A method for safely transitioning the product life cycle stages to the next stage through a forward-only life cycle and verifying the integrity of data and product status

The Merkle tree-based data structure with cryptographic hash functions addresses the issue of maintaining data confidentiality and preventing reverse transitions in product life cycles, ensuring secure and authorized transitions.

JP7714791B2Active Publication Date: 2025-07-29コンチネンタル·オートモーティヴ·テクノロジーズ·ゲゼルシャフト·ミト·ベシュレンクテル·ハフツング
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024519403
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-09-29
Filing Date
2022-09-20
Publication Date
2025-07-29
Estimated Expiration
2042-09-20

AI Technical Summary

Technical Problem

Existing technologies fail to ensure that confidential data in products is kept secret from unauthorized entities and prevent reverse transitions during the product's life cycle, compromising security and safety.

Method used

A Merkle tree-based data structure with hash values and a control hash value ensures the integrity and secure transition of data through life cycle stages, using cryptographic hash functions to verify the current stage and prevent backward transitions.

Benefits of technology

The solution securely verifies the current life cycle stage without revealing confidential data, ensuring data integrity and preventing unauthorized access, thus enhancing security and safety throughout the product's life cycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007714791000001
    Figure 0007714791000001
  • Figure 0007714791000002
    Figure 0007714791000002
  • Figure 0007714791000003
    Figure 0007714791000003
Patent Text Reader

Abstract

A lifecycle certificate implementing a Merkle tree-based data structure allows for validating a current lifecycle stage and for securely transitioning a first component or product to a next lifecycle stage in a forward-only manner. The lifecycle certificate includes a lifecycle index, a first level hash value or a reference thereto, at least one second level hash value or a reference thereto, a third level hash value, and a further third level hash value or a corresponding reference thereto. The third level hash value represents a hash of the corresponding secret data associated with each value of the lifecycle index. The lifecycle certificate further includes a control hash value, which is a hash value of the concatenation of all other components of the data structure. The method for forward-only transitioning a product's lifecycle stage uses the lifecycle certificate and a unique property of the Merkle tree-based data structure to prevent transition to a previous lifecycle stage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a product or component that stores data, which may change during forward transitions through various stages of the product's life cycle. In particular, the present invention relates to ensuring and verifying that the stored data corresponds to the corresponding stage of the life cycle and that reverse transitions to previous life cycle stages are prevented and / or at least detectable.

Background Art

[0002] In various technical fields, a product or component stores data that changes during forward transitions through various stages of the product's life cycle. Such a component or product can generally communicate with an external entity via a communication interface, either directly or via an interface provided and / or shared by another component or product. The life cycle of a component or product can include stages such as production, customer acceptance, OEM production, field application (also called post-sale use), and failure analysis or end-of-life analysis. End-of-life analysis can include general analysis to learn how a product or component was used throughout its life, and failure analysis can be relevant, for example, when a product or component fails before its normal end of life. However, since end-of-life analysis and failure analysis are sufficiently similar, both terms can be used interchangeably.

[0003] In the following description, the terms "component" or "product" are used interchangeably since they can comprise one or more components that store data that changes during transitions between the life cycle stages of a product.

[0004] The data to be stored can only be used during each stage of the life cycle and can further be confidential data that is only used by entities authorized during each stage. Such confidential data may include data required for testing or executing security functions or features, such as encryption keys, access authentication information, etc.

[0005] To ensure the proper operation of a component or product, it may be obvious that some tests of such functions that depend on or use confidential data should be executed during the production of the component or product. Similarly, after a product or component is received by an OEM manufacturer and before it is implemented in another product sold to a customer, some tests may be executed. Also, the advanced test capabilities and diagnostic capabilities of a product or component may only be available for end-of-life analysis, and then the product or component should not be returned to normal service. However, if such confidential data is available to too many entities during the life cycle of a product or component, it may not be compatible with the goal of keeping the confidential data secret.

[0006] For example, any confidential data that can be used during the production of a component can be accessed by the component manufacturer but should not be passed to the customer. Reading of such confidential data is prevented by the security mechanism implemented in the component, and once the component is received, such confidential data can be replaced with customer confidential data.

[0007] Customers may use the component for the development of more complex and further products that include or implement the component. Similarly, in this case, some tests of the component in the context of the more complex and further products may require the use of appropriate confidential data. Once the development of the more complex and further products is completed and either the customer or a third party, such as an OEM manufacturer, is ready for production, the confidential data in the component will be replaced by corresponding data adapted for testing during the production of the more complex and further products. Therefore, when the more complex and further products are received in the production facility, the confidential data may be replaced by the OEM manufacturer's confidential data.

[0008] Once the more complex and further products are produced and ready for sale to users or, broadly speaking, ready for use in the field, the confidential data necessary to operate the more complex and further products that include or implement the component may be stored in the component. The operation may include field tests and field diagnostics. The storage of the confidential data for field use may be performed by the user or by the producer at the request of the user.

