Method for barricading security related data processing systems against influence of other data networks and apparatus for carrying out the method
Abstract
The method involves securing data processor arrangements against unintentional and inadmissible influence from other data networks, with which the data processors are connected over communication services. A filter function is used, to delete all messages, which are recognised as ambiguous with respect to their safety. The data messages delivered over the communication services are filtered in at least two independent observation units connected in series with each other, and preceding the security-related data processor. The messages are encoded in a first observation unit and are decoded again in the second observation unit which follows in the data transfer direction. Test data are formed, at least indirectly, through programs and necessary unchangeable data implemented in both observation units, and are compared with the reference data stored in the observation units and/or test- and/or reference data originating in the partner observation unit. If a test is not successfully completed within a defined crash recognition time, the observation unit which recognised the crash is irreversibly switched off.

Term
Term ended
Projected expiry passed 10 September 2018, 8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
18 claims: 18 independent, 0 dependent
- 1A method for partitioning of safety-related data processing systems against unintended and undue influence out from other data networks, with which the data processing system on communications services in connection is, by applying a filter function according to which all Telegrams are deleted that are not unequivocally considered fail safely be detected, marked by following features:1) via the communication services (D3) supplied data telegrams be in at least two independent, the upstream security-related data processing system (BLZ) and series-viewing units (PC1, PC2) filtered.2) The messages are in a first viewing unit (PC1) encrypted (V) and is in data transfer direction following second viewing unit (PC2) again decrypted (E).3) are implemented, in two viewing units Programs (F, VG) and if necessary fixed data (PD1, PD2) are formed at least indirectly and test data with stored in the viewing units reference data and / or originating from the partner-viewing unit Testing - and / or reference data is compared for a match.4) If a testing not within a defined successfully failure disclosure time is the observation unit, which has found that, irreversible off. Verfahren zum Abschotten sicherheitsrelevanter Datenverarbeitungsanlagen gegen ungewollte und unzulässige Beeinflussung aus anderen Datennetzen heraus, mit denen die Datenverarbeitungsanlage über Kommunikationsdienste in Verbindung steht, durch Anwendung einer Filterfunktion, nach der alle Telegramme gelöscht werden, die nicht zweifelsfrei als signaltechnisch unbedenklich erkannt werden, gekennzeichnet durch folgende Merkmale: 1) Die über die Kommunikationsdienste (D3) angelieferten Datentelegramme werden in mindestens zwei unabhängigen, der sicherheitsrelevanten Datenverarbeitungsanlage (BLZ) vorgeschalteten und in Reihe geschalteten Betrachtungseinheiten (PC1, PC2) gefiltert.2) Die Telegramme werden in einer ersten Betrachtungseinheit (PC1) verschlüsselt (V) und in der in Datentransferrichtung folgenden zweiten Betrachtungseinheit (PC2) wieder entschlüsselt (E).3) Über die in beiden Betrachtungseinheiten implementierten Programme (F, VG) und ggf. unveränderlichen Daten (PD1, PD2) werden mindestens mittelbar Prüfdaten gebildet und mit in den Betrachtungseinheiten hinterlegten Referenzdaten und/oder von der Partner-Betrachtungseinheit stammenden Prüf - und/oder Referenzdaten auf Übereinstimmung verglichen.4) Wird eine Prüfungen nicht innerhalb einer definierten Ausfalloffenbarungszeit erfolgreich abgeschlossen, wird die Betrachtungseinheit, die das festgestellt hat, irreversibel abgeschaltet.
- 2The method of claim 1, characterized, that if not successfully completed testing testing possibly repeated several times until the expiration of failure disclosure time becomes. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß bei nicht erfolgreich abgeschlossener Prüfung die Prüfung ggf. mehrfach bis zum Ablauf der Ausfalloffenbarungszeit wiederholt wird.
- 3The method of claim 1 or 2, characterized, that during commissioning of the data processing system in both viewing units (PC1, PC2) an identifier (FS) as absorbed. Release key is entered, the numerical value according to a predetermined algorithm in the calculation of Test data flows, that for each cooperating viewing units same release key will be awarded, that this release key for each observation unit an exclusive identity are linked, that fixed for the peer review of the programs and if necessary Data each considered exclusive Identification of the test data is eliminated again and that if not successful within the failure disclosure time deleted concluded its consideration of the release key becomes. Verfahren nach Anspruch 1 oder 2, dadurch gekennzeichnet, daß bei der Inbetriebnahme der Datenverarbeitungsanlage in beide Betrachtungseinheiten (PC1, PC2) eine Kennung (FS) als sogen. Freigabeschlüssel eingegebenen wird, deren Zahlenwert nach einem vorgegebenen Algorithmus in die Berechnung der Prüfdaten einfließt, daß für die jeweils zusammenwirkenden Betrachtungseinheiten gleiche Freigabeschlüssel vergeben werden, daß diese Freigabeschlüssel für jede Betrachtungseinheit mit einer exklusiven Kennung verknüpft werden, daß für die gegenseitige Prüfung der Programme und ggf. unveränderlichen Daten die jeweils berücksichtigte exklusive Kennung aus den Prüfdaten wieder herausgerechnet wird und daß bei innerhalb der Ausfalloffenbarungszeit nicht erfolgreich abgeschlossener Prüfung der Freigabeschlüssel gelöscht wird.
