in the second area, encrypts and outputs data stored in the first area using the common key, decrypts update data encrypted using the common key using the common key, and outputs the encrypted update data using the decrypted update data. 1 Update the area.
[0013] According to this disclosure, by encrypting the data stored in the first area with a common key and outputting it, an end user can decrypt the data in another control device in which the common key is stored and replace the broken control device with the other control device, thereby preventing a decrease in productivity. Also, a control device vendor can limit devices that can copy the data stored in the first area of the control device to control devices produced by the vendor. This can protect the opportunity for the vendor to receive payment for the control device from the end user.
[0014] A method according to another example of the present disclosure manages input and output of data stored in a storage unit of a control device, the storage unit including a first area and a second area, the method includes a step of authenticating access to the second area from a device different from the control device using a password, a step of storing a common key in the second area, a step of encrypting and outputting data stored in the first area using the common key, a step of decrypting update data encrypted using the common key using the common key, and a step of outputting the update data using the decrypted update data. 1 and updating the region.
[0015] According to this disclosure, by encrypting the data stored in the first area with a common key and outputting it, an end user can decrypt the data in another control device in which the common key is stored and replace the broken control device with the other control device, thereby preventing a decrease in productivity. Also, a control device vendor can limit devices that can copy the data stored in the first area of the control device to control devices produced by the vendor. This can protect the opportunity for the vendor to receive payment for the control device from the end user. Effect of the Invention
[0016] According to the control device, program, and method disclosed herein, data stored in the first area is encrypted using a common key and then output, thereby protecting the interests of the control device vendor while preventing a decline in productivity for the end user of the control device. [Brief description of the drawings]
[0017] [Figure 1] 2 is a block diagram showing a configuration of a control device according to an embodiment; FIG. [Diagram 2] 2 is a schematic diagram showing a configuration example of a control system including the control device of FIG. 1. [Diagram 3] 3 is a schematic diagram illustrating an example of a hardware configuration of the control device in FIG. 2. [Figure 4] 3 is a schematic diagram illustrating an example of a hardware configuration of the support device of FIG. 2. [Diagram 5] FIG. 2 is a diagram showing each phase in which update data is input to a control device and each phase in which update data is output from the control device. [Figure 6] 10 is a diagram showing an example of a password setting dialog displayed on the screen of the support device by the secure area management unit of FIG. 1 when backup / restore key management in the control device is enabled by the support device. FIG. [Figure 7]FIG. 13 is a diagram showing an example of an authentication dialog displayed on the screen of a support device by a secure area management unit when a vendor password is set and access to the secure area from a device other than the control device is detected. [Figure 8] 13 is a diagram showing an example of a common key setting dialogue displayed on the screen of the support device by the secure area management unit when access to the secure area is permitted. FIG. [Figure 9] 7 is a flowchart showing the flow of a vendor password setting process performed by the secure area management unit in FIG. 1 when backup / restore key management is enabled by the vendor in FIG. 5. [Figure 10] 2 is a flowchart showing the flow of a shared key setting process performed by a secure area management unit in FIG. 1; [Figure 11] 2 is a flowchart showing the flow of a backup process performed by a user area management unit in FIG. 1; [Figure 12] 2 is a flowchart showing the flow of a restore process performed by a user area management unit in FIG. 1. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0018] Hereinafter, the embodiments will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference characters and, in principle, the description thereof will not be repeated.
[0019] <Application Examples> Fig. 1 is a block diagram showing a configuration of a control device 100 according to an embodiment. As shown in Fig. 1, the control device 100 includes a storage unit 1, a user area management unit 2 (first area management unit), and a secure area management unit 3 (second area management unit).
[0020] The storage unit 1 includes a system area 10, a user area 11 (first area), and a secure area 12 (second area). The user area 11 stores data Du related to a control target and an online password Pw2 (second password). The secure area 12 stores a common key Kc1 and a vendor password Pw1 (first password). The common key Kc1 is used in common for both encryption and decryption of data.
[0021] The secure area management unit 3 performs a vendor password setting process and stores the input vendor password Pw1 in the secure area 12. After authentication using the vendor password Pw1, the secure area management unit 3 stores the input common key Kc1 in the secure area 12. The secure area management unit 3 authenticates access to the secure area 12 from a device other than the control device 100 using the vendor password Pw1.
