Control unit having a cyber resilience device

The control unit with a cyber resilience device addresses vulnerabilities in industrial control systems by implementing measures based on stored process data to limit physical damage and ensure reliable recovery, enhancing cyber resilience and process safety.

WO2026046906A1PCT designated stage Publication Date: 2026-03-05SIEMENS AG
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Industrial control systems face vulnerabilities to cyberattacks, leading to potential disruptions and physical damage due to the lack of comprehensive cyber resilience measures that consider the state of the controlled physical processes.

Method used

A control unit with an access-protected process data storage unit and a cyber resilience device that performs measures based on stored process data, including features like flushing fluid lines, moving robots, and reorganizing tool magazines, to limit physical damage and ensure reliable recovery.

Benefits of technology

The solution enhances cyber resilience by minimizing disruptions and downtime, ensuring the safety and reliability of industrial processes by effectively mitigating potential damage from cyberattacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025074106_05032026_PF_FP_ABST
    Figure EP2025074106_05032026_PF_FP_ABST
Patent Text Reader

Abstract

The control unit has an access-protected process data memory which continuously stores process data relating to a technical process controlled by the control unit; said control unit additionally comprises a cyber resilience device (DRE), the cyber resilience device (DRE) carrying out at least one cyber resilience measure on the technical process in accordance with process data stored in the process data memory.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] 202415961 Foreign version

[0002] 1

[0003] Description

[0004] Control unit with cyber resilience feature

[0005] The invention relates to control units with a cyber resilience device.

[0006] Industrial control systems, such as programmable logic controllers (PLCs) and other automation devices, play a crucial role in managing and controlling complex technical processes across various industries. These systems are responsible for monitoring operations ranging from production facilities and chemical reactors to power plants. As industrial environments become increasingly digitized and networked, particularly with the advent of the Internet of Things (IoT), these control systems are often connected to external networks and systems.

[0007] Connecting industrial control systems to external networks, while advantageous for remote monitoring and management, also creates potential vulnerabilities for cyberattacks and manipulation. Attackers can exploit weaknesses in the firmware or software of industrial control devices to disrupt technical processes, potentially causing significant damage or even security risks. The time lag between discovering vulnerabilities and implementing patches further exacerbates this problem, leaving industrial control systems exposed to potential threats for extended periods.

[0008] In the event of a successful cyberattack or manipulation, it is essential to ensure that the compromised industrial control device can be quickly and reliably restored to a secure state. However, simply restoring the device itself may not be sufficient, as the controlled physical processes could also be affected. For example, in food production systems or process industries, an attack on the automation system could lead to blocked pipes or solidified molten materials, resulting in costly damage and downtime.

[0009] Therefore, the object of the present invention is to provide an improved control unit which, compared to the control units used in the prior art, 202415961 Foreign version

[0010] 2. It exhibits improved cyber resilience capabilities. Furthermore, the objective of the present invention is to provide an improved industrial plant.

[0011] These objectives of the present invention are achieved with a control unit having the features claimed in claim 1 of the present invention, and with a manufacturing plant having the features specified in claim 14.

[0012] Advantageous embodiments of the invention are specified in the associated dependent claims, the following description and the drawing.

[0013] The control unit according to the invention comprises an access-protected process data storage unit that continuously stores process data of a technical process controlled by the control unit, and a cyber resilience device, wherein the cyber resilience device performs at least one cyber resilience measure on the technical process depending on the stored process data of the process data storage unit.

[0014] The control unit according to the invention enables reliable recording of the state of the technical process controlled by the control unit. Such reliable recording allows for improved recovery of the technical process, i.e., reliable continuation or resumption of the technical process. According to the invention, the at least one cyber resilience measure is based on stored process data. In this way, the control unit can effectively limit potential damage resulting from the process controlled by the control unit according to the invention, for example, to persons or components involved in the technical process, and ensure reliable and efficient recovery or resumption of both the control unit and the technical process it controls.The control unit according to the invention therefore significantly improves the cyber resilience of industrial plants with such a control unit and reduces downtime and potential security risks as a result of a cyberattack on such a control unit or as a result of manipulation of such a control unit.