[0009] Finally, at the end of the product's life cycle, in a mode that provides access to more advanced tests and diagnostics, the confidential data for operating the more complex and further products may be replaced by the confidential data for field use. This may be limited to, for example, trusted and authorized entities because such advanced tests and diagnostics may reveal confidential information from previous stages.

[0010] From the above examples, since reselling a used or otherwise leaked product can be dangerous in security or safety-related applications, it is clear that the confidential data at each stage should be kept secret from other parties controlling during other stages and that going back to previous stages should be prevented. Preventing going back to previous stages of the product life cycle is hereinafter referred to as a forward-only life cycle.

[0011] The object of the present invention is to provide a data structure that enables verification of the current life cycle stage and safe transition of the product life cycle stage to the next life cycle stage only in the forward direction. A further object of the present invention is to provide a method for safely transitioning the life cycle stage and a method for ensuring and verifying the integrity of data and device status through various life cycle stages of the product's forward-only life cycle.

Summary of the Invention

Means for Solving the Problems

[0012] These objects are achieved by the data structure of claim 1 and the methods of claims 3, 4, and 6. Advantageous embodiments and developments of the data structure and the methods are indicated in the respective dependent claims.

[0013] According to a first aspect of the present invention, a Merkle tree-based data structure for verifying the current life cycle stage and for safely transitioning the product life cycle stage to the next life cycle stage only in the forward direction includes a life cycle stage index field, a first-level hash value or a reference value to the first-level hash value, at least one second-level hash value or a reference value to at least one second-level hash value, a third-level hash value, a further third-level hash value or a reference value corresponding to the latter, and a control hash value. The control hash value is a hash value of the concatenation of the index field, the first-level hash value or its reference value, at least one second-level hash value or its reference value, the third-level hash value and the further third-level hash value or its reference value. The control hash value prevents any manipulation of the individual fields of the data structure and guarantees its integrity.

[0014] An exemplary Merkle tree (hash tree) showing the relationship of some elements of a data structure to the nodes of the Merkle tree is shown in FIG. 1. The leaf nodes of the Merkle tree, in this data structure, the hash values H0-0, H0-1, H1-0, H1-1, H2-0, and H2-1 at the third level include the hash values #(D0) to #(D5) of the corresponding data blocks D0 to D5. The data blocks D0 to D5 may store confidential data related to different life cycle stages of a product, represented by an index i, such as operating software and / or parameters, access authentication information, encryption keys, secrets, signatures, etc. The life cycle stages may correspond to, for example, a device production stage, an OEM customer delivery stage, such as when the device is incorporated into a product, an OEM production stage, a field application stage, or a usage stage, a failure analysis stage, and further stages.

[0015] The hash values H0, H1, H2 at the second level, which are non-leaf node hash values, each include the hash values of the hash values H0-0, H0-1, H1-0, H1-1, H2-0, and H2-1 at the third level to which they are connected. In FIG. 1, the hash value H0 at the second level includes the hash values of the hash values H0-0 and H0-1 at the third level, the hash value H1 at the second level includes the hash values of the hash values H1-0 and H1-1 at the third level, and the hash value H2 at the second level includes the hash values of the hash values H2-0 and H2-1 at the third level. The hash value H at the first level includes the hash values of the hash values H0, H1, and H3 at the second level.

[0016] The index field i of the data structure represents the index of the life cycle stage. The data structure may also include a field for additional data. In this case, the concatenation of various fields for determining the control hash value includes the field for additional data.

[0017] Figure 2 shows an exemplary data structure of a preferred embodiment of the present invention. This data structure includes various fields and hash values in the following order, namely, index field i, field of additional information or data, second-level hash value H0, third-level hash value for index i = 2, further third-level hash value or its reference value for index i = 3, second-level hash value H2, first-level hash value, and finally control hash value. As can be easily seen, the second-level hash value H1 including the third-level hash value related to the current life cycle stage is replaced by the third-level hash value of the current life cycle stage and the third-level hash value or its reference value of the next life cycle stage. Generally, the second-level hash value or its reference value is provided and arranged in ascending order unless it is replaced by the underlying third-level hash value or its reference value. However, other predetermined orders may also be used. Note that the exemplary data structure shown in Figure 2 corresponds to a life cycle certificate transmitted by the product after the transition from life cycle stage index 1 to life cycle stage index 2.

[0018] The various fields and hash values of the data structure may be separated by a predetermined character or code, or may have a predetermined length, whereby padding with default data may be performed if the entire space provided with the actual content is not used.

[0019] The hash value can be determined according to a secure hash algorithm, such as SHA-256, SHA-512, or SHAKE hash function. However, other hash functions for calculating an encrypted hash value with a width of at least 128 bits, including the Davies-Meyer hash operation combined with AES-128, such as a hash operation based on a special operation mode of a symmetric block cipher or a stream cipher, may also be used.

