Computer Program Verification Using Activation Code Seal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for verifying the operationally safe state of safety-critical systems, such as railway safety systems, fail to prevent a computer from being activated with potentially faulty software before it is confirmed to be error-free and running on the intended system, leading to a gap where the computer can operate undetectably in a non-secure state.

Innovation Solution

A method that uses a start-up seal, linked with the program code and computer identification number, to ensure the program is correctly stored and verified before allowing external operation, with the activation code being calculated in a non-reloadable program memory area and only enabling the output module if the expected values match, preventing external activation without proper verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the computer is allowed to run programs before verification, then productivity is improved (faster software updates), but reliability deteriorates (computer may run with faulty or incorrect programs)

Engineering Contradiction:
Improvesoftware update speedVSAvoidprogram correctness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by verifying the program code and computer identification number before allowing the computer to run the program. The activation code is checked in advance, and only after successful verification is the computer permitted to execute the loaded program, thus ensuring reliability before productivity is realized.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism - the activation code and verification routine act as a mediator between program loading and program execution. This intermediary layer checks whether the program is correctly stored on the correct computer before allowing external effects, resolving the contradiction between fast updates and reliable execution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual verification is required before computer activation, then reliability is improved (operator can confirm safety), but productivity deteriorates (activation process is slower)

Engineering Contradiction:
Improveoperational safetyVSAvoidactivation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies self-service by implementing an automated verification routine that checks the activation code, program code, and computer identification number without requiring manual operator intervention. The system verifies safety conditions automatically and activates the computer based on the verification result, thus improving productivity while maintaining reliability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the output module is enabled before verification, then ease of operation is improved (computer can communicate immediately), but harmful factors increase (computer can activate with faulty programs)

Engineering Contradiction:
Improvecommunication availabilityVSAvoidunauthorized activation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preventing the output module from being enabled until verification is complete. The system proactively blocks the harmful effect of unauthorized activation by keeping the output module disabled during the verification process, and only enables it after confirming the program is correct and the computer is the intended target.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2992426B1Method for verifying an operationally safe state of a computer
Publication Date: 2018.11.28 SIEMENS MOBILITY GMBH

AI summary

The invention relates to a method for verifying an operationally safe state of a computer for controlling a safety-critical system, particularly a railroad safety system, wherein a safety gap is closed by the following steps: 1. a loaded computer program or the program code thereof and a computer identification number are read back and compared to first expectation values, 2. a startup code valid exclusively for the intended combination of computer program and computer identification number is stored in a non-rewritable non-volatile program memory region of the computer, and 3. the non-rewritable non-volatile program memory region of the computer links the startup code to the program code of the computer program and the computer identification number to form an activation code which activates an output module of the computer in case of agreement with a second expectation value.