Restoring of a device comprising a user-specific restoring action
The module for restoring IoT devices autonomously executes user-defined recovery actions upon detecting attacks, effectively minimizing the risk of compromised IoT devices and ensuring reliable restoration to an intact state.
Patent Information
- Application Number
- PCT/EP2024/081338
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-20
- Filing Date
- 2024-11-06
- Publication Date
- 2025-05-30
AI Technical Summary
IoT devices, especially industrial control units, are vulnerable to remote exploitation of software vulnerabilities, leading to potential device manipulation and compromised security.
A module for restoring a device that includes a receiving unit for detecting attack messages, a configuration unit for setting user-specific recovery actions, and a recovery unit for autonomously executing these actions, allowing the device to independently restore itself to a reliable state without external assistance.
This solution enables IoT devices to perform reliable, user-configurable, and adaptable recovery actions, minimizing the risk posed by attacked devices and ensuring quick restoration to an intact state, even in the absence of network connectivity.
Smart Images

Figure EP2024081338_30052025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Restoring a device comprising a user-specific recovery action
[0003] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.
[0004] BACKGROUND OF THE INVENTION
[0005] Field of the invention
[0006] The invention relates to a module for restoring a device. Furthermore, the invention relates to a higher-level device and an associated method for restoring a device.
[0007] Description of the state of the art
[0008] The software, especially firmware, of IoT devices, especially industrial control units, is known to have vulnerabilities. Because they are networked with external systems, these vulnerabilities can also be exploited remotely. Since vulnerabilities can only be patched with a time delay, IoT devices are inherently vulnerable.
[0009] It is common for vulnerabilities to be closed by installing firmware updates or security patches.
[0010] Technologies are also known that at least make it more difficult for attackers to exploit vulnerabilities (exploit protection), particularly stack randomization (ASLR); stack protection (e.g., stack canaries or shadow stack), control flow integrity (CFI), virus scanners, and host-based intrusion detection systems (HIDS). Hypervisors and mandatory access control systems (e.g., SELinux, AppArmor) for application isolation are also known. Firewalls, network-based intrusion detection systems, and log data analysis systems are also known.
[0011] It is also known that attacks can be detected at a deeper hardware level:
[0012] • Dover Microsystems: Monitoring on a processor / SoC that the instructions executed by the CPU comply with defined security rules ("monitoring every instruction executed to ensure it complies with a set of security, safety, and privacy rules")
[0013] • On-chip monitoring: UltraSoc / Siemens Tessent Embedded Analytics. This allows internal chip behavior, such as memory access, to be recorded and evaluated.
[0014] • Jintide is known to monitor the IO behavior and memory access behavior of a CPU, see Zhu, J. ; Luo, A. ; Li, G. ; Zhang, B. ; Wang, Y. ; Shan, G. ; Li, Y. ; Pan, J. ; Deng, C. ; Yin, S. ; Wei, S. ; Liu, L. , "Jintide: Utilizing Low-Cost Reconfigurable External Monitors to Substantially Enhance Hardware Security of Large-Scale CPU Clusters", IEEE Journal of Solid-State Circuits, vol. 56, issue 8, pp. 2585 - 2601
[0015] • X-PHY is known to be able to detect access to an SSD memory by an AI engine integrated on the SSD memory and to block further access in response.
[0016] • Power Fingerprinting: Monitoring the power consumption profile or electromagnetic radiation of a device
[0017] Approaches for "resilience under attack" and reliable, automated recovery after a successful security attack are described in the following publications:
[0018] • TCG Cyber Resilient Module and Building Block Requirements: The described "Cyber Resilient Module" relies on a separate "Resilience Authority" unit that provides the CRM (or its Resilience Engine) with instructions on the recovery actions to be carried out.
[0019] • NIST Platform Firmware Resiliency Guidelines, NIST SP 800-193: This states that a computer system (server) can have a "root of trust for recovery" through which the computer system can be remotely and reliably restored to an intact state after an attack.
[0020] • Rainer Falk, Steffen Fries: Enhancing Attack Resilience in the Presence of Manipulated loT Devices within a Cyber Physical System, The Sixth International Conference on Cyber-Technologies and Cyber-Systems CYBER 2021, 3-7 October 2021, Barcelona, Spain: This means that higher-level integrity monitoring is known in industrial systems, and that a specially protected execution environment can be prepared in control units / loT devices / servers in order to be able to reliably execute certain functions on a device even during or after a successful attack on it.
[0021] It is also known to keep a fixed default firmware image or the last executable firmware image available during a firmware update in order to fall back to a known executable image in the event of an error during the firmware update.
[0022] The object of the invention is to provide a solution that minimizes the risk posed by attacked devices.