[0020] If the data structure includes actual hash values, all information necessary for verification or transition is included in the message.

[0021] However, when a reference value to a hash value and the actual hash value are provided in a data structure, the data structure rather provides the correct path through the Merkle tree. The hash values that are only referenced in the data structure need to be obtained from other sources or can be determined based on data that is known to the verification entity. Thus, the data structure provides, respectively, some information or representation of information that is currently available in the product or, otherwise, information indicating what additional data is required for verification. This data can be obtained from entities related to other life cycle stages. Since the information required does not include actual confidential data but only its hash, this information can be provided through a relatively insecure channel. The validity of the complementary data can always be verified against a first-level hash that can be stored in the product and provided from the product itself, which is considered a trustworthy source. Embodiments of the present invention that use this type of content in a data structure need to provide information missing by various different entities authorized for other life cycle stages, so they can provide an additional security level with additional communication and additional authentication checks.

[0022] In order to transition from one life cycle stage to the next, for example, from the life cycle stage with index 1 to the next life cycle stage with index 2, for example, from the OEM customer supply stage to the OEM production stage, it may be necessary for the confidential data stored in the components for OEM supply and testing to be replaced by the data necessary for integration into the OEM product. Such replacement is usually done along with the transition of the life cycle stage. Further, as described above, it is preferably not possible to return the product to a previous life cycle stage. The memory of the product usually cannot and need not permanently store all types of data that can be used through different life cycle stages, but rather stores only the data required in the current life cycle stage. Thus, ideally, in a way that is secure against tampering and does not reveal any information that can be used for reverse engineering of the data, the product must provide some evidence that it is or was in a particular life cycle stage. This evidence may be provided by the product itself using a data structure, thereby eliminating the need to maintain a record in some locations external to the product.

[0023] It is well known that a special form of hash function belonging to a group of cryptographic hash functions can generate a unique and unambiguous representation of a large amount of data, which occupies only a relatively small memory space and does not permit the identification or determination of the data on which the representation is based. Thus, by retaining only the small-size hash value of the life cycle stage data in the product's memory, while using the main part of the memory for the data related to the current life cycle stage, a unique and unambiguous evidence is retained that indicates that the confidential data of the previous life cycle stage was previously stored in the product, ultimately making it possible to show that the product was in that life cycle stage.

[0024] Such cryptographic hash values can be calculated with relatively little effort, but are considered impossible to reconstruct the underlying data from the hash value, which is why such special hash functions are considered resistant to quantum computer-based attacks.

[0025] In a second aspect of the present invention, a method for verifying the current lifecycle stage of a product in a requesting entity, for example, before transitioning to the next lifecycle stage, includes sending a request to the product asking for the provision of the current lifecycle stage. The method further includes receiving from the product the current lifecycle stage and a lifecycle certificate implementing the data structure according to the present invention, reconstructing a path through the Merkle tree based on the hash values or reference values thereof at the first, second, and third levels provided in the lifecycle certificate, determining the corresponding lifecycle stage index, and verifying whether the received provided lifecycle stage index matches the determined lifecycle stage index. If the received lifecycle index matches the lifecycle index determined from the other information provided in the lifecycle certificate, the current lifecycle stage is verified.

[0026] The requesting entity in this context may be any device that is at least temporarily communicatively connected to the product. The communication connection may be wired or wireless and may use any suitable communication protocol. Similarly, the communication between the requesting entity and the product may be direct or via an intermediate communication node.

[0027] The lifecycle stage index and the lifecycle certificate may be obtained from the product's memory or may be generated based on data stored in the product's memory in response to a request. In the former case, the lifecycle certificate has been previously generated and stored.

[0028] If the requesting entity is an entity related to the current life cycle stage, in order to determine the control hash value, all the information provided in the life cycle certificate except the index field of the current life cycle stage and the third-level hash value can be used. The index is replaced with the index received in response to the request, and the third-level hash value related to the current life cycle stage provided in the received life cycle certificate is replaced with the hash value of the confidential data that the requesting entity knows should be stored in the product. The hash value of the known confidential data is determined by the requesting entity. If the control hash provided in the life cycle certificate matches, i.e., is equal to, the control hash determined by the requesting entity, the life cycle stage reported by the product is valid. Otherwise, the reported life cycle stage is invalid, and the product may not be usable at the current life cycle stage or may be defective and may need to be discarded.

[0029] Therefore, if the requesting entity is an entity related to the next life cycle stage, in order to determine the control hash value, all the information provided in the life cycle certificate except the index field of the next life cycle stage and the third-level hash value can be used. The index is replaced with the index received in response to the request, and the third-level hash value related to the next life cycle stage provided in the received life cycle certificate is replaced with the hash value of the confidential data that the requesting entity knows will be or should be stored in the product at the next life cycle stage. If the control hash provided in the life cycle certificate matches the control hash determined by the requesting entity, the life cycle stage reported by the product is valid. Otherwise, the reported life cycle stage is invalid, and the product may not be able to transition to the next life cycle stage or may be defective and may need to be discarded.