[0015] The cyber resilience measure in the control unit according to the invention preferably comprises one or more of the following measures: flushing a fluid line, in particular a pipe; clearing a conveyor belt; activating a heater, in particular a minimum heater, of a melting process; moving a robot and / or an autonomous transport vehicle to a specific position, in particular a predetermined position. 202415961 Foreign version

[0016] 3

[0017] Position and / or a default position; reorganizing a tool magazine, in particular creating a default configuration of tools in or around the tool magazine; operating a machine in a material flow-free and / or workpiece-free state.

[0018] Such cyber resilience measures have a particularly significant and beneficial impact on the safety of industrial processes: By incorporating cyber resilience measures such as flushing fluid lines, clearing conveyor belts, and managing heating processes, the control unit can effectively mitigate potential physical damage resulting from cyberattacks. The ability to move robots or autonomous vehicles to safe positions and reorganize tool magazines further improves operational safety and continuity. Together, these measures help to minimize disruptions and potential losses in industrial processes, thereby improving the overall operational safety, process safety, and reliability of the controlled technical processes, and consequently, the safety of the industrial plants in which one or more control units according to the invention are used.

[0019] The process data preferably comprises, in the case of the control unit according to the invention, a process image, in particular a most recent past recorded process image, and / or past process images and / or at least one status information on the controlled technical process.

[0020] This further development of the invention advantageously enables a more comprehensive and detailed understanding of the state of the technical process. By storing not only the most recent process image but also historical data and specific status information, the control unit can make more informed decisions when implementing cyber resilience measures. This detailed recording, in particular, allows for a more precise restoration or resumption of the technical process, which can shorten the recovery time and consequently also reduce the productivity downtime of an industrial plant with a control unit according to the invention. Furthermore, the more precise recording of the state of the technical process made possible by this further development of the invention allows for a more tailored design of the cyber resilience measure(s).

[0021] In an advantageous embodiment of the control unit according to the invention, the process data memory can be combined with a ring data memory and / or a non-volatile memory, 202415961 Foreign version

[0022] 4 in particular a Flash memory and / or an EEPROM and / or a Non-Volatile Random Access Memory and / or a Magnetoresistive RAM and / or a Ferroelectric RAM and / or a Phase-Change Memory, and / or a Battery-backed SRAM.

[0023] This further development of the invention ensures that critical process data is retained even in the event of a power outage or system restart. The use of non-volatile memory technologies provides robust data storage and improves the reliability of the stored process data. The ring-shaped data storage structure enables efficient storage and management of historical process data and allows the control unit to maintain a comprehensive yet manageable record of the technical process's state. Such reliable data storage is crucial for effective cyber resilience measures and accurate system recovery.

[0024] In an advantageous further development, the control unit according to the invention is set up to certify the implementation of the cyber resilience measure.

[0025] In this advantageous further development of the invention, the transparency of cyber resilience measures and accountability for these measures are further improved. By providing attestation of the implemented cyber resilience measures, the control unit provides a verifiable record of its cyber resilience measures in response to detected threats. This function is particularly relevant for subsequent auditing purposes, incident response analysis, and compliance with safety regulations. It also enables better coordination with other systems and personnel in the assessment, handling, and documentation of cyber incidents.

[0026] In an advantageous further development of the invention, the control unit comprises an integrity testing device which is designed to implement the cyber resilience measure depending on an integrity test result of the integrity testing device.

[0027] In this further development of the invention, an additional layer of security is provided by incorporating integrity checks into the decision-making process for cyber resilience measures. By basing cyber resilience measures on integrity check results, the control unit can more accurately identify and respond to potential security breaches or system anomalies. This function improves the precision and effectiveness of the 202415961 foreign version

[0028] 5

[0029] Cyber ​​resilience measures reduce the likelihood of false alarms or unnecessary system disruptions.

[0030] In preferred embodiments of the invention, the control unit has a watchdog, in particular a cryptographically protected one, which is designed to trigger the integrity testing device to obtain an integrity test result.

[0031] This further development of the invention provides a robust mechanism for the continuous monitoring of the technical process. The cryptographically protected watchdog ensures that the integrity check process itself is secure and tamper-proof. By regularly triggering integrity checks, the watchdog helps to maintain constant vigilance for potential threats, enabling faster detection and response to security issues. This proactive approach significantly improves the overall security posture of the control unit according to the invention.

[0032] The control unit according to the invention preferably has an integrity monitoring device for monitoring the integrity of the control unit, wherein the integrity monitoring device is configured to trigger the integrity testing device.

