Method for signalling security events and automation component configured therefor
The automation component with a security manager and dedicated LED indicator addresses the challenge of unreliable security event detection by providing clear and reliable signaling, ensuring timely and appropriate responses during startup and operation.
Patent Information
- Application Number
- PCT/EP2025/066710
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-26
- Filing Date
- 2025-06-16
- Publication Date
- 2026-01-02
AI Technical Summary
Existing automation systems lack reliable methods for detecting and signaling security events during the startup and operating phases, leading to potential misinterpretations and incorrect troubleshooting, especially in cases affecting security.
An automation component equipped with a security manager that checks firmware during activation and operating phases, using a security indicator to exclusively display security events based on diagnostic tests, ensuring clear and reliable signaling through a dedicated LED.
Enables effective and accurate detection and signaling of security events, allowing for timely and appropriate responses, particularly during startup and operation, thereby enhancing system reliability and safety.
Smart Images

Figure EP2025066710_02012026_PF_FP_ABST
Abstract
Description
[0001] Method for signaling security events and automation component set up for this purpose
[0002] Description
[0003] The invention relates to a method for detecting and signaling security events occurring in an automation component within an automation system, and to an automation component that is suitably configured, in particular for carrying out the method.
[0004] For example, WO 2021 / 163829 states that a modem can have a processor configured to run software, such as an operating system. When the modem is switched off, the software is normally stored in non-volatile memory. When the modem is switched on again, i.e., booted, a fixed program code for system initialization (the so-called bootloader) starts. This bootloader then loads further program code, for example, from the non-volatile memory, and executes it. This bootloader can operate in stages, loading several programs of increasing complexity. After the boot sequence is complete, or at the end of this boot sequence, the operating system is loaded and executed by the last bootloader stage.When a modem is booted with a processor configured for secure boot, the first bootloader checks the subsequent one before execution. The first program code (bootloader) is permanently stored in immutable memory directly within the processor. This is done, among other things, by comparing the signature contained in the bootloader with the fingerprint stored in the processor. If a match is found, the bootloader is allowed to execute. If a mismatch is found, the bootloader is not allowed to execute, and the modem does not boot, or at least not successfully. A common cause of a mismatch or misconfiguration can be corrupted firmware. However, a firmware update can also cause the secure boot function to prevent the modem from booting, thus "bricking" the modem.
[0005] Against this background, WO 2021 / 163829 proposes a modem that includes a processor with a UEFI (Unified Extensible Firmware Interface) driver, which provides a software interface between the modem's operating system and firmware, as well as a boot diagnostic driver executed by the UEFI driver that performs a diagnostic test when the modem boots up. The boot diagnostic driver is configured to generate a signal based on the result of the diagnostic test, for example, if a hardware test error is detected, and transmit this signal to the processor. The processor then generates a command representative of the signal, which causes an indicator light, in particular a light-emitting diode (LED), to illuminate.
[0006] As further explained, the processor can, in principle, cause indicator lights to illuminate depending on the activity status. For example, any one or a combination of indicator lights can be illuminated, off, a specific color (e.g., red, green, yellow, etc.), a constant and continuous emission, pulses with a pulse frequency, pulses with a pulse duration, a specific brightness, a changing color, etc., depending on the modem's activity level.
[0007] However, as further explained, during the boot phase(s), the indicator lights, with the exception of the power indicator, are offline; that is, they are not illuminated and are not used by the processor as indicators of the modem's activity level. Therefore, the indicator lights can be used to monitor the modem's functions during the boot phase(s). For this purpose, the results of the diagnostic tests performed by the boot diagnostic driver are displayed as illumination sequences (Z-schemes) of the indicator lights. These illumination sequences (Z-schemes) can include combinations and / or permutations of on or off indicator lights, the color of the indicator lights, whether the indicator lights are constantly emitting light or pulsing, the pulsing frequency, the pulsing duration, and so on.A user can therefore monitor the indicator lights during startup or in the event of a modem failure to aid in troubleshooting.