[0022] The user area management unit 2 encrypts data Du related to the control target using a common key Kc1 and outputs the encrypted data as update data Db1. The user area management unit 2 decrypts the update data Db2 encrypted using the common key Kc1 using the common key Kc1, and updates the user area 11 using the decrypted update data Db2. The user area management unit 2 authenticates the update of the user area 11 using an online password Pw2.
[0023] <Control system configuration> Fig. 2 is a schematic diagram showing a configuration example of a control system 1000 including the control device 100 of Fig. 1. As shown in Fig. 2, the control system 1000 includes a device group in which a plurality of devices are configured to be able to communicate with each other. Typically, the devices may include the control device 100, which is a processing entity that executes a control program, and peripheral devices connected to the control device 100.
[0024] The control device 100 corresponds to an industrial controller that controls control targets such as various facilities or devices. The control device 100 is a type of computer that executes control calculations, and typically includes a PLC (Programmable Logic Controller). The control device 100 is connected to field devices 500 via a field network 20. The control device 100 exchanges data with at least one field device 500 via the field network 20.
[0025] The control calculations executed in the control device 100 include a process of collecting data collected or generated in the field device 500, a process of generating data such as command values for the field device 500, and a process of transmitting the generated output data to the target field device 500.
[0026] It is preferable that the field network 20 employs a bus or network that performs periodic communication. Known examples of such buses or networks that perform periodic communication include EtherCAT (registered trademark), EtherNet / IP (registered trademark), DeviceNet (registered trademark), and CompoNet (registered trademark). EtherCAT (registered trademark) is preferable because it guarantees the arrival time of data.
[0027] Any field device 500 can be connected to the field network 20. The field device 500 includes an actuator that exerts some kind of physical action on a robot or a conveyor in the field, and an input / output device that exchanges information with the field.
[0028] In the control system 1000, the field device 500 includes a plurality of servo drivers 520_1 and 520_2, and a plurality of servo motors 522_1 and 522_2 connected to the plurality of servo drivers 520_1 and 520_2, respectively. The field device 500 is an example of a "controlled object."
[0029] The servo drivers 520_1 and 520_2 drive corresponding ones of the servo motors 522_1 and 522_2 in accordance with command values (such as a position command value or a speed command value) from the control device 100. In this manner, the control device 100 can control the field device 500.
[0030] The control device 100 is also connected to other devices via a higher-level network 60. The higher-level network 60 is connected to the Internet, which is an external network, via a gateway 700. The higher-level network 60 may employ Ethernet (registered trademark) or EtherNet / IP (registered trademark), which are general network protocols. More specifically, at least one server device 300 and at least one display device 400 may be connected to the higher-level network 60.
[0031] The server device 300 may be a database system or a manufacturing execution system (MES). The manufacturing execution system acquires information from the manufacturing device or facility to be controlled, monitors and manages the entire production, and may handle order information, quality information, shipping information, and the like. In addition, a device that provides an information system service may be connected to the upper network 60. The information system service may be a process that acquires information from the manufacturing device or facility to be controlled and performs macro or micro analysis. For example, the information system service may be data mining that extracts some characteristic tendency contained in the information from the manufacturing device or facility to be controlled, or a machine learning tool that performs machine learning based on the information from the facility or machine to be controlled.
[0032] The display device 400 receives operations from a user, outputs commands to the control device 100 in response to the user operations, and also graphically displays the results of calculations performed by the control device 100, etc.
[0033] A support device 200 can be connected to the control device 100. The support device 200 is a device that supports the preparations required for the control device 100 to control a control target. Specifically, the support device 200 provides a development environment (program creation and editing tools, a parser, a compiler, etc.) for a program executed by the control device 100, a setting environment for setting configuration information (configuration) of the control device 100 and various devices connected to the control device 100, a function for outputting a generated program to the control device 100, and a function for correcting and changing a program executed on the control device 100 online.
[0034] In the control system 1000, the control device 100, the support device 200, and the display device 400 are configured as separate entities, but a configuration in which all or part of these functions are integrated into a single device may also be adopted.