[0030] Only hash values or information known to each requester entity are used, so the information provided in the data structure enables the current life cycle stage to be securely verified without revealing or having knowledge of the confidential data of other life cycle stages.

[0031] Alternatively, in the requester entity, to determine the control hash, all data from the received life cycle certificate except for the life cycle stage to be replaced with the life cycle stage received in response to the request may be used to compare the control hash with the life cycle stage from the received life cycle certificate. This reveals any tampering where malicious software or an intermediary sends a life cycle stage and adds a certificate received from the product.

[0032] According to a third aspect of the present invention, a method for migrating a product from the current life cycle stage to the next life cycle stage includes receiving, at the product from the requester entity, a request to provide the current life cycle stage. In response to the request, the product provides the current life cycle stage, as well as a life cycle certificate implementing the data structure according to the first aspect of the present invention, to the requester entity.

[0033] As described above, the life cycle stage and the data structure may be obtained from the product's memory or may be generated based on data stored in the product's memory in response to a request. In the former case, the data structure has been previously generated and stored. If the life cycle certificate includes any actual third-level hash values other than the current life cycle stage, all at least third-level hash values except the current life cycle stage need to be stored in the product, thereby enabling the determination of second-level and first-level hash values in the product. However, it is also possible to store all hash values in the components or the product. If the life cycle certificate includes reference values to various hash values, only the appropriate reference values need to be stored in the product.

[0034] The requesting entity can use the information provided to verify the life cycle stage before continuing the transition, for example, as described above with reference to the method according to the second aspect of the present invention.

[0035] The method further includes receiving a request to transition the product to a target life cycle stage (usually a life cycle stage having a higher index than the current life cycle stage). The product verifies whether the target life cycle stage received in the request is higher than the current life cycle stage. If affirmative, i.e., if the target life cycle stage is higher than the current life cycle stage, the current life cycle certificate or information regarding the method of constructing or generating the current life cycle certificate is deleted, and the index counter representing the current life cycle stage is incremented to the index corresponding to the target life cycle stage.

[0036] The index counter can preferably be provided in a protected memory area that cannot be easily accessed through a communication interface. The protected memory can include OTP memory, i.e., memory where the content can be written only once. Similarly, the computer program instructions for incrementing the index counter are preferably stored in a protected memory area and executed from the protected memory area to prevent tampering.

[0037] Before or after incrementing the index counter, new confidential data for the target life cycle stage can be stored in the memory of the component. Further, information for generating a life cycle certificate for the new life cycle stage, i.e., the path through the Merkle tree on which the life cycle certificate is based, is determined, and a new life cycle certificate is generated. Then, the new life cycle certificate and the new current life cycle stage index are provided to the requesting entity.

[0038] If the target life cycle stage is not higher than the current life cycle stage, the request is ignored.

[0039] In one or more embodiments of the method, the requesting entity may determine the life cycle certificate of the target life cycle stage based on data from the life cycle certificate received before requesting the transition, the index of the target life cycle stage, and the confidential data of the target life cycle stage sent to the product, and verify whether the transition was successful by comparing the life cycle certificate received from the product after the transition with the previously determined one. If the two life cycle certificates are identical, the transition is completed successfully. In some cases, it may be sufficient to compare only the control hashes of the life cycle certificates, thereby reducing at least the processing amount required for the comparison. Thus, the requesting entity uses the information provided by the product regarding the life cycle stage before the request for the transition, as well as the information regarding the target life cycle stage known to the requesting entity, to predict the life cycle certificate expected after the transition is successful. The requesting entity may store the received life cycle certificate in association with the product for later use.

[0040] According to a fourth aspect of the present invention, a method for verifying the validity of a product's life cycle certificate includes receiving, from a requesting entity, a request to verify the life cycle certificate in a component. The request may include the life cycle certificate to be verified, or the life cycle certificate may be received in a separate transmission after the request is confirmed. The life cycle certificate to be verified is typically for the assumed current life cycle stage of the product. The product verifies whether the life cycle stage index of the life cycle certificate to be verified matches the current value of the life cycle stage index present in the product's index counter. If the result of the verification is positive, the product compares the life cycle certificate with the one stored in the device's memory or the one determined from the information stored in the product's memory according to the information for generating the life cycle certificate stored in the product. If the two life cycle certificates match, for example, are identical, the product responds with a message indicating that the life cycle certificate received for verification is valid. Otherwise, if either the index does not match the value of the index counter or the life cycle certificates are not equal, the product responds with a message indicating that the transmitted life cycle certificate is no longer valid. A life cycle certificate that is no longer valid may be invalidated.