[0023] SUMMARY OF THE INVENTION
[0024] The invention results from the features of the independent claims. Advantageous further developments and refinements are the subject of the dependent claims. Embodiments, possible applications, and advantages of the invention emerge from the following description and the drawings. The invention relates to a module (also referred to as a device unit) for restoring (also referred to as recovery) a device, comprising:
[0025] - a receiving unit, designed to receive a message (also referred to as a recovery trigger) regarding an attack (also referred to as manipulation) on the device,
[0026] - a configuration unit designed to configure at least one user-specific recovery action (also referred to as recovery action) in a computer program for restoring the device (in particular a software program (programmed in the form of software), a template, an image, a projection, a projectable recovery image, a configuration setting), and
[0027] - a recovery unit, designed to carry out the recovery of the device using the computer program for device recovery when the message regarding the attack that has occurred is present (also referred to as carrying out). In one variant, the device has a control unit for controlling or monitoring a technical process via connectable sensors and / or actuators. In this variant, the recovery unit sets up the control functionality of the control unit of the device during a recovery depending on the configured user-specific recovery action. In this way, the device or its control unit implements a user-definable control functionality for controlling or monitoring the technical process during a device recovery.Furthermore, in this variant, the recovery unit sets up program code and / or configuration data for the regular control functionality of the device's control unit during a recovery, depending on the configured user-specific recovery action. After the recovery is complete, the restored, regular control functionality can be reliably performed again by the device or its control unit.
[0028] The computer program can in particular be loaded into a memory device of a computing unit and executed by the computing unit.
[0029] According to one aspect of the invention, after an attack (manipulation) on the IoT device is detected by an attack detection system of the IoT device, a predeterminable (user-defined) recovery action is automatically initiated and executed on the IoT device at runtime. The IoT device can thus independently restore itself to a reliable state, i.e., without relying on external (central) security monitoring and device management services. This allows the IoT device to reliably realize an autonomous recovery of a mission-critical control functionality.
[0030] The user-specific recovery action is to be understood as a recovery action that can be specified and / or adapted and / or projected and / or configured by the user.
[0031] The invention has the advantage that a user-specified, adaptable, and configurable recovery action is performed on the IoT device. This can be configured by the user, meaning they can specify the behavior of an IoT device after a detected device manipulation. This has the advantage that reliable recovery can be performed, but flexibly according to the user's requirements. This ensures that attacked or manipulated IoT devices pose only a limited, manageable risk, and that they can be reliably and quickly restored to an intact state after a successful attack. The user-specified, adaptable, and configurable recovery action can also be referred to as a user-defined recovery action.The message (recovery trigger) can be, for example, an electrical or optical signal, or a bit sequence or symbol sequence that can be transmitted via a device communication interface, e.g. SPI, I2C, PCIe, device bus, backplane bus.
[0032] In other words, the invention offers the advantage that a user (machine builder, integrator, OT operator) can define how an attacked control unit reacts. The control unit performs the recovery action independently, i.e., unlike in server environments or consumer-oriented IoT environments, without the use of a central management system. This also improves the attack resilience of an individual system. Furthermore, this functionality is applied regardless of whether network connectivity exists.
[0033] In a further development of the invention, the configuration unit is further configured to configure at least one manufacturer-specific recovery action into the computer program for the recovery of the device (in particular, a firmware and / or a fixed recovery image specified by the device manufacturer). The manufacturer-specific recovery action is predefined by the device manufacturer, i.e., it cannot be specified or customized by the user. The manufacturer-specific recovery action can also be referred to as a device manufacturer-defined recovery action.
[0034] The computer program for recovery thus also includes a manufacturer-specific component. The recovery unit thus executes at least one manufacturer-specific recovery action (an optional reference recovery firmware, which is defined by the device manufacturer) and a user-programmable recovery configuration. A recovery image is thus executed which includes a device manufacturer-defined component and a user-defined component. This combination enables a reliable recovery that is, however, customized by the user. Thus, a fixed recovery image specified by the device manufacturer and a user-configurable recovery image are combined.
[0035] In a further development of the invention, the configuration unit is also designed to configure at least one combined user- and manufacturer-specific recovery action in the computer program for recovering the device.
[0036] According to this embodiment, potentially conflicting, i.e., not fully compatible, i.e., not jointly executable, user-specific recovery actions and manufacturer-specific recovery actions are combined into a combined user- and manufacturer-specific recovery action. The combined recovery action is created according to a predefined guideline that considers and balances the specifications of the user and the manufacturer.
[0037] In a further development of the invention, the computer program for the recovery (and thus the at least one user-specific recovery action) has modification protection.