[0008] The problem here, however, is that the indicator lights can be used for different purposes, making it difficult for the user to perform a correct diagnosis. Furthermore, the functionality of the indicator lights can be manipulated. Consequently, a reliable display and / or diagnosis of potential events during the boot phase is not adequately guaranteed.
[0009] If events occurring in this process are not clearly signaled and / or if faulty signaling leads to misinterpretations, possibly to troubleshooting in the wrong areas, this can lead to unforeseen, undesirable consequences, especially in the case of security events, i.e., events that affect security.
[0010] The object of the invention is to ensure the improved detection and signaling of security events, both during a start-up phase and during the operating phase of an automation component.
[0011] Since the concept of security is generally subdivided into the terms safety, security, and privacy, each addressing a different aspect of security, it should be expressly noted here that, within the context of this invention, which is situated in the field of automation technology, the term "security," when used in the following description and / or claims and unless otherwise stated, refers to the concept described by the term "security" and not to the concepts described by the terms "safety" and "privacy." Although safety, security, and privacy are often used interchangeably or equated, they differ fundamentally in their meaning with regard to definition and context, as well as potential threats, risks, attack scenarios, and avoidance and defense strategies.
[0012] While "safety" refers to protection against malfunctions of software / systems during intended use, and "privacy" refers to the protection of data from falling into the hands of unauthorized persons, the term "security" in the context of this invention, which is situated in the field of automation technology, is defined, unless otherwise stated, as the following description and / or claims define it as the protection of software / systems against corruption, damage, manipulation, and attacks on the confidentiality, integrity, and availability of information used or managed by the software / system. For example, standardized protocols can also protect software / systems from manipulation if they are correctly implemented and operated.
[0013] The solution of the invention is provided by an automation component and a method with the features according to the independent claims.
[0014] Accordingly, the invention proposes a method for detecting and signaling security events occurring within an automation system in an automation component, in particular an automation component configured for processing automation tasks, wherein, in response to the initiation of an activation process, i.e., in particular in response to the switching on and startup of the automation component, firmware stored in it is processed by a processor, and during the activation process of the automation component, the firmware to be processed by the processor is checked by a security manager before processing by the processor, i.e., subjected to a diagnostic test; and a security event based on the result of the diagnostic test is detected by a security manager.A security indicator instrument is displayed, which works exclusively with the security manager and / or the processor to display such security events based on the result of the diagnostic test.
[0015] Accordingly, the invention further proposes an automation component, in particular an automation component configured for carrying out the method, and specifically configured for processing automation tasks within an automation system, which on the one hand comprises a processor configured to execute firmware stored in the automation component in response to the initiation of an activation process, i.e., in particular, in response to the switching on and startup of the automation component, and on the other hand a security manager which checks the firmware to be executed by the processor during the activation process before it is executed by the processor.in particular a diagnostic test, wherein the automation component further comprises a security display instrument that interacts with the security manager and / or the processor to exclusively display a security event based on the result of the diagnostic test.
[0016] Key advantages of the invention for the detection and signaling of security events in automation components are therefore that the invention provides a clear and consequently particularly reliable, requirements-compliant and simple signaling of possible security events, such as special security incidents including faulty operating states, by means of the security indicator instrument provided for the exclusive display of the security event based on the result of the diagnostic test, so that a correct reaction of the system of the connected components and, if applicable, of the service personnel can be ensured as soon as the automation component is activated, which is particularly important with regard to reliable operation during the subsequent processing of automation tasks.
[0017] Accordingly, the security manager is further provided with supplementary, appropriate training and is trained to also check events and / or states occurring during and / or at least during the processing of automation tasks, so that security events based on these can also be displayed.
[0018] Consequently, the invention enables not only the recording of security events during both the start-up phase (secure boot) and the operating phase of automation components, but also, in particular, a significantly more effective signaling during the start-up phase and the operating phase of automation components.