[0041] In one or more embodiments of the method according to the present invention, the requesting entity may need to go through an authentication and / or authorization process before the product accepts the request. If the authentication or authorization fails, the request is ignored. To prevent brute force attacks against authentication or authorization, generally known mechanisms, such as increasing the delay time between attempts and / or the maximum allowable number of failed attempts for each user, may be employed.

[0042] A computer program product includes computer program instructions that, when executed by a computer, cause the computer to execute a method according to one of the methods according to the aspects of the present invention presented herein.

[0043] A computer program product can be stored on a computer-readable medium or data carrier. The medium or data carrier can be physically embodied, for example, in the form of a hard disk, a solid-state disk, a flash memory device, etc. However, the medium or data carrier can also comprise a modulated electromagnetic signal, an electrical signal, or an optical signal that is received by a computer using a corresponding receiver and transferred and stored in the memory of the computer.

[0044] Since the trusted source of the first-level hash value is the product itself, the present data structure and the present method using the data structure do not depend on an external key infrastructure and reduce possible attack vectors. In addition, this data structure enables local verification of the life cycle certificate without the need to access a remote database.

[0045] Hereinafter, the present invention will be described with reference to the following drawings.

Brief Description of the Drawings

[0046]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

[0047] In the drawings, identical or similar elements may be labeled with the same reference value indicators.

DETAILED DESCRIPTION OF THE INVENTION

[0048] Since FIGS. 1 and 2 have been further described above, they will not be described in detail again.

[0049] FIG. 3 shows a data structure according to the present invention, with the information that needs to be provided by the requester entity in order to effectively transition from life cycle index 1 to life cycle index 2. The information to be provided is shown in text boxes with solid line contours, and the information that does not need to be provided is represented by text boxes with dashed lines. Data D0... D5, which may represent signatures or other confidential data that form the basis of those hash values not belonging to the next life cycle index, need not be provided by the requester entity, or even need not be known to the requester entity.

[0050] In this example, the claimant entity is an entity related to the life cycle index 2. It may receive products from a supplier related to the life cycle index 1, where it stores its own confidential data in the product and is ready to trigger the transition to the life cycle index 2. For example, to ensure that the product is at the correct life cycle index, or at least a lower life cycle index than the target life cycle index, the claimant entity can first send a request to the product to inquire about the current life cycle index of the product. The product responds by sending the requested information together with the life cycle certificate of the current life cycle stage. From the received life cycle index and life cycle certificate, the claimant entity can determine what information it must provide to the product in the next step.

[0051] The first-level hash H is provided in the life cycle certificate. However, in order to be able to calculate the first-level hash H, the second-level hashes H0, H1, H2 must be known. Since they do not give any information about the confidential data they represent, they can be provided in the life cycle certificate or obtained through other channels. The validity of the second-level hashes can be verified by concatenating and hashing them and comparing the result with the first-level hash provided in the life cycle certificate. The source providing the second-level hashes that have passed the verification can be considered a reliable source.

[0052] Here, the claimant entity sends a request to transfer the life cycle index to the target life cycle index.

[0053] The request may include the confidential data related to the target life cycle index, or its hash value, along with the hash value H1-1 of the third level, and the hash values H0 and H2 of the second level. The hash value H1-1 can be provided to the requesting entity by an entity authorized for subsequent life cycle stages. Since it does not give any information about the underlying data, the confidential data from other authorized entities remains confidential.

[0054] The data received in the request enables the product to verify that the requesting entity is actually authorized to start the transition to a higher life cycle index. To verify, the product determines the hash value H1-0 of the third level from the received confidential data, or uses the hash value provided in the request, and determines the hash value H1 of the second level from the received or previously determined hash value H1-0 of the third level and the hash value H1-1 of the third level received in the request, and determines the hash value H of the first level from the previously determined hash value H1 of the second level and the hash values H0 and H2 of the second level received in the request. The hash value H of the first level thus determined is compared with the hash value of the first level stored in the product. If both hash values match, the request is legitimate and can be executed.

[0055] Figure 4 shows an exemplary flowchart of a method 200 for verifying the current life cycle stage of a component. This method includes, at step 202, sending a request to a product and requesting that the product provide its current life cycle stage, and at step 204, receiving the current life cycle stage and life cycle certificate as described with reference to FIG. 2. Next, the requesting entity verifies whether the life cycle stage index included in the received life cycle certificate matches the one provided in response to the request. In the affirmative case, the reported life cycle stage is verified; otherwise, the product may be defective and may need to be discarded. In the figure, this includes, at step 206, reconstructing the path through the Merkle tree and determining the corresponding life cycle stage index, and at step 208, verifying whether the received life cycle stage index matches the determined life cycle stage index.