[0033] This advantageous further development of the invention ensures comprehensive integrity monitoring. Through a dedicated integrity monitoring device that can trigger integrity checks, the control unit maintains a constant state of self-assessment. This multi-layered approach to integrity monitoring improves the system's ability to detect more subtle or complex attacks and enhances the overall resilience and reliability of the control unit in industrial environments.

[0034] In a preferred embodiment of the invention, the control unit is an automation device.

[0035] In this way, cyber resilience is also advantageously improved in the field of industrial automation. This is particularly important in environments where continuous operation and precision control are essential, such as in manufacturing plants or chemical reactors. 202415961 Foreign version

[0036] 6

[0037] The control unit according to the invention is particularly preferably an IoT device.

[0038] This further development of the invention advantageously addresses unique security challenges of IoT devices in industrial environments. By integrating advanced cyber resilience functions into IoT devices, the invention improves the security of networked industrial systems. This is particularly important given the increasing reliance on IoT technologies in industrial environments and the potential vulnerabilities introduced by their connectivity.

[0039] In a particularly preferred embodiment of the invention, the control unit is a manufacturing device.

[0040] The invention will now be explained in more detail with reference to an embodiment shown in the drawing.

[0041] The single drawing figure 1 shows a block diagram of a cyber-resilient industrial device schematically in a principle sketch.

[0042] This disclosure relates to the field of industrial control devices, in particular those with cyber resilience capabilities. In the context of the increasing digitization and networking of industrial systems, as found in the Internet of Things (IoT), the security and resilience of these systems against cyberattacks or manipulation is of growing importance.

[0043] Industrial control devices, such as programmable logic controllers (PLCs), are regularly used to control complex technical processes. These processes can range from controlling machines in a manufacturing plant to regulating conditions in a chemical reactor. The integrity and correct functioning of these control devices are crucial to ensuring the smooth operation of the technical processes they control.

[0044] However, due to their connection to external systems, these control units are vulnerable to cyberattacks or manipulation. Such attacks create vulnerabilities in the device's firmware or software, potentially leading to disruptions in technical processes, which can cause significant damage or even security risks. 202415961 Foreign version

[0045] 7

[0046] While solutions already exist to increase the resilience of these devices against cyberattacks, there remains a need for solutions that not only protect the control unit itself but also consider the state of the controlled physical process during a recovery operation. This is particularly important in scenarios where an attack on the control system could lead to significant damage to the physical system, such as blocked pipes in a food production line or the solidification of molten metal in a blast furnace.

[0047] Therefore, the present invention provides industrial control units with enhanced cyber resilience capabilities that take into account the state of the controlled physical process during a recovery operation. This approach aims to limit potential damage to the physical system affected by the controlled process and to ensure reliable and efficient recovery of the control unit and the technical process it manages.

[0048] Fig. 1 shows a cyber-resilient industrial IoT device CRIID, which forms a control unit within the meaning of this invention and which comprises a central processing unit (CPU), a security element (SE), a working memory (RAM), and a flash memory (F). The processing unit (CPU) is responsible for executing control software that manages the technical process. The security element (SE) provides secure storage for cryptographic keys and other sensitive data, while the working memory (RAM) and the flash memory (F) provide temporary and permanent storage, respectively, for the control software and data.

[0049] The cyber-resilient industrial IoT device CRIID also includes an input / output interface (IO) that connects to sensors (S) and actuators (A) involved in the technical process. The sensors (S) provide real-time data on the state of the technical process, while the actuators (A) execute actions based on control commands from the processor unit (CPU).

[0050] In some aspects, the cyber-resilient industrial IoT device CRIID includes a device runtime health check module (DRHC) and an authenticated watchdog (AW). The DRHC monitors the device's runtime integrity and checks for anomalies or signs of tampering. The AW, on the other hand, is a cryptographically protected watchdog that can trigger the DRHC.

[0051] 8. To obtain an integrity check result. If the device runtime health check module DRHC or the authenticated watchdog AW detects a potential security problem or anomaly, they can trigger a device resilience engine DRE to initiate appropriate resilience measures.

[0052] The Device Resilience Engine (DRE) interacts with the processor unit (CPU), the security element (SE), the RAM, and the flash memory (F) to execute these resilience measures. These measures can include halting the processor unit (CPU), writing a reference memory image to the flash memory (F), or deleting keys on the security element (SE). The Device Resilience Engine (DRE) is configured to execute these measures based on the integrity check result of the Device Runtime Health Check (DRHC) module or the authenticated watchdog (AW).

