Software Package Signatures for Automated Modification Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying and verifying software packages in machine tools are inefficient due to non-standardized metadata formats, difficulty in accessing storage formats, and the lack of automated detection of modifications, leading to manual verification efforts.
Innovation Solution
Generating and comparing hash values of digital objects within software packages, such as memory images of PLCs, CNCs, and HMIs, to create unique signatures that allow for automated identification and integrity checks, independent of proprietary systems, using predefined rules to select significant digital objects and combining hash values into signatures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If non-standardized metadata formats are used for software package identification, then software packages can be stored with their identification information, but automated identification becomes difficult or impossible
Solution Approach 1:
The patent creates a standardized copy (signature) of the software package by generating a hash value from the binary data. This signature serves as a universal representation that can be automatically compared and identified, replacing the need for non-standardized metadata formats while enabling automated identification processes.
Solution Approach 2:
The patent transforms the software package identification from using diverse metadata formats to using a standardized hash value parameter. By changing the identification parameter from human-readable metadata to a computed hash signature, the system achieves both information preservation and automated identification capability.
2Reliability
If manual verification methods are used to detect software modifications, then modification detection can be achieved, but considerable time and effort are required
Solution Approach 1:
The patent creates a signature copy (hash value) of the software package that can be quickly regenerated and compared. This signature serves as a efficient proxy for verification, maintaining high reliability in detecting modifications while dramatically reducing the time and effort required compared to manual verification of all software components.
Solution Approach 2:
The patent replaces the mechanical manual verification process with an automated computational system that generates and compares hash signatures. This substitution eliminates the need for human intervention in verification while maintaining accurate detection of software modifications.
3Ease of manufacture
If proprietary storage formats are used for software packages, then software can be stored with its specific format requirements, but access to identification information becomes difficult
Solution Approach 1:
The patent creates a format-independent signature copy (hash value) from the proprietary software package. This signature can be generated from the binary data regardless of the original storage format, enabling easy access to identification information without requiring knowledge of or access to the proprietary storage format itself.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method for generating and comparing signatures of software packages. Various digital objects are identified that are associated with a software package. From these digital objects, a hash value for each individual digital object can then be generated using a hashing method. These hash values can then be combined as a signature for the software package. This type of signature allows for the unambiguous identification of a specific software package, a version of a software package, or a specific variant of a software package. If these hash values are stored when the software package is created, it is later possible to easily and reliably verify, in all possible applications, for example, in software for machine tools, whether it is a modified variant of the software package, an outdated version of the software package, or something similar.In this way, follow-up measures after such a review can ensure that only variants approved by the software developer are used for their intended purpose. This increases safety, particularly for software used on machine tools, where unintended modification can lead to significant damage.