[0035] The control device 100 may be used not only at one production site but also at other production sites, and may also be used at a plurality of different lines at one production site.
[0036] <Control device hardware configuration> Fig. 3 is a schematic diagram showing an example of a hardware configuration of the control device 100 of Fig. 2. As shown in Fig. 3, the control device 100 includes, as main components, a processor 102, a chipset 104, a main memory device 106, a secondary memory device 108, a host network controller 110, a support device interface 112, a memory card interface 114, a field network controller 116, an internal bus controller 120, an indicator 124, a DIP (Dual In-line Package) switch interface 125, a DIP switch 126, a power supply switch interface 127, and a power supply switch 128.
[0037] The secondary storage device 108 typically comprises a non-volatile storage device such as, for example, a hard disk drive (HDD), a solid state drive (SSD), a read only memory (ROM), an erasable programmable read only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM).
[0038] The secondary storage device 108 includes a system area 10 and a user area 11. A system program 95, a user area management program Pg1, and a system setting file 96 are stored in the system area 10. The system program 95 includes an OS (Operating System) program and a user area management program Pg1. The system program 95 provides a program execution environment for a user program 97 stored in the user area 11 to operate.
[0039] The user area 11 stores a user program 97, a user setting file 98, and a user variable 99. The user program 97 is a program created by the vendor of the control device 100 according to the manufacturing device or facility to be controlled, and in which instructions for controlling the controlled device are specified. The user setting file 98 includes an online password Pw2. The user variable 99 includes a value indicating a backup / restore instruction. In addition, the user area 11 includes product recipe data, retained variables related to various processes, traceability data, data related to spooling (SQL queuing), logs related to the operation of the system and the device, error information, configuration information in the system (unit / slave settings), security information (account information, certificates, and access control), values of memory for units, and absolute value encoders. An end user can create desired data in the user area 11 based on the end user's knowledge, experience, and arrangements by using a setting tool such as the support device 200. In other words, the user area 11 can include data as an information asset that reflects the end user's unique expertise.
[0040] The chipset 104 mediates data exchange between the processor 102 and each component, thereby realizing processing of the control device 100 as a whole. The chipset 104 includes a plurality of chips mounted on a board. The plurality of chips includes a secure chip 105. The secure chip 105 includes a non-volatile memory 107. The memory 107 includes a secure area 12. A secure area management program Pg2, a common key Kc1, and a vendor password Pw1 are stored in the secure area 12.
[0041] The processor 102 includes, for example, a CPU (Central Processing Unit) or a GPU (Graphical Processing Unit), etc. The processor 102 reads out various programs stored in the secondary storage device 108 or the memory 107, and deploys and executes the programs in the main storage device 106 to realize various processes including control calculations and service processes.
[0042] The main memory device 106 includes a volatile memory device such as a dynamic random access memory (DRAM) or a static random access memory (SRAM).
[0043] The upper network controller 110 controls data exchange with external devices (for example, the server device 300 and the display device 400 shown in FIG. 1) via the upper network 60. The field network controller 116 controls data exchange with the field devices 500 via the field network 20. Each of the upper network controller 110 and the field network controller 116 may employ an industrial network protocol such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), DeviceNet (registered trademark), or CompoNet (registered trademark).
[0044] The support device interface 112 controls the exchange of data with the support device 200, for example, via a Universal Serial Bus (USB) connection or by EtherNet communication.
[0045] Memory card interface 114 is configured to allow memory card 115 to be attached / detached, and is configured to allow writing of user programs or data such as various settings to memory card 115. Memory card interface 114 is also configured to allow reading of the programs or data such as various settings from memory card 115.
[0046] The internal bus controller 120 controls data exchange with an I / O (Input / Output) unit 122 attached to the control device 100. The internal bus controller 120 may use a communication protocol specific to the PLC manufacturer, or may use a communication protocol that is the same as or conforms to any industrial network protocol.
[0047] The indicator 124 notifies the operation state of the control device 100. The indicator 124 is configured with at least one LED (Light Emitting Diode) or the like arranged on the surface of the control device 100.