[0019] Particularly to further increase effectiveness, the security manager is advantageously configured to classify the security event and, in response to the classification, to trigger a predetermined security response, up to and including the complete termination of the activation process and / or the termination of the processing of the automation tasks. If, in addition, the security indicator instrument is configured to display the security event in a predetermined manner in response to the triggered security response, and / or if the security indicator instrument includes a signal light, in particular an LED, which can be controlled in a predetermined manner depending on the security event, the invention enables highly effective attention signaling to ensure a correct response from the system of connected components and / or, if applicable,This ensures the safety of service personnel. In a highly practical implementation, predefined signals can be clearly assigned to various security events, making signaling much more needs-based, i.e., depending on the potential security incident and / or operating state. Consequently, the security indicator, which is not used for other functions, provides a clear signal of attention at all times.
[0020] In the context of an independent analysis of security events, the use of a blue LED for simple signaling has proven particularly useful, as other colors, such as green or red, are usually already reserved for other attention signals.
[0021] The security manager also expediently includes a log instance and a memory, the log instance being configured to store the result of the diagnostic test on which the display of the security event is based in the memory.
[0022] Thus, in a particularly preferred embodiment, the invention enables security events to be detected not only during the start-up phase and during the operating phase, but also to be weighted differently by classification, whereby there may be incidents that are only logged and can consequently be recognized, while others must lead to a greater signal of attention and some may even lead to countermeasures or the need for intervention by service personnel.
[0023] The features and advantages of the invention already outlined above, as well as further features and advantages relating to the detection and signaling, in particular by LED, of security events, expediently not only during a start-up phase (secure boot) but also during an operating phase of automation components, will become apparent from the following description of some preferred embodiments with reference to the accompanying drawing, in which the following are shown:
[0024] Fig. 1 is a highly simplified and schematic schematic diagram of an exemplary embodiment of a preferred automation component according to the invention.
[0025] As is well known, an automation system typically consists of several automation components. For such an automation system to achieve optimal performance, the individual automation components must generally work together and are therefore appropriately configured to perform their respective automation tasks within the system.
[0026] An exemplary embodiment of a preferred automation component 100 according to the invention, which is thus expediently configured for processing automation tasks within such an automation system (not shown in detail for the sake of clarity), is shown in a highly simplified and schematic way in Fig. 1 by way of a schematic diagram. The automation component 100 has a processor designated by the reference numeral 110. As is known, a processor, as a central processing unit, typically contains an arithmetic unit, memory, in particular main memory, control logic, and other necessary components to process data and execute instructions according to the application. The processor 110 is configured here such that, in response to the initiation of an activation process of the automation component 100, i.e.,In particular, in response to the power-on and startup of automation component 100, the firmware stored in memory 131 is initially processed. This startup process is often referred to in technical circles as the startup phase or boot phase. During the startup phase, a bootloader, also called a startup program or boot loader, is typically used. This bootloader is usually loaded from memory, specifically non-volatile memory, such as memory 131, which then loads and starts the firmware from memory 131. Following the startup phase, i.e., once the firmware has been processed, the operating phase of the respective automation component typically begins. This phase involves loading and executing automation software stored in memory 132, i.e., one or more programs for processing the specific automation task(s).During the operational phase, another so-called loader, i.e., another startup program, is typically used to load and start the automation software from memory 132. This additional loader can also be loaded from memory, particularly non-volatile memory, e.g., memory 132, which then in turn loads and starts the automation software. Figure 1 shows a bootloader already loaded and suitably configured according to the invention for loading and starting the firmware, designated by reference numeral 141, and another loader, also suitably configured according to the invention, for loading and starting the automation software, designated by reference numeral 142.
[0027] As can be further seen in Fig. 1, the automation component 100 also has a security manager designated by reference numeral 120, which, in a suitably advantageous embodiment, is also formed by a part of the processor 110, i.e., is itself a part of the processor 110. The security manager 120 thus also suitably contains at least parts of an arithmetic unit, a memory, in particular main memory, a control logic, and / or other components necessary for processing data and executing instructions, i.e., in particular, a component for managing the security check to be carried out within the scope of the invention. The security manager 120 is therefore, in particular, a sub-area of the processor 110 appropriately configured for managing the security check to be carried out within the scope of the invention. The already suitably configured bootloader 141 and the further suitably configured loader 142 are also, according to the embodiment of Fig. 1,1 is therefore preferably located in an area of the security manager 120.