[0053] In some embodiments, the cyber-resilient industrial IoT device CRIID includes a protected process data store that continuously records process data of the technical process controlled by the device. This process data store provides a reliable record of the technical process's state, which can be crucial during a recovery operation.

[0054] The cyber-resilient industrial IoT device CRIID also includes a cyber resilience feature that implements at least one cyber resilience measure on the technical process, depending on the stored process data. These cyber resilience measures aim to limit potential damage to the physical system and ensure reliable and efficient recovery of the control unit and the technical process it manages.

[0055] In some aspects, the cyber-resilient industrial IoT device CRIID is configured to attest to the implementation of cyber resilience measures. This attestation can provide cryptographically protected confirmation that a resilience measure has been initiated or is being implemented, thus offering a reliable record of the resilience measures taken by the device. This can be particularly useful for documentation, auditing, or troubleshooting purposes.

[0056] According to Fig. 1, the cyber-resilient industrial IoT device CRIID can also include a physical process state monitor pwSM, which is connected to the input / output interface IO 202415961 (foreign version).

[0057] 9 is connected to monitor the state of the physical process. The process state monitor pwSM can acquire information by monitoring signals on the lines to sensor S and actuator A and / or by listening to the communication between the processor unit CPU and the input / output interface IO. In some cases, the processor unit CPU can explicitly provide information about the state of the physical world, such as a process image.

[0058] In some aspects, the cyber-resilient industrial IoT device CRIID can include a physical process simulator component, pwS. The process simulator component, pwS, can estimate future states of the physical process based on values ​​captured by the process simulator component, pwSM. This can be particularly useful for predicting the potential impact of a resilience measure on the physical process and enabling the device resilience engine, DRE, to select the most appropriate cyber resilience measure.

[0059] In some cases, the Device Resilience Engine (DRE) can generate a cryptographically protected resilience execution attestation. This attestation can confirm that a resilience action has been initiated or provide details about current, completed, or planned resilience actions. This can provide a reliable record of the resilience actions taken by the device, which can be useful for auditing or troubleshooting purposes.

[0060] In some aspects, the cyber-resilient industrial IoT device CRIID can have two separate resilience engines: a physical process resilience engine and a control function resilience engine. Each of these engines can be triggered by the device runtime health check module DRHC or the authenticated watchdog AW and perform resilience measures depending on the integrity check result and the state of the physical process. The physical process resilience engine can perform resilience measures that directly affect the physical process, such as flushing a pipe or moving a robot to a standard position. The control function resilience engine, on the other hand, can perform resilience measures that affect the device's control function, such as replacing the firmware or software on the device with a reference image.

[0061] In some cases, the state of the physical process is stored in non-volatile memory, such as flash memory (F) or battery-powered RAM. This is the foreign version (202415961).

[0062] Section 10 ensures that the state information is reliably available even in the event of a device restart or reboot. The Device Resilience Engine (DRE) can use this state information to perform appropriate resilience measures on the physical process during a recovery operation. For example, the DRE can stop the CPU, write a physical world recovery image to flash memory F, and start the CPU with this image to perform a recovery action in the physical world. After the recovery action is complete, the DRE can stop the CPU again, write a regular image to flash memory F, and start the CPU with this image.

[0063] The depicted cyber-resilient industrial IoT device CRIID is equipped with a range of specific cyber resilience measures designed to mitigate potential risks and maintain the operational integrity of the controlled physical processes. These measures are implemented by the device resilience engine DRE based on the stored process data and the integrity check result of the device runtime health check module DRHC or the authenticated watchdog AW.

[0064] In some aspects, cyber resilience measures can include flushing a fluid line, particularly a pipe. This action can be especially useful in scenarios where the technical process involves the transport of liquids, such as in a food production line or a chemical plant. By flushing the fluid line, the cyber-resilient industrial IoT device CRIID can prevent potential blockages or contamination of the line, thereby minimizing possible damage to the physical system.

[0065] In some cases, the cyber resilience measure may involve clearing a conveyor belt. This action can be advantageous in scenarios where the technical process involves transporting goods or materials on a conveyor belt. By clearing the conveyor belt, the cyber-resilient industrial IoT device CRIID can prevent potential blockages or disruptions in the transport process, thus ensuring the smooth operation of the technical process.