[0048] The DIP switch 126 is connected to the chipset 104 via the DIP switch interface 125. The DIP switch 126 includes a plurality of switches Sw1, Sw2, Sw3, and Sw4. Each of the plurality of switches Sw1 to Sw4 selectively switches its state between ON and OFF. The start-up mode of the control device 100 is switched by a combination of the plurality of switches Sw1 to Sw4 switched ON or OFF. The start-up mode includes a normal mode, a backup mode, and a restore mode. In FIG. 3, all of the switches Sw1 to Sw4 are switched ON, and the start-up mode specified by the DIP switch 126 is the normal mode. In the backup mode, for example, the switches Sw1 and Sw3 are switched ON, and the switches Sw2 and Sw4 are switched OFF. In the restore mode, for example, the switches Sw1 and Sw3 are switched OFF, and the switches Sw2 and Sw4 are switched ON.
[0049] The power supply switch 128 is connected to the chipset 104 via a power supply switch interface 127. The power supply switch 128 switches between starting and stopping the supply of power from a power source (not shown) to the control device 100. When the power supply switch 128 is pressed for a predetermined time while no power is being supplied to the control device 100 from the power source, the control device 100 is started in the start-up mode specified by the DIP switch 126.
[0050] The secondary storage device 108 and the memory 107 of the secure chip 105 correspond to the storage unit 1 in Fig. 1. The processor 102 that executes the user area management program Pg1 corresponds to the user area management unit 2 in Fig. 1. The processor 102 that executes the secure area management program Pg2 corresponds to the secure area management unit 3 in Fig. 1. Note that the memory 107 and the secondary storage device 108 may be formed as a single storage device rather than separate storage devices. Also, the user area management program Pg1 and the secure area management program Pg2 may be created as a single program rather than separate programs.
[0051] 3 shows an example of a hardware configuration of the control device 100 in which the necessary functions are provided by the processor 102 executing a program. Some or all of the functions may be implemented using a dedicated hardware circuit (for example, an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array)). Alternatively, the main part of the control device 100 may be realized using hardware that conforms to a general-purpose architecture (for example, an industrial PC based on a general-purpose PC). In this case, a virtualization technique may be used to run multiple OSs with different uses in parallel, and necessary applications may be run on each OS.
[0052] <Hardware configuration of the support device> Fig. 4 is a schematic diagram showing an example of the hardware configuration of the support device 200 in Fig. 2. As an example, the support device 200 is realized by a computer that conforms to a general-purpose architecture executing a program.
[0053] 4, the support device 200 includes a processor 202, a volatile memory 204, a non-volatile memory 206, a hard disk drive (HDD) 208, a display 250, a keyboard 210, a mouse 212, a memory card interface 214, and an external device interface 218. These components are connected to each other via a processor bus 220 so as to be able to communicate with each other.
[0054] The processor 202 is composed of a CPU, a GPU, etc., and realizes various processes by reading programs (for example, support program 230) stored in the non-volatile memory 206 and the HDD 208, expanding them in the volatile memory 204, and executing them.
[0055] In the support device 200, the processor 202 executes a predetermined program to provide functions necessary for the support device 200. Some or all of the functions may be implemented using a dedicated hardware circuit (for example, ASIC or FPGA).
[0056] The volatile memory 204 is composed of various volatile storage devices such as DRAM, SRAM, etc. The non-volatile memory 206 is composed of various non-volatile storage devices such as SSD.
[0057] In addition to an OS for realizing basic functions, the non-volatile memory 206 and the HDD 208 store a support program 230 for providing the functions of the support device 200. In the support device 200, the support program 230 is stored in the HDD 208. The support program 230 defines instructions for causing the computer to function as the support device 200.
[0058] The display 250 outputs processing results and the like from the processor 202. The keyboard 210 and mouse 212 receive user operations when the user creates various programs such as a user program, or when the user inputs setting values and the like according to the object to be controlled.
[0059] The memory card interface 214 is configured so that the memory card 115 can be attached and detached, and various data (such as a user program) can be written to the memory card 115 and various data can be read from the memory card 115 .
[0060] The external device interface 218 transmits and receives data to and from any external device, such as the control device 100, via the network.