[0028] According to the invention, the security manager 120 is configured to check the firmware to be processed by the processor during the activation process, i.e., to subject it to a diagnostic test before processing. The check itself, or the process of checking, is advantageously carried out by the bootloader itself, which is configured accordingly for this purpose. However, in a supplementary or alternative configuration, it can also be carried out in conjunction with a test circuit designed as part of the security manager 120, which is indicated in Fig. 1 by the rectangle marked with reference numeral 150 for illustrative purposes.
[0029] Finally, the automation component 100 also includes a security indicator 160, which interacts with the security manager 120 and / or the processor 110 to exclusively display a security event based on the result of the diagnostic test. In the illustrated embodiment, the security indicator 160 is a signal lamp, in particular an LED.
[0030] In the startup phase of the automation component configured according to the invention, a secure boot mechanism is therefore prioritized. This involves, in particular, the preliminary testing of the firmware that is loaded onto the automation component. For this purpose, a multi-stage process is advantageously used, which tests and executes increasingly larger portions of the firmware in several steps. Within the scope of the invention, this process can thus also be generally referred to as "secure boot." Specifically, to achieve a complete "secure boot," a small, subsequently unchangeable, partial boot loader is preferably integrated into the hardware as part of the security manager 120, for example, in the test circuit 150. This partial boot loader loads, tests, and starts the full boot loader 141, which in turn loads, tests, and starts the complete firmware. This mechanism can also be extended to include further levels.By means of such a “secure boot” distributed across several levels, the part that cannot be changed subsequently can be designed to be as small as possible but as large as necessary in preferred training, and the functional possibilities of the levels can also be continuously expanded.
[0031] In particular, to ensure the aforementioned immutability during the testing process and the associated reliable, and especially functional and tamper-proof, display of a security event based on the diagnostic test result, at least one dedicated processor pin, i.e., connected solely for this purpose to the boot loader 141 and / or the test circuit 150 as indicated in Fig. 1, is preferably provided for signaling via the security indicator 160. Advantageously, several dedicated processor pins are also provided. In particular, such or similar hardware connections allow for the advantageous early signaling of a complete failure of the boot process, i.e., not only as a result of (partial) loading and testing followed by the non-execution of further sub-steps, but rather the occurrence of an abort or lock state.In its preferred configuration, the boot loader 141 is therefore already able to directly and / or via the test circuit 150 control individual hardware elements, whereas a fully loaded firmware provides all hardware drivers. In summary, the security manager 120 is therefore preferably configured to classify the security event and, based on this classification, to trigger a predetermined security response, up to and including the complete termination of the activation process.
[0032] By means of the security manager 120 configured according to the invention, i.e., in particular with the boot loader 141 and / or the test circuit 150, a faulty firmware test can therefore be signaled at essentially every test stage and thus displayed via the security indicator 160, which therefore functions exclusively as a kind of "security alarm indicator". Any service personnel 170 assigned to the automation component 100 can therefore easily recognize such a security event. The display of the security event can therefore preferably be carried out in a predetermined manner by means of the security indicator 160 and / or the latter expediently has a signal lamp, in particular the LED described above, which can be controlled in a predetermined manner depending on the security event.
[0033] To cover all levels during (partial) loading and testing, i.e., to ensure proper and tamper-proof coverage of essentially every test stage, the preferred enhancement is to implement the signaling of a security event, particularly during the startup phase, for example, via a modified watchdog function. If the startup phase is monitored, for instance, by the corresponding hardware of the Security Manager 120, this can automatically trigger a security event signal if the watchdog is not deactivated within a defined time. Consequently, it is not strictly necessary to require a potentially complex function in an early phase of secure boot, and signaling is always guaranteed.