[0066] In some aspects, the cyber resilience measure can include activating a heater, particularly a minimum heater, for a melting process. This action can be crucial in scenarios where the technical process involves melting [202415961 foreign version].

[0067] 11

[0068] It contains materials similar to those found in a blast furnace. By activating the minimum heating, the cyber-resilient industrial IoT device CRIID can prevent the solidification of the molten material, thus avoiding potential damage to the furnace and ensuring the continuity of the melting process.

[0069] In some cases, the cyber resilience measure may involve moving a robot and / or an autonomous transport vehicle to a specific position, particularly a predetermined position and / or a default position. This action can be advantageous in scenarios where the technical process involves the use of robots or autonomous transport vehicles. By moving these units to a specific position, the cyber-resilient industrial IoT device CRIID can prevent potential collisions or disruptions in the operation of these units, thereby ensuring the smooth running of the technical process.

[0070] In some aspects, the cyber resilience measure can involve reorganizing a tool magazine, specifically establishing a default tool configuration within the magazine. This action can be useful in scenarios where the technical process involves the use of a tool magazine, such as in a manufacturing plant. By reorganizing the tool magazine, the cyber-resilient industrial IoT device CRIID can ensure that the correct tools are available in the correct positions, thus guaranteeing the smooth operation of the manufacturing process.

[0071] The cyber-resilient industrial IoT device CRIID, as previously described, is equipped with a process data logger that continuously records process data from the technical process controlled by the device. This process data logger provides a reliable record of the technical process's state, which can be crucial during a recovery operation.

[0072] In some aspects, the process data storage is formed using a ring buffer. A ring buffer, also known as a circular buffer or ring buffer, is a data structure that uses a single, fixed buffer as if it were connected at the ends. This structure is well-suited for buffering data streams. In the context of the cyber-resilient industrial IoT device CRIID, the ring buffer can store a sequence of process data, such as the most recently captured process image, past process images, and / or the foreign version.

[0073] 12. At least one status piece of information about the controlled technical process. When the buffer is full, new data is written to the beginning of the buffer, overwriting the old data. In some cases, the process data memory is formed using non-volatile memory. Non-volatile memory is a type of computer memory that can retain the stored information even after the power supply is switched off. Examples of non-volatile memory include the previously mentioned Flash memory (F) or Electrically Erasable Programmable Read-Only Memory (EEPROM), Non-Volatile Random Access Memory (NVRAM), Magnetoresistive RAM (MRAM), Ferroelectric RAM (FeRAM or FRAM), Phase-Change Memory (PCM), and Battery-backed Static Random Access Memory (SRAM). The use of non-volatile memory ensures that the process data is reliably available even in the event of a device restart or reboot.

[0074] In some aspects, the Device Resilience Engine (DRE) can halt the central processing unit (CPU), write a physical process recovery image to flash memory F, and restart with this process recovery image to perform a physical process recovery action. This recovery action can be based on the stored process data and the integrity check result from the Device Runtime Health Check Module (DRHC) or the authenticated watchdog (AW). For example, the recovery action might involve operating a machine in a material-flow-free and / or workpiece-free state. This action can be advantageous in scenarios where the engineering process involves the processing or manufacturing of workpieces.By operating the machine in a material flow-free and / or workpiece-free state, the cyber-resilient industrial IoT device CRIID can prevent potential blockages or disruptions in the processing or manufacturing process, thus ensuring the smooth operation of the technical process.

[0075] Once the recovery process is complete, the Device Resilience Engine (DRE) can stop the processor unit (CPU) again, write a regular image to the flash memory (F), and then start the processor unit (CPU) with that image. This ensures that the cyber-resilient industrial IoT device (CRIID) returns to normal operation after the recovery process and is ready to continue controlling the engineering process.

[0076] The depicted cyber-resilient industrial IoT device CRIID can be implemented in various contexts, for example as an automation device, IoT device, and / or manufacturing device. 202415961 Foreign version

[0077] 13

[0078] In some aspects, the cyber-resilient industrial IoT device CRIID, when implemented as an automation device, can be responsible for controlling a wide range of automated processes, such as those found in manufacturing plants, chemical reactors, or power plants. The device's cyber resilience features, including the Device Resilience Engine (DRE), the Device Runtime Health Check Module (DRHC), and the Authenticated Watchdog (AW), can provide robust protection against potential cyberattacks or tampering. These features can ensure the smooth operation of automated processes by initiating appropriate resilience measures based on stored process data and integrity check results.