[0061] Although not shown in the figure, the support device 200 may be equipped with an optical drive, and a program (such as a support program) stored in an optical recording medium such as a DVD (Digital Versatile Disc) that non-transiently stores a computer-readable program is read and installed in the non-volatile memory 206 or the HDD 208, etc.
[0062] The support program 230 executed in the support device 200 may be installed via a computer-readable DVD, or may be installed by downloading from a server device 300 on a network. The functions provided by the support device 200 may also be realized by utilizing some of the modules provided by the OS.
[0063] FIG. 5 is a diagram showing each phase in which update data is input to the control device 100 and the phase in which update data is output from the control device 100. As shown in FIG. 5, the vendor Uv acquires the PLC 90 from the PLC manufacturer and produces the control device 100. An example of the vendor Uv is a system integrator called an SIer. The vendor Uv sets up the control device 100 using the support device 200A. Specifically, the vendor Uv installs a system program in the system area 10 of the control device 100. The vendor Uv installs the first version of the user program in the user area 11 of the control device 100. The vendor Uv installs the secure area management program Pg2 in the secure area 12 of the control device 100. The vendor Uv sets the vendor password Pw1 and stores it in the secure area 12, and also stores the common key Kc1 in the secure area 12.
[0064] Fig. 6 is a diagram showing an example of a password setting dialog displayed on the screen of the support device 200A by the secure area management unit 3 of Fig. 1 when the support device 200A enables the backup / restore key management in the control device 100. "Backup" means duplicating data stored in the user area 11 of the control device 100 as backup data (update data). "Restore" means updating the user area of the control device 100 using the backup data. "Backup / restore key management" means encrypting the backup data with a common key in the backup and decrypting the encrypted backup data with the common key in the restore.
[0065] As shown in FIG. 6, the password setting dialog Dg1 includes edit boxes Eb1 and Eb2, an OK button, and a cancel button. The vendor Uv inputs a character string that the vendor Uv desires to set as the vendor password Pw1 into each of the edit boxes Eb1 and Eb2. When the OK button is pressed and the character string input into the edit box Eb1 matches the character string input into the edit box Eb2, the secure area management unit 3 sets the character string input into the edit box Eb1 as the vendor password Pw1 and stores the character string in the secure area 12. The vendor password Pw1 is managed by the vendor Uv as a character string unique to the end user who purchases the control device 100. The vendor password Pw1 is kept secret from the end user Ue. As a result, the end user Ue cannot know the contents of the common key Kc1 unless he is permitted to access the secure area 12. In order to reduce the risk of the vendor password Pw1 being deciphered, it is desirable that the password unique to the end user be changed every time a certain period of time (for example, the production year of the control device 100) elapses.
[0066] 7 is a diagram showing an example of an authentication dialog displayed by the secure area management unit 3 on the screen of the support device 200A when the vendor password Pw1 is set and access to the secure area 12 from a device other than the control device 100 is detected. As shown in FIG. 7, the authentication dialog Dg2 includes an edit box Eb3, an OK button, and a cancel button. When the OK button is pressed and the character string entered in the edit box Eb3 matches the vendor password Pw1 stored in the secure area 12, the secure area management unit 3 permits access to the secure area 12. In order to prevent the vendor password from being identified by multiple attempts to enter a password in the edit box Eb3, it is desirable to prohibit authentication of access to the secure area 12 for a predetermined time interval (e.g., 10 minutes) when password authentication has failed a predetermined number of times.
[0067] FIG. 8 is a diagram showing an example of a common key setting dialogue displayed on the screen of the support device 200A by the secure area management unit 3 when access to the secure area 12 is permitted. As shown in FIG. 8, the common key setting dialogue Dg3 includes a check box Cb, an edit box Eb4, a transfer button, and a cancel button. When the check box Cb is checked, the name of a file including the value of the common key Kc1 is input in the edit box Eb4, and the transfer button is pressed, the secure area management unit 3 transfers the file from the support device 200A to the control device 100 and stores it in the secure area 12. The file is created by a dedicated tool (not shown). It is desirable that the common key Kc1 has a value unique to the end user Ue (a specific user) who purchases the control device 100. As a result, the encrypted backup data is prevented from being decrypted in a control device produced for another end user, so that the information assets of the end user Ue included in the user area 11 can be prevented from being leaked to the other end user.