[0056] Figure 5 shows an exemplary flowchart of a method 300 for safely transitioning the current life cycle stage of a product to a target life cycle stage in only the forward direction. At step 302, the product receives a request from the requesting entity to provide the current life cycle stage index (i c ). In response to the request, at step 304, the product provides the current life cycle stage index (i c ) and the life cycle certificate. The requesting entity can verify the information provided in the received data, for example, as described with reference to FIG. 4. Next, at step 306, the product receives a request to transition to the target life cycle stage. At step 308, the product verifies whether the target life cycle stage index (i t ) is higher than the current life cycle stage index (i c ). In the affirmative case, in the "yes" branch of step 308, the product sets the target life cycle index (i t ) received in the request as the current life cycle stage index (ic ) is set as, and in step 312, the product stores in the product new confidential data that replaces the confidential data related to the previous lifecycle stage index, and in step 314, generates and stores at least temporarily a hash value of the third level representing the new confidential data. In step 316, the product determines a path through the Merkle tree based on the information for generating a new lifecycle certificate, i.e., the data structure, and generates a new lifecycle certificate. In step 318, the product provides the new current lifecycle stage index (i c ) and the new lifecycle certificate to the requesting entity. If the target lifecycle stage index (i t ) is not higher than the current lifecycle stage index (i c ), the request is ignored in the "No" branch of step 308 and the process proceeds to step 320.

[0057] The requesting entity, in step 322, determines a lifecycle certificate based on the lifecycle stage index and lifecycle certificate received in response to the initial request, and the target lifecycle stage and the confidential data sent to the product, and in step 324, can compare the previously determined lifecycle certificate with the lifecycle certificate received from the product after the transition. If the lifecycle certificates are identical, the transition has been completed successfully. However, other ways to verify the success of the update are also possible, for example, by checking whether the hash value of the sent confidential data matches the hash value determined at the requesting entity and reported in the lifecycle certificate, and / or whether the path through the data structure sent in the lifecycle certificate is correct.

[0058] FIG. 6 shows an exemplary message flow diagram between a requesting entity RE and a product P when transitioning through life cycle stages according to the method described with reference to FIG. 5. Before performing the actual steps of the method, authentication and authorization may be performed, or more generally, an access control scheme 500 that may involve sending a challenge and receiving a response may be performed. If access is denied, the product P will reject any requests. The access control scheme may be optional and is shown only illustratively by a dashed line.

[0059] As described above, a request to provide the current life cycle stage index is sent to the product P, and the product P responds by providing the current life cycle stage index as well as the current life cycle certificate. Here, the requesting entity RE sends a request to the product P to execute steps 306 - 316, or 320, and further to transition to the target life cycle stage that provides the requesting entity RE with a new current life cycle stage index and a new life cycle certificate. Next, the requesting entity RE can perform steps 322 and 324 to check whether the transition was successful.

[0060] FIG. 7 shows an exemplary flow diagram of a method 400 for verifying the validity of a lifecycle certificate implementing the data structure according to the present invention. In step 402, the product P receives a request to verify a lifecycle certificate from the requester entity RE. If the lifecycle certificate to be verified is not received with the request, the request is received from the requester entity RE in another step 404. In step 406, the product P compares the lifecycle stage index included in the received lifecycle certificate with the current lifecycle stage index of the product P indicated by the lifecycle stage index counter provided in the product P. If the lifecycle stage indices are equal, in the "yes" branch of step 406, the product P, in step 408, compares the received lifecycle certificate with the lifecycle certificate obtained from the memory of the product P or the lifecycle certificate generated by the product P based on the information stored in the memory of the product P. If the lifecycle certificates are equal, in the "yes" branch of step 408, the product P responds to the requester entity RE that the lifecycle certificate is valid. Otherwise, that is, if the lifecycle stage index or the lifecycle certificate is not the same, the product P responds to the requester entity RE that the lifecycle certificate is invalid.

[0061] FIG. 8 shows an exemplary message flow diagram between the requester entity RE and the product P when verifying a lifecycle certificate according to the method 400 described with reference to FIG. 7. Before performing the actual steps of the method, authentication and authorization may be performed, or more generally, an access control scheme 500 that may involve sending a challenge and receiving a response may be performed. If access is denied, the product P will reject any requests. The access control scheme may be optional and is shown only exemplarily by a dashed line.

[0062] As described above, the requesting entity RE sends a request to the product P to verify the life cycle certificate. If the life cycle certificate to be verified is not received with the request, the request is sent in another message, for example, after a confirmation signal from the product P. The product executes steps 406 to 408 of method 400 and responds whether the life cycle certificate is valid or invalid.

[0063] FIG. 9 shows an exemplary block diagram of a product P adapted to execute the product-side steps of method 300 and / or 400 previously presented herein. The product P includes a microprocessor 602, a volatile memory 604, a non-volatile memory 606, and a communication interface 608, which are communicatively connected via at least one data connection or bus 610. The product P further includes a secure memory area 616a for storing, in a tamper-proof manner, a life cycle stage index counter value and, optionally, computer program instructions for incrementing the life cycle stage index counter in a tamper-proof manner. The non-volatile memory 606 stores computer program instructions that, when executed by the microprocessor 602, cause the product P to execute the product-side steps of method 300 and / or 400 of the present invention presented above.