[0079] In some cases, the cyber-resilient industrial IoT device CRIID, when implemented as an IoT device, can be part of a larger network of interconnected devices, sensors S, and actuators A. The cyber resilience measures of the cyber-resilient industrial IoT device CRIID can provide robust protection against potential cyberattacks or tampering that could exploit the device's connectivity with external systems. For example, the device resilience engine DRE can initiate resilience measures such as halting the processor unit CPU, writing a reference memory image to the flash memory F, or deleting keys on the security element SE, thereby ensuring the integrity and correct functioning of the cyber-resilient industrial IoT device CRIID.

[0080] In some aspects, the cyber-resilient industrial IoT device CRIID, when implemented as a manufacturing device, can be responsible for controlling complex manufacturing processes, such as those found in a production line. The device's cyber resilience functions can provide robust protection against potential cyberattacks or manipulations that could disrupt the manufacturing process and cause significant damage or security risks. For example, the device resilience engine DRE can initiate resilience measures, such as operating a machine in a material-flow-free and / or workpiece-free state, thereby ensuring the smooth operation of the manufacturing process.

[0081] In other embodiments, which are identical in all other aspects to the embodiment shown, the cyber-resilient industrial IoT device CRIID can be implemented in other contexts, such as energy management systems, transportation systems, or healthcare systems. Regardless of the specific context, the cyber resilience- 202415961 Foreign version

[0082] 14

[0083] The device's functions provide robust protection against potential cyberattacks or manipulations, thus ensuring the smooth operation of the technical processes it controls.

Claims

202415961 Foreign version 15 Patent claims 1. Control unit with an access-protected process data storage that continuously stores process data of a technical process controlled by the control unit, and a cyber resilience device (DRE) in which the cyber resilience device (DRE) performs at least one cyber resilience measure on the technical process depending on the stored process data of the process data storage.

2. Control unit according to claim 1, wherein the cyber resilience measure comprises one or more of the measures listed below: - flushing a fluid line, especially a pipe, - clearing a conveyor belt, - activating a heating system, especially a minimum heating system, or a melting process - a movement of a robot and / or an autonomous transport vehicle into a specific position, in particular a predetermined position and / or a default position - a reorganization of a tool magazine, in particular the creation of a default configuration of tools in or around the tool magazine - operating a machine in a material flow-free and / or workpiece-free state.

3. Control unit according to one of the preceding claims, wherein the control data comprise a process image, in particular a most recent past captured process image, and / or past process images and / or at least one status information on the controlled technical process.

4. Control unit according to one of the preceding claims, which is configured to restore and / or resume the technical process based on the process data.

5. Control unit according to the preceding claim, which is configured to restore and / or resume the technical process by implementing the cyber resilience measure.

6. Control unit according to one of the preceding claims, wherein the process data memory comprises a ring data memory, and / or a non-volatile memory, in particular a flash memory (F) and / or an EEPROM and / or a non-volatile random access memory and / or a magnetoresistive RAM and / or a ferroelectric 202415961 Foreign version 16 RAM and / or a Phase-Change Memory and / or a Battery-backed SRAM.

7. Control unit according to one of the preceding claims, which is configured to certify the implementation of the cyber resilience measure.

8. Control unit according to one of the preceding claims with an integrity control unit (DRHC) which is designed to perform the cyber resilience measure depending on an integrity test result of the integrity control unit (DRHC).

9. Control unit according to one of the preceding claims, which has a watchdog (AW) which is in particular cryptographically protected and which is designed to trigger the integrity control unit (DRHC) to obtain an integrity control result.

10. Control unit according to one of the preceding claims, which has an integrity monitoring device for monitoring the integrity of the control unit, wherein the integrity monitoring device is configured to trigger the integrity testing device (DRHC).

11. Control unit according to one of the preceding claims, which is an automation device.

12. Control unit according to one of the preceding claims, which is an IoT device.

13. Control unit according to one of the preceding claims, which is a manufacturing device.

14. Industrial plant with a control unit according to one of the preceding claims, in particular a manufacturing plant.

Citation Information

Patent Citations

  • Intelligent programmable logic controller and memory access management method thereof

    EP3067765A1

  • Mechanism for testing a sequence of process images

    EP3739835A1

  • Method for operating a process engineering system, and process engineering system

    WO2021078411A1