Industrial Apparatus Confirmation Unit for Updateable Cryptographic Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial devices face challenges in maintaining long-term reliable attestation functionality due to the inability to update cryptographic algorithms and hardware-implemented systems, especially in the face of advancements like quantum computing, which can weaken existing security measures.
Innovation Solution
A computer-based industrial device with a confirmation unit providing additional cryptographic protection, enabling long-term attestation through integrity measurements and updateable confirmation certificates, ensuring the integrity attestation can be reliably evaluated even if cryptographic methods are weakened.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware-based attestation unit is used, then the integrity measurement can be reliably stored, but the cryptographic protection cannot be updated
Solution Approach 1:
The system is divided into two separate units: an attestation unit that stores integrity measurements and a confirmation unit that provides cryptographic protection. This segmentation allows each unit to have specialized functionality - the attestation unit reliably stores measurements while the confirmation unit can be updated with new cryptographic algorithms.
Solution Approach 2:
The confirmation unit acts as an intermediary between the attestation unit and the external world. It receives integrity measurements from the attestation unit, applies cryptographic protection using updateable algorithms, and outputs confirmed attestation data. This intermediary role enables cryptographic updates without affecting the attestation storage functionality.
2Reliability
If cryptographic algorithms are updated, then long-term security is improved, but the hardware attestation unit cannot be updated
Solution Approach 1:
The confirmation unit is designed with dynamic update capability, allowing its cryptographic algorithms to be changed over time. This dynamic nature enables the system to adapt to new security threats and quantum computing advancements while maintaining the static, reliable integrity measurement storage function of the attestation unit.
Solution Approach 2:
The system changes the parameter of cryptographic algorithms in the confirmation unit without changing the fundamental structure or updateability of the attestation unit. This allows long-term security improvement through algorithm updates while maintaining the hardware-based reliability of integrity measurement.
3Adaptability or versatility
If a separate confirmation unit is added, then updateable cryptographic protection is enabled, but device complexity increases
Solution Approach 1:
The confirmation unit is designed as a multi-functional component that handles cryptographic key management, algorithm execution, and attestation confirmation. By consolidating these functions into a single unit, the system achieves updateable cryptographic protection without proportionally increasing overall system complexity.
Data Source
Figure 1~3
Figure 4
Figure 5~6
AI summary
The invention relates to a computer-supported industrial device (1), comprising: a number of integrity measuring units (2), each of which is designed to provide an integrity measurement value (IM), an attestation unit (3) for providing an integrity attestation (IA), which is protected by a first cryptographic protection (DS1), for specifying the integrity of the industrial device (1) or a part of the industrial device (1), wherein the integrity attestation (IA) has at least a number of provided integrity measurement values (IM), and a confirmation unit (5) which is connected to the attestation unit (3) via a physically protected transmission path (4) and which comprises: a checking unit (6) for providing checking information (PI) by checking at least one state of the confirmation unit (5) and/or the industrial device (1) and an issuing unit (7) for issuing a confirmation attestation (BA), which is protected by a second cryptographic protection (DS2), on the basis of the provided checking information (PI). The confirmation attestation (BA) comprises at least the number of integrity measurement values (IM) of the integrity attestation (IA) and information which can be derived from the first cryptographic protection (DS1) of the integrity attestation (IA).