[0038] Furthermore, it is particularly intended to seal the computer program for recovery (the recovery configuration setting), i.e., to provide protection so that it cannot be modified (either set once or only completely reset via a factory reset or similar). Furthermore, it is possible that the recovery configuration setting can only be modified or replaced after providing a valid recovery modification code, for example in the form of a numeric code or an alphanumeric character string entered via a user interface, or in the form of an authorization token provided via a communication interface or network interface.
[0039] In a further development of the invention, the attack that had taken place was detected by:
[0040] - a Host-Based Intrusion Detection System (HIDS) and / or
[0041] - monitoring at the hardware level, in particular of bus accesses, input and output interface accesses, memory accesses, power fingerprinting, triggering of exploit protection measures, in particular a violation of control flow integrity monitoring or stack protection.
[0042] - a host-external signal, e.g. from a sensor that signals a change in the operating environment (e.g. fire detector).
[0043] In a further development of the invention, the receiving unit is designed to receive the message regarding the attack that has occurred (also referred to as a "recovery trigger") from an attack detection module.
[0044] The attack detection module is specifically designed as a component of the device.
[0045] In a further development of the invention, the message regarding the attack that has taken place takes into account a user-specific device integrity policy.
[0046] According to this embodiment, the user-specific device integrity monitoring policy is configurable by the user in addition to the user-specific recovery action.
[0047] In a further development of the invention, the configuration unit is designed to configure a plurality of user-specific recovery actions (also referred to as recovery actions) in the computer program for restoring the device.
[0048] In a further embodiment, a plurality (in the plural sense, i.e., a multitude) of recovery action sets and associated selection rules can be configured. A recovery action set comprises one or more recovery actions.
[0049] In a further development of the invention, the configuration unit is designed to configure at least one user-specific recovery action (also referred to as recovery action) in the computer program for restoring the device depending on the attack that has occurred.
[0050] Depending on the type of attack that occurred, at least one of the user-specific recovery actions (or configured recovery action sets) is selected and implemented based on configured selection rules. This allows a user to configure a specific resilience response depending on the type of attack or detected tampering.
[0051] In a further development of the invention, the configuration unit is designed to configure at least one user-specific recovery action (also referred to as recovery action) in the computer program for restoring the device depending on an integrity violation caused by the attack that has occurred.
[0052] Depending on the type of integrity violation detected, at least one of the user-specific recovery actions (or multiple configured recovery action sets) is selected and implemented based on configured selection rules. This allows a user to configure a specific resilience response depending on the type of integrity violation, i.e., depending on the detected attack or tampering.
[0053] In a further development of the invention, the at least one user-specific recovery action is designed as:
[0054] - stopping a processor of the device (in particular stopping a CPU of the device by a (HALT signal)
[0055] - blocking at least one input and output interface of the device (in particular, setting the input and output interface / lO interface / lO interface to a defined fail-safe state)
[0056] - blocking access to at least one additional component of the device (in particular access to the 10-interface and / or to a secure element by the device's processor)
[0057] - blocking and / or restricting (in particular by a firewall) at least one communication module of the device,
[0058] - blocking and / or restricting (in particular by a firewall) at least one communication interface of the device (in particular blocking and / or restricting Ethernet, WLAN, 5G, so that the processor (CPU) of the device can only send and / or receive data via the at least one communication interface to a limited extent), and / or
[0059] - deleting and / or archiving a working memory of the device (particularly in combination with archiving for subsequent analysis (e.g. in a free memory area in the flash) or with transferring a memory content to an external analysis system).
[0060] The invention also encompasses a device comprising a module according to the invention. In a further development of the invention, the device is designed as:
[0061] - a control unit,
[0062] - an Internet of Things device,
[0063] - an embedded system,
[0064] - an industrial control device and / or
[0065] - a programmable logic controller (PLC).
[0066] In a further development of the invention 14. Device according to claim 12 or 13, further comprising:
[0067] - an attack detection module.
[0068] The functionality for attack detection and (as well as for performing a recovery action) is integrated directly into the device (preferably) as a separate (as a module locally on the device, connected via an interface and thus specially protectable, i.e. but not external to the device), associated component, in particular as a technology module, as a memory module (SD card form factor, SSD form factor, USB stick form factor) or as an expansion module (in particular as a PCIe plug-in module).
[0069] The invention also includes a method for restoring (also referred to as recovery) a device, comprising the steps:
[0070] - receiving a message (also known as a recovery trigger) regarding an attack (also known as manipulation) on the device,
[0071] - configuring at least one user-specific recovery action (also referred to as recovery action) in a computer program for restoring the device (in particular a software program (programmed in the form of software), a template, an image, a configuration, a configurable recovery image, a configuration setting), and
[0072] - performing (also referred to as performing) the recovery of the device using the computer program for device recovery in the presence of the message regarding the attack that has taken place.