Explanation of Signs

[0064] 100 Data Structure H Hash value of the first level H0, H1, H2 Hash values of the second level H0-0, H0-1, H1-0, H1-1, H2-0, H2-1 Hash values of the third level CTRL Control hash value P Product RE Requesting entity i Life cycle stage index 200 Method 202 Sending of request 204 Current life cycle stage and receipt of certificate 206 Reconstruction of path through Merkle tree 208 Verification 300 Method 302 Receipt of request 304 Current life cycle stage and provision of certificate 306 Receipt of request to migrate 308 Verification of target life cycle stage 310 Setting of life cycle stage 312 Storage of new confidential data 314 Generation of third-level hash value 316 Determination of path 318 Provision of life cycle index and certificate 320 Ignoring of request 322 Determination of life cycle certificate 324 Comparison of received life cycle certificate and determined life cycle certificate 400 Method 402 Receipt of request to verify 404 Receipt of life cycle certificate for verification 406 Comparison of received life cycle index and life cycle index stored in product 408 Comparison of received life cycle certificate and product's life cycle certificate 410 "Valid" response 412 "Invalid" response 602 Microprocessor 604 Volatile memory 606 Non-volatile memory 606a Secure memory area 608 Communication interface 610 Data line / bus

Claims

Claim 1 A method (200) for verifying the current lifecycle stage of a product (P) in a requesting source entity (RE), comprising: sending (202) a request to the product (P) asking for the provision of the current lifecycle stage of the product (P); receiving (204) from the product (P) the current lifecycle stage and a lifecycle certificate implementing a data structure (100); reconstructing (206) a path through the Merkle tree based on first-level, second-level, and third-level hash values or reference values thereof provided in the data structure, and determining the corresponding lifecycle stage index; verifying (208) whether the received lifecycle stage index is equal to the determined lifecycle stage index, wherein if the received lifecycle stage index is equal to the determined lifecycle stage index, the lifecycle stage is verified; wherein the data structure (100) comprises the lifecycle stage index (i); a first-level hash value (H) or a reference value to the first-level hash value (H); at least one second-level hash value (H0, H1, H2) or a reference value to the at least one second-level hash value (H0, H1, H2); third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) representing hashes of corresponding confidential data associated with respective values of the lifecycle stage index (i), and further third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) or corresponding reference values (H0-0, H0-1, H1-0, H1-1, H2-0, H2-1) therefor; The control hash value (CTRL), which is a hash value of the concatenation of the life cycle stage index (i), the hash value (H) of the first level or its reference value, the at least one hash value (H0, H1, H2) of the second level or its reference value, the hash values of the third level (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)), and the hash values of a further third level (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) or their reference values (H0-0, H0-1, H1-0, H1-1, H2-0, H2-1). A Merkle tree-based data structure (100) including Method (200).

2. A method (300) for safely transitioning the life cycle stage of a product (P) in only the forward direction to a target life cycle stage, a) Receiving, in the product (P) from the requesting meta-entity (RE), a request to provide a current life cycle stage index (i c ) (302); b) providing the requesting entity (RE) with a current life cycle stage index (i c ) and a life cycle certificate implementing the data structure (100) (304); c) Receiving (306) a request to transition the product (P) to a target life cycle stage in the product (P); d) verifying whether the target life cycle stage index (i t ) is higher than the current life cycle stage index (i c ) (308); Including The target life cycle stage index (i t ), if it is higher than the current life cycle stage index (i c ), the method (300) is e) setting the target life cycle stage index (i) received in the request as the current life cycle stage index (ic) (310); t ​ f) Storing (312) in the product (P) new confidential data that replaces the confidential data related to the previous life cycle stage index; g) Generating (314) a hash value of the third level representing the new confidential data and storing it at least temporarily; h) Determining (316) information for generating a new life cycle certificate implementing the data structure (100) and generating the new life cycle certificate; i) providing the current life cycle stage index (i c ) and the new life cycle certificate generated in step h) to the requesting entity (RE) (318); Including Or, if the target life cycle stage index (i t ) is not higher than the current life cycle stage index (i c ), the method (300) is j) Ignoring (320) the request Including The data structure (100) is The life cycle stage index (i), The hash value (H) of the first level or the reference value to the hash value (H) of the first level, At least one hash value (H0, H1, H2) of the second level or the reference value to the at least one hash value (H0, H1, H2) of the second level, Third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) representing the hash of the corresponding confidential data associated with each value of the life cycle stage index (i), and further third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) or corresponding reference values (H0-0, H0-1, H1-0, H1-1, H2-0, H2-1) for the latter, and A control hash value (CTRL) that is a hash value of the concatenation of the life cycle stage index (i), the first-level hash value (H) or its reference value, the at least one second-level hash value (H0, H1, H2) or its reference value, the third-level hash value (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)), and further third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) or its reference values (H0-0, H0-1, H1-0, H1-1, H2-0, H2-1), A Merkle tree-based data structure (100) comprising A method (300).