[0034] Due to the functionality of the Security Manager 120, included in the preferred version, which classifies security events and triggers a predetermined security response based on this classification, it is possible, for example, to start in a secure mode instead of entering a full lock state. This secure mode limits potential attacks but still allows external access, e.g., via a web-based management system. This allows the automation component to be reset to a predefined initial or default state without requiring physical access. Additionally or alternatively, further boot attempts, at least a predetermined number of them, and / or loading a backup firmware can also be permitted.
[0035] Essentially similar to the start-up phase, the security manager 120 also performs a check of occurring events and / or operating states during and / or at least during the processing of automation tasks, and the security indicator instrument 160 displays security events based on this, i.e., events and / or operating states recognized as security events.
[0036] In other words, it is advantageous for each automation software loaded for processing an automation task—as shown in Fig. 1, the automation software loaded from memory 132 via the loader 142—to undergo a diagnostic test before it is started. Here, too, the check itself, or rather the process of checking, is preferably carried out by the appropriately configured loader 142 itself. However, it can also be carried out in a supplementary or alternative configuration in conjunction with the test circuit 150, which, as shown in Fig. 1, is part of the safety manager 120. If security events can thus also be detected during the operating phase, these generally have different weightings.In particular, there are security events that only need to be logged, while others must lead to greater alerts and / or some may even require countermeasures or intervention by service personnel.
[0037] Therefore, as part of appropriate training, the Security Manager 120 is also trained to classify security events and, based on the classification, to trigger a predetermined security response, up to and including the complete termination of the automation tasks. As a result, detected security events can be categorized into different priorities and alert states. The priority then effectively influences the type of signaling and / or the alert state the options for acknowledging this signaling.
[0038] Priorities for security events can be differentiated, for example, according to whether they are classified as "high" or "critical" or only as "medium" or "low", and reporting states for security events can preferably be differentiated according to whether they only occur impulsively, e.g. only coming, i.e. only at the moment of actual occurrence, or whether they are pending for a longer period and also disappear again (coming / going).
[0039] Against this background, a single incorrect password entry and rejection of a user login to the automation component is preferably, in practical implementation, classified as a notification state of a one-time, "only forthcoming" security event and / or, for example, categorized as a security event with medium priority. In contrast, a successful user login is preferably, in practical implementation, classified as a notification state of an "upcoming" security event until the user logs out, a "going" security event, and / or, for example, categorized as a security event with low priority.
[0040] For logging detected security events, i.e., not only during the operating phase but also during the startup phase, the automation component 100, and in particular the security manager 120, consequently comprises a logging instance and a memory, collectively identified during execution according to Fig. 1 by the rectangle labeled with reference numeral 180, wherein the logging instance is configured to store the result of the diagnostic test on which the display of the security event is based in the memory. The events recorded by the logging instance 180 during the operation of an automation component and expediently stored in a security event log are then...In a suitable implementation, recorded security events can then also be read out from the automation component 100 by service personnel 170, for example via a computer 190 connected to the protocol instance 180 or an alternative readout device, and can thus be used for additional diagnostics. Additionally or alternatively, depending on the specific embodiment of the invention, active transmission of recorded security events and / or the security event log via a communication network is also possible.
[0041] To reliably log detected security events at virtually any point during the startup phase, while allowing the startup phase to be aborted early as described above, it is advantageous for at least part of the logging instance 150 to be integrated into the hardware of the security manager 120, or at least defined in its firmware. This also advantageously ensures that reading recorded / logged security events remains possible even when starting in safe mode.
[0042] As described above, an LED has proven particularly suitable as a security indicator instrument 160, which interacts with the security manager and the processor solely for displaying a security event based on the result of the diagnostic test. This is especially true because such an LED can be very easily connected directly to the processor via hardware and is therefore tamper-proof. Signaling via a single-color LED has also proven to be a particularly cost-effective option. Furthermore, the color blue has proven especially appropriate, particularly since blue is also known as the "official" color for the so-called "blue lights" of emergency services, signaling a special operation but not necessarily an immediate fault condition. In IT security color theory, the color "blue" also represents the defending function.The "Blue Team" is responsible for protecting the systems. Therefore, a blue LED signaling the protective function of an automation component can be immediately seen and recognized as such by any service personnel, without misinterpretation. Furthermore, in conjunction with any other dependent LEDs, a more thorough, and therefore more in-depth, diagnosis by the service personnel can be performed much more easily.