[0073] BRIEF DESCRIPTION OF THE DRAWINGS
[0074] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawing.
[0075] It shows
[0076] Fig. 1 shows a device according to the invention.
[0077] DETAILED DESCRIPTION OF THE INVENTION
[0078] Fig. 1 shows a control device D, in particular an industrial IoT device D, with a processor CPU, program and configuration memory F, also referred to as flash F, RAM, a communication module CM, a security element SE, an input / output interface I / O for connecting sensors and actuators and a power management unit P, also referred to as energy management unit P.
[0079] The control unit D also has a component for integrity monitoring 1 of the device D, also referred to as a device-autonomous device integrity monitoring module 1, which implements a runtime health check 11. For the check, a fixed policy 12 specified by the device manufacturer and, according to the invention, a policy 13 configurable by the user can be used.
[0080] The control unit D further comprises the resilience module 2 according to the invention, also referred to as a device resilience module 2, which has a recovery engine 23 which, in the event of device manipulation detected by a recovery trigger 14, carries out a user-adaptable, i.e., configurable, recovery action. In the case shown, a fixed recovery image 21 specified by the device manufacturer and a user-configurable recovery image 22 are combined by a recovery image combiner 2122. Although the invention has been illustrated and described in detail by the exemplary embodiments, the invention is not restricted by the disclosed examples, and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.
Claims
Patent claims 1. Module (2) for restoring a device (D), comprising: - a receiving unit configured to receive a message (14) relating to an attack on the device (D), - a configuration unit configured to configure at least one user-specific recovery action (22) in a computer program for the recovery of the device (D), wherein the user-specific recovery action (22) is configured as a recovery action (22) that can be specified and / or adapted and / or projected by a user, and - a recovery unit (23) configured to carry out the recovery of the device using the computer program for device recovery in the presence of the message (14) regarding the attack that has taken place.
2. The module according to claim 1, wherein the configuration unit is further configured to configure at least one manufacturer-specific recovery action (21) into the computer program for recovering the device.
3. Module according to one of the preceding claims, wherein the configuration unit is further configured to configure at least one combined (2122) user- and manufacturer-specific recovery action into the computer program for recovering the device.
4. Module according to one of the preceding claims, wherein the computer program for the recovery has modification protection.
5. Module according to one of the preceding claims, The attack that took place was detected (11) by: - a Host-Based Intrusion Detection System (HIDS) and / or - monitoring at the hardware level, in particular of bus accesses, input and output interface accesses, memory accesses, power fingerprinting, triggering of exploit protection measures, in particular a violation of control flow integrity monitoring or stack protection.
6. Module according to one of the preceding claims, wherein the receiving unit is designed to receive the message (14) regarding the attack that has taken place from an attack detection module (1).
7. Module according to one of the preceding claims, wherein the message (14) regarding the attack that has occurred takes into account a user-specific device integrity policy (13).
8. Module according to one of the preceding claims, wherein the configuration unit is designed to configure a plurality of user-specific recovery actions (22) into the computer program for recovering the device (D).
9. Module according to one of the preceding claims, wherein the configuration unit is designed to configure the at least one user-specific recovery action (22) in the computer program for the recovery of the device (D) depending on the attack that has occurred.
10. Module according to one of the preceding claims, wherein the configuration unit is designed to include at least one user-specific recovery action (22) in the computer program for the recovery of the device (D) to be configured depending on an integrity violation caused by the attack that has taken place.
11. Module according to one of the preceding claims, wherein the at least one user-specific recovery action (22) is designed as: - stopping a processor (CPU) of the device, - blocking at least one input and output interface (I / O) of the device, - blocking access to at least one additional component of the device, - blocking and / or restricting at least one communication module (CM) of the device, - blocking and / or restricting at least one communication interface of the device, and / or - deleting and / or archiving a memory (RAM, F) of the device.
12. Device (D) comprising a module (2) according to one of the preceding claims.
13. Device (D) according to claim 12, designed as: - a control unit, - an Internet of Things device, - an embedded system, - an industrial control device and / or - a programmable logic controller.
14. Device according to claim 12 or 13, further comprising: - an attack detection module (1) .
15. Method for restoring a device (D) , comprising the steps: - receiving a message (14) regarding an attack on the device (D), - configuring at least one user-specific recovery action (22) in a computer program for restoring the device (D), wherein the user-specific recovery action (22) is designed as a recovery action (22) that can be specified and / or adapted and / or projected by a user, and - carrying out the recovery of the device (D) using the device recovery computer program in the presence of the message (14) regarding the attack that has taken place.
Citation Information
Patent Citations
Fight-through nodes for survivable computer network
US20170034198A1
Mitigating actions
US20190347155A1
Systems and methods for evasive resiliency countermeasures
US20220191217A1