3. k) In the requesting entity (RE), based on the life cycle stage index and the life cycle certificate provided in step b), determining a life cycle certificate from the target life cycle stage and the confidential data transmitted to the product (P) (322); l) Comparing the life cycle certificate determined in step k) with the life cycle certificate provided by the product (P) in step h) (324); Further comprising If the determined life cycle certificate and the provided life cycle certificate are the same, the migration is completed successfully. The method (300) according to claim 2.

4. A method (400) for verifying the validity of a life cycle certificate of a product implementing a data structure (100), comprising Receiving a request to verify a life cycle certificate from a requesting entity (RE) and in the product (P) (402); If the life cycle certificate to be verified is not received together with the request, receiving the life cycle certificate to be verified from the requesting entity (RE) and in the product (P) (404); Comparing the life cycle stage index included in the received life cycle certificate with the current life cycle stage index of the product (P) (406); If the life cycle stage indexes are equal, In the product (P), comparing the received life cycle certificate with a life cycle certificate obtained from the memory of the product (P) or generated by the product (P) based on information stored in the memory of the product (P) (408); If the life cycle certificates are identical, Responding to the requesting entity (RE) that the life cycle certificate is valid (410); Or If the life cycle stage indexes are not equal or the life cycle certificates are not identical, Responding to the requesting entity (RE) that the life cycle certificate is invalid (412); Including, The data structure (100) includes The life cycle stage index (i), A first-level hash value (H) or a reference value to the first-level hash value (H), At least one second-level hash value (H0, H1, H2) or a reference value to the at least one second-level hash value (H0, H1, H2), Third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) representing the hashes of the corresponding confidential data associated with each value of the life cycle stage index (i), and further third-level hash values (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) or corresponding reference values (H0-0, H0-1, H1-0, H1-1, H2-0, H2-1) for the latter; The control hash value (CTRL) which is a hash value of the concatenation of the life cycle stage index (i), the hash value (H) of the first level or its reference value, the at least one hash value (H0, H1, H2) of the second level or its reference value, the hash value of the third level (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)), and the additional hash value of the third level (#(D0), #(D1), #(D2), #(D3), #(D4), #(D5)) or its reference value (H0-0, H0-1, H1-0, H1-1, H2-0, H2-1). A Merkle tree-based data structure (100) including the above. Method (400).

5. The method (200) according to claim 1, Executing an access control scheme for performing authentication and / or authorization between the requesting entity (RE) and the product (P), Upon successful authentication and / or authorization, accepting the request in the product (P), or Rejecting the request, The method (200) further including the above.

6. A product (P) comprising a microprocessor (602), a volatile memory (604) and a non-volatile memory (606) communicably connected via one or more data lines and / or buses (610), and a communication interface (608), and further comprising a secure memory area (606a) for storing a life cycle stage index counter value, wherein when the non-volatile memory (606) is executed by the microprocessor (602), the product (P) is configured to execute the steps of the method according to claim 2, and the product (P) stores computer program instructions for this purpose. **Claim 7** A product (P) comprising a microprocessor (602), a volatile memory (604), and a non-volatile memory (606), and a communication interface (608), communicatively connected via one or more data lines and / or a bus (610), further comprising a secure memory area (606a) for storing a life cycle stage index counter value, wherein the non-volatile memory (606) stores computer program instructions that, when executed by the microprocessor (602), configure the product (P) to perform the steps of the method according to claim 4. **Claim 8** A product (P) comprising a microprocessor (602), a volatile memory (604), and a non-volatile memory (606), and a communication interface (608), communicatively connected via one or more data lines and / or a bus (610), further comprising a secure memory area (606a) for storing a life cycle stage index counter value, wherein the non-volatile memory (606) stores computer program instructions that, when executed by the microprocessor (602), configure the product (P) to perform the steps of the method according to claim 5. **Claim 9** A computer program comprising computer program instructions that, when executed by a computer, cause the computer to perform the method according to claim 1 or 5. **Claim 10** A computer-readable medium storing the computer program according to claim 9 in a retrievable manner. **Claim 11** A computer program comprising computer program instructions that, when executed by a computer, cause the computer to perform the method according to claim 2 or 3. **Claim 12** A computer-readable medium storing the computer program according to claim 11 in a retrievable manner. **Claim 13** A computer program comprising computer program instructions that, when executed by a computer, cause the computer to perform the method according to claim 4. **Claim 14** A computer-readable medium storing the computer program according to claim 13 in a retrievable manner.

Citation Information

Patent Citations

  • Event certificate for electronic device

    JP2018121328A

  • Apparatus and method for making certificate data digitally available, and program therefor

    JP2021097392A

  • Method and system for tracking food safety data using hash trees

    JP2021518600A

  • Device authentication

    US20200274706A1