[0068] Fig. 9 is a flowchart showing the flow of vendor password setting processing performed by the secure area management unit 3 of Fig. 1 when backup / restore key management is enabled by the vendor Uv of Fig. 5. Below, steps are simply abbreviated as S. As shown in Fig. 9, the secure area management unit 3 performs vendor password setting processing in S101 and proceeds to processing in S102. In S102, the secure area management unit 3 stores the vendor password in the secure area 12 and ends the vendor password setting processing.
[0069] Fig. 10 is a flowchart showing the flow of the common key setting process performed by the secure area management unit 3 of Fig. 1. As shown in Fig. 10, the secure area management unit 3 determines whether or not authentication of access to the secure area 12 has been successful in S111. If authentication of access to the secure area 12 has been successful (YES in S111), the secure area management unit 3 stores the common key in the secure area 12 in S112 and terminates the process. If authentication of access to the secure area 12 has failed (NO in S111), the secure area management unit 3 prohibits authentication of access to the secure area 12 for a predetermined time and then terminates the process.
[0070] 5, the end user Ue who has acquired the control device 100 from the vendor Uv generates backup data Db3 (update data) in case the control device 100 breaks down. The backup data Db3 is encrypted by a common key Kc1. The backup data Db3 may be output to the support device 200B in response to a backup instruction from the support device 200B of the end user Ue, or may be output to a storage medium (e.g., memory card 115) attached to the memory card interface 114 when a backup mode is selected by the DIP switch 126.
[0071] When the control device 100 breaks down, the end user Ue acquires the control device 100_1 in which the common key Kc1 is stored from the vendor Uv, and reproduces the user area 11 of the control device 100 in the user area 11 of the control device 100_1 using the backup data Db3. In the control device 100_1, the encrypted backup data Db3 is decrypted using the common key Kc1 and restored in the user area 11.
[0072] The backup data Db3 cannot be decrypted in a control device that does not store the common key Kc1, even if the control device is manufactured by the vendor Uv. For example, a common key Kc2 different from the common key Kc1 is stored in the control device 100_2 manufactured for an end user different from the end user Ue, so the backup data Db3 encrypted with the common key Kc1 cannot be decrypted in the control device 100_2. In addition, a common key is not stored in the control device 900 manufactured by a vendor different from the vendor Uv, so the encrypted backup data Db3 cannot be decrypted in the control device 900.
[0073] Since the backup data Db3 is encrypted by the common key Kc1, the end user Ue can replace the failed control device 100 with the control device 100_1 in which the backup data Db3 is copied, thereby preventing a decrease in productivity. In addition, the vendor Uv can limit the devices that can copy the data stored in the user area 11 of the control device 100 to those produced by the vendor Uv. Therefore, the opportunity for the vendor Uv to obtain the price of the control device from the end user Ue can be protected. Furthermore, when the data in the user area 11 is output to the outside of the control device 100, the data is encrypted by the common key Kc1, so that the data cannot be decrypted in a device in which the common key Kc1 is not stored. Therefore, it is possible to prevent the information assets of the end user Ue and the vendor Uv contained in the user area 11 from being illegally obtained by a third party.
[0074] FIG. 11 is a flowchart showing the flow of the backup process performed by the user area management unit 2 of FIG. 1. As shown in FIG. 11, the user area management unit 2 judges in S121 whether or not a common key is stored in the secure area 12. If the common key is stored in the secure area 12 (YES in S121), the user area management unit 2 encrypts the data of the user area 11 using the common key in S122 and advances the process to S123. In S123, the user area management unit 2 outputs the encrypted backup data to the support device 200B connected to the control device 100 or the memory card 115 attached to the memory card interface 114, and ends the backup process. If the common key is not stored in the secure area 12 (NO in S121), the user area management unit 2 performs error processing in S124 and ends the backup process. The error processing includes, for example, outputting a message indicating that the common key is not stored to the support device 200B, or turning on the indicator 124 in a manner indicating that the common key is not stored.
