Safety Data Checksums for Control Device Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for creating or changing safety-relevant data in control devices are prone to manipulation and errors, particularly due to the complexity of the process and the risk of incorrect program activation during startup, which can compromise industrial or personal safety.
Innovation Solution
A method involving the creation of checksums and an encrypted enable code allows for secure and flexible creation or change of safety-relevant data, enabling offline data management and transmission using portable storage media, with additional safety checks and authorization to prevent erroneous activation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional methods are used to create or change safety-relevant data in control devices, then the process is simple and direct, but the data are prone to manipulation and errors, compromising safety
Solution Approach 1:
The patent applies preliminary action by pre-calculating and storing checksums and encrypted enable codes in the data record before transmission to the control device. This allows validation to be performed later without adding complexity to the data creation process, as the safety mechanisms are prepared in advance.
Solution Approach 2:
The patent introduces checksums and encrypted enable codes as intermediary elements between the data processing installation and the control device. These intermediaries serve as mediators that verify data integrity and authorize activation, preventing direct manipulation while maintaining a structured process.
2Reliability
If multiple validation steps are implemented to prevent manipulation, then data integrity is improved, but the process becomes more complex and time-consuming
Solution Approach 1:
By pre-calculating checksums and encrypted enable codes during data creation, the patent eliminates the need for time-consuming validation calculations during activation. The control device can quickly verify data integrity by comparing stored checksums, significantly reducing validation time.
Solution Approach 2:
The data record structure enables self-validation through embedded checksums and enable codes. The control device autonomously verifies data integrity and authorization without requiring external validation systems, reducing both process complexity and time requirements.
3Reliability
If checksums and encrypted enable codes are used to verify data, then security against manipulation is enhanced, but the data structure becomes more complex
Solution Approach 1:
The patent merges the safety validation mechanisms (checksums and encrypted enable codes) directly into the data record structure itself. By combining these security elements with the safety-relevant data in a unified record format, the system avoids separate complex validation structures while maintaining enhanced security.
Solution Approach 2:
The data record structure serves multiple functions simultaneously: it stores safety-relevant data, contains integrity verification through checksums, and provides authorization through encrypted enable codes. This multi-functionality reduces the need for separate structures for each function, managing complexity while enhancing security.
4Ease of operation
If offline data management is implemented using portable storage media, then flexibility and ease of operation are improved, but the risk of transmission errors increases
Solution Approach 1:
The patent uses checksums as intermediary verification elements that accompany safety-relevant data during offline transmission via portable storage media. These checksums act as mediators that enable the control device to detect and reject transmission errors, maintaining reliability while preserving the flexibility of offline data management.
Data Source
AI summary
A system and method for changing safety-relevant data for a control device is provided wherein an authorized user inputs new or altered safety-relevant data, which is received on a data processing installation. A first checksum for the safety-relevant data is established and stored along with the safety-relevant data in at least one data record on the data processing installation. An enable code may also be stored in the at least one data record. This enable code may be produced by a code generator and encrypted by a key module. The data processing installation then reads back the safety-relevant data from a memory in the data processing installation, thereby allowing a comparison of the received safety-relevant data and the read back safety-relevant data. A second checksum is generated in a case where the comparison resulted in no differences. The second checksum may also be stored in the at least one data record. At least one new data record containing the safety-relevant data, the encrypted enable code and the first and second checksums is created and transmitted to the control device. The new data record is checked against prior data records and prior checksums stored on a storage medium to determine that the at least one new data record is known to the control device.