[0043] The following table lists exemplary possibilities for displaying security events in a predetermined manner or for controlling a signal light in a predetermined manner and depending on the error, and their associated meanings:
[0044] To continuously demonstrate the intact function of the security indicator instrument, it can, for example, additionally glow slightly or flash briefly at regular intervals (e.g., every minute) when switched off.
[0045] In summary, the solution according to the invention thus enables the detection and signaling of security events of automation components, with particular attention paid to their start-up and operating phases, and these functions are bundled in the form of the security manager.
Claims
Patent claims 1. Automation component (100), in particular configured for processing automation tasks within an automation system, comprising: a processor (110) configured to process firmware stored in the automation component in response to the initiation of an activation process, i.e., the power-on and startup; a security manager (120) which, during the activation process, checks the firmware to be processed by the processor before processing it, i.e., subjects it to a diagnostic test, wherein the automation component further comprises a security indicator instrument (160) which interacts with the security manager and / or the processor to exclusively display a security event based on the result of the diagnostic test.
2. Automation component according to claim 1, wherein the security manager is further configured to check events and / or operating states occurring during and / or at least during the execution of automation tasks, i.e. to subject them to diagnostic testing, wherein the security display instrument is configured to also display security events based thereon.
3. Automation component according to claim 2, wherein the security manager is configured to classify the security event and, in response to the classification made, to trigger a predetermined security response up to and including the complete termination of the processing of the automation tasks.
4. Automation component according to one of claims 1 to 3, wherein the security manager is configured to classify the security event and, in response to the classification made, to trigger a predetermined security response up to and including the complete termination of the activation process.
5. Automation component according to one of claims 1 to 4, wherein the security indicator instrument is configured to display the security event in a predetermined manner in response to the triggered security reaction and / or wherein the security indicator instrument has a signal light, in particular an LED, which can be controlled in a predetermined manner depending on the fault.
6. Automation component according to one of claims 1 to 5, wherein the security manager comprises a protocol instance (180) and a memory, wherein the protocol instance is configured to store the result of the diagnostic test on which the display of the security event is based in the memory.
7. Method for detecting and signaling security events occurring within an automation system in an automation component (100), in particular configured for processing automation tasks, wherein, in response to the initiation of an activation process, i.e., the switching on and startup of the automation component, firmware stored in it is processed by a processor (110), and during the activation process of the automation component, firmware to be processed by the processor is checked by a security manager (120) before processing by the processor, i.e., subjected to a diagnostic test, and a security event based on the result of the diagnostic test is displayed by a security indicator (160), which is used exclusively for displaying such based on the result of the diagnostic test, security events interact with the security manager and / or the processor.
8. Method according to claim 7, wherein furthermore, events and / or operating states occurring during and / or at least during the execution of automation tasks are checked by the security manager, i.e., subjected to diagnostic testing, and security events based thereon are also displayed by the security display instrument.
9. Method according to claim 7 or 8, wherein a classification of the fault is performed and a predetermined safety response is triggered in response to the classification performed.
10. Method according to claim 7, 8 or 9, wherein, in response to the triggered security reaction, the display of the security event is carried out in a predetermined manner, and / or wherein the security display instrument has a signal light, in particular an LED, which is controlled in a predetermined manner depending on the security event, and / or wherein the result of the diagnostic test on which the display of the security event is based is stored in a memory by a protocol instance.
Citation Information
Patent Citations
Systems and methods for narrowing the scope of a problem when a modem is bricked
WO2021163829A1
Firmware development method based on BMC Post operational process detection of BMC server
CN107145413A
Baseboard management controller (BMC)-based security processor
US11531760B1
Method and system for indicating BIOS post status from a chassis identify LED
US20210200650A1
Systems and methods for narrowing the scope of a problem when a modem is bricked
US20230078692A1