[0075] Referring again to FIG. 5, the vendor Uv provides the end user Ue with the modified user program as an update program Pgu1 (update data). The update program Pgu1 is encrypted by a common key Kc1. The encryption of the update program Pgu1 may be performed in the support device 200A or in another device. The end user Ue updates the user program 97 of the control device 100 using the update program Pgu1 after authentication using the online password Pw2. The authentication using the online password Pw2 can prevent the user area 11 from being illegally updated. The update program Pgu1 may be input to the control device 100 from the support device 200B of the end user Ue in response to a restore instruction from the support device 200B, or may be input to the control device 100 from the memory card 115 that is attached to the memory card interface 114 and in which the update program Pgu1 is stored, when the restore mode is selected by the DIP switch 126.
[0076] Because the update program Pgu1 is encrypted with the common key Kc1, it is possible to prevent the update program Pgu2 created by an unauthorized third party Ut from being installed in the control device 100. Even if the update program Pgu2 is encrypted with the common key Kc3, it is possible to prevent the encrypted update program Pgu2 from being installed in the control device 100 unless the common key Kc3 matches Kc1.
[0077] Fig. 12 is a flowchart showing the flow of the restore process performed by the user area management unit 2 of Fig. 1. As shown in Fig. 12, the user area management unit 2 determines whether or not the authentication of the access to the user area 11 has been successful in S131.
[0078] If the authentication of the access to the user area 11 fails (NO in S131), the user area management unit 2 advances the process to S136. If the authentication of the access to the user area 11 succeeds (YES in S131), the user area management unit 2 determines whether or not the common key is stored in the secure area 12 in S132.
[0079] If the common key is not stored in the secure area 12 (NO in S132), the user area management unit 2 advances the process to S136. If the common key is stored in the secure area 12 (YES in S132), the user area management unit 2 performs a decryption process on the update data in S133 and advances the process to S134.
[0080] The user area management unit 2 determines whether the decryption process for the update data is successful in S134. If the decryption process for the update data is unsuccessful (NO in S134), the user area management unit 2 advances the process to S136. If the decryption process for the update data is successful (YES in S134), the user area management unit 2 updates the user area 11 of the control device 100 using the decrypted update data in S135, and ends the restore process.
[0081] In S136, the user area management unit 2 performs error processing and ends the restore processing. Errors when NO in S131 include failure of authentication using the online password Pw2. Errors when NO in S132 include a case where a common key is not stored in the secure area 12. Errors when NO in S134 include a case where the common key stored in the secure area 12 does not match the common key used to encrypt the update data, and a case where the update data is not encrypted. Error processing includes, for example, outputting a message corresponding to the content of the error to the support device 200B, or lighting the indicator 124 in a manner corresponding to the content of the error.
[0082] As described above, according to the device, program, and method of the embodiment, it is possible to prevent a decline in productivity of the end user of the control device while protecting the profits of the vendor of the control device.
[0083] <Additional Notes> The above-described embodiment includes the following technical idea.
[0084] (Configuration 1) A control device (100), A storage unit (1) including a first area (11) and a second area (12) in which a common key (Kc1) is stored; a first area management unit (2) that encrypts data stored in the first area (11) using the common key (Kc1) and outputs the encrypted data; a second area management unit (3) that authenticates access to the second area (12) from a device different from the control device (100) by using a first password (Pw1); The first area management unit (2) decrypts the update data (Db2) encrypted using the common key (Kc1) using the common key (Kc1), and performs the above operation using the decrypted update data (Db2). 1 region( 11 ) is updated by the control device (100).
[0085] (Configuration 2) The first area (11) stores a second password (Pw2), The control device (100) according to configuration 1, wherein the first area management unit (2) authenticates the update using the second password (Pw2).
[0086] (Configuration 3) The control device (100) according to configuration 1 or 2, wherein the common key (Kc1) has a value unique to a particular user (Ue) associated with the control device (100).
[0087] (Configuration 4) A program (Pg1, Pg2) for managing input and output of data stored in a memory unit (1) of a control device (100) including a first area (11) and a second area (12), The programs (Pg1, Pg2) are executed by the processor (102) to authenticating access to the second area (12) from a device other than the control device (100) using a password (Pw1); A common key (Kc1) is stored in the second area (12); encrypting the data stored in the first area (11) using the common key (Kc1) and outputting the encrypted data; The update data (Db2) encrypted using the common key (Kc1) is decrypted using the common key (Kc1), and the decrypted update data (Db2) is used to 1 Program (Pg1, Pg2) updates area (11).
[0088] (Configuration 5) A method for managing input and output of data stored in a memory unit (1) of a control device (100) including a first area (11) and a second area (12), comprising: a step (S111) of authenticating access to the second area (12) from a device other than the control device (100) using a password (Pw1); A step (S112) of storing a common key (Kc1) in the second area (12); a step (S122, S123) of encrypting the data stored in the first area (11) using the common key (Kc1) and outputting the encrypted data; The update data (Db2) encrypted using the common key (Kc1) is decrypted using the common key (Kc1), and the decrypted update data (Db2) is used to 1 and updating the area (S133 to S135).
[0089] The embodiments disclosed herein should be considered to be illustrative and not restrictive in all respects. The scope of the present invention is defined by the claims, not the above description, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0090] 1 memory unit, 2 user area management unit, 3 secure area management unit, 10 system area, 11 user area, 12 secure area, 20 field network, 60 upper network, 95 system program, 96 system setting file, 97 user program, 98 user setting file, 99 user variable, 100, 100_1, 100_2, 900 control device, 102, 202 processor, 104 chip set, 105 secure chip, 106 main memory device, 107 memory, 108 secondary memory device, 110 upper network controller, 112 support device interface, 114, 214 memory card interface, 115 memory card, 116 field network controller, 120 internal bus controller, 122 I / O unit, 124 indicator, 125 switch interface, 126 DIP switch, Sw1 to Sw4 switch, 127 power supply switch interface, 128 Power supply switch, 200, 200A, 200B support device, 204 volatile memory, 206 non-volatile memory, 210 keyboard, 212 mouse, 218 external device interface, 220 processor bus, 230 support program, 250 display, 300 server device, 400 display device, 500 field device, 520 servo driver, 522 servo motor, 700 gateway, 1000 control system, Db1, Db2 update data, Db3 backup data, Kc1 to Kc3 common key, Pg1 user area management program, Pg2 secure area management program, Pgu1, Pgu2 update program, Pw1 vendor password, Pw2 online password.
Claims
1. A control device for controlling an external control target, A storage unit including a first area in which data relating to the control target is stored and a second area in which a common key is stored; a first area management unit that encrypts the data stored in the first area using the common key and outputs the encrypted data; a second area management unit that authenticates access to the second area from a device different from the control device by using a first password; The control device controls the external control target via a bus or a network that performs periodic communication; The first area management unit decrypts update data encrypted using the common key using the common key, and updates the first area using the decrypted update data.
2. A second password is stored in the first area; The control device according to claim 1 , wherein the first area management unit authenticates the update using the second password.
3. The control device of claim 1 or 2, wherein the common key has a value that is unique to a particular user associated with the control device.
4. A program for managing input and output of data stored in a storage unit of a control device, the program including a first area and a second area, The control device controls an external control target, The first area stores data related to the control object, The control device controls the external control target via a bus or a network that performs periodic communication; The program is executed by a processor, authenticating access to the second area from a device different from the control device using a password; storing a common key in the second area; encrypting the data stored in the first area using the common key and outputting the encrypted data; a program for decrypting update data encrypted using the common key using the common key, and updating the first area using the decrypted update data.
5. A method for managing input and output of data stored in a storage unit of a control device, the method comprising: The control device controls an external control target, The first area stores data related to the control object, The control device controls the external control target via a bus or a network that performs periodic communication, and the method includes: authenticating access to the second area from a device different from the control device using a password; storing a common key in the second area; encrypting the data stored in the first area using the common key and outputting the encrypted data; decrypting update data encrypted with the common key using the common key, and updating the first area using the decrypted update data.
Citation Information
Patent Citations
Decryption backup method, decryption restoration method, attestation device, individual key setting machine, user terminal, backup equipment, encryption backup program, decryption restoration program
JP2007020065A
Control system of equipment, control apparatus, and protection method of program
JP2008065678A
Control system, security apparatus and method
JP2020166317A
Programmable logic controller, and method of storing password for programmable logic controller
WO2012111117A1