- 4A method according to claim 3, characterized, that the input of the release key by an operator Hand and Einrechnen the respective exclusive identifier in and the Eliminating these identifier from the by ID modified input key by an automatic is made. Verfahren nach Anspruch 3, dadurch gekennzeichnet, daß die Eingabe der Freigabeschlüssel durch einen Bediener von Hand und das Einrechnen der jeweiligen exklusiven Kennung in sowie das Herausrechnen dieser Kennung aus dem durch eine Kennung modifizierten Eingabeschlüssel durch eine Automatik vorgenommen wird.
- 5Device for carrying out the method according to the Claims 1 to 4, characterized, that for the viewing units (PC1, PC2) data processing devices are used, their operating systems manufacturer do not include communication services and the only the user side by specified communication services (D1 to D3) are complemented, or their communication services except for certain, selectable by the user Communication Services are eliminated, that each data processing device for reference memory which on its programs (F, VG) and if necessary fixed data (PD) formed test data and means for prompting for and processing the data by the partner data processing device and to transmit such data to having the partner data processing device, that each data processing device an encryption or decryption device (V, E) for the respectively supplied having data telegrams via a separated outward internal point-to-point connection (IV) communicate with each other and that each data processing device a at startup and restart, as well as successful completion of Review of the programs and if necessary fixed data triggerable comprises timer, the switching time of the allowable maximum Cycle aftermath of the tests consists of and with Expiry of him impressed switching time the release key (FS) extinguished and the deactivation of the associated data processing device causes. Einrichtung zur Durchführung des Verfahrens nach einem der Ansprüche 1 bis 4, dadurch gekennzeichnet, daß für die Betrachtungseinheiten (PC1, PC2) Datenverarbeitungseinrichtungen verwendet sind, deren Betriebssysteme herstellerseitig keine Kommunikationsdienste beinhalten und die erst anwenderseitig durch spezifizierte Kommunikationsdienste (D1 bis D3) ergänzt werden, oder deren Kommunikationsdienste mit Ausnahme bestimmter, vom Anwender auswählbarer Kommunikationsdienste eliminiert werden, daß jede Datenverarbeitungseinrichtung Referenzspeicher für die über ihre Programme (F, VG) und ggf. unveränderlichen Daten (PD) gebildeten Prüfdaten sowie Einrichtungen zum Abfordern und Verarbeiten der Daten durch die Partner-Datenverarbeitungseinrichtung sowie zum Übermitteln solcher Daten an die Partner-Datenverarbeitungseinrichtung aufweist, daß jede Datenverarbeitungseinrichtung eine Ver- bzw. Entschlüsselungseinrichtung (V, E) für die jeweils zugeführten Datentelegramme aufweist, die über eine nach außen abgetrennte interne Punkt-zu-Punkt-Verbindung (IV) miteinander kommunizieren und daß jede Datenverarbeitungseinrichtung einen bei Inbetriebnahme und bei Neustart sowie bei erfolgreich abgeschlossener Prüfung der Programme und ggf. unveränderlichen Daten triggerbaren Timer aufweist, dessen Schaltzeit der zulässigen maximalen Zyklusfolgezeit der Prüfungen entspricht und der mit Ablauf der ihm eingeprägten Schaltzeit den Freigabeschlüssel (FS) löscht und die Abschaltung der zugehörigen Datenverarbeitungseinrichtung veranlaßt.
- 6Device according to claim 5, characterized, that the program check (ZP) the cyclical inspection at least the filter and the comparison functions (F, VG) of the individual Data processing means (PC1, PC2) includes. Einrichtung nach Anspruch 5, dadurch gekennzeichnet, daß die Programmprüfung (ZP) die zyklische Prüfung mindestens der Filter- und der Vergleichsfunktionen (F, VG) der einzelnen Datenverarbeitungseinrichtungen (PC1, PC2) beinhaltet.
- 7Device according to claim 5 or 6, characterized, that for reasons of redundancy, at least two of two series-connected data processing devices (PC1, provided PC2) existing data processing systems (ST) are separated from each other and work independently and that in regard to the transfer of data telegrams the restricted area of safety-related data processing system from one or the other system coordination the data processing systems is provided. Einrichtung nach Anspruch 5 oder 6, dadurch gekennzeichnet, daß aus Redundanzgründen jeweils mindestens zwei aus je zwei in Reihe geschalteten Datenverarbeitungseinrichtungen (PC1, PC2) bestehende Datenverarbeitungssysteme (ST) vorgesehen sind, die voneinander getrennt sind und eigenständig arbeiten und daß hinsichtlich der Weitergabe von Datentelegrammen in den geschützten Bereich der sicherheitsrelevanten Datenverarbeitungsanlage aus dem einen oder anderen System eine Koordinierung der Datenverarbeitungssysteme vorgesehen ist.
- 8Device according to claim 7, characterized, that each data processing system at least one interface module Connects to a public data network and an own interface for connecting Haug Ruppe the protected data network of security-related data processing system having. Einrichtung nach Anspruch 7, dadurch gekennzeichnet, daß jedes Datenverarbeitungssystem mindestens eine Schnittstellenbaugruppe zum Anschließen eines öffentlichen Datennetzes sowie eine eigene Schnittstellenhaugruppe zum Anschließen des geschützten Datennetzes der sicherheitsrelevanten Datenverarbeitungsanlage aufweist.
- 9Device according to claim 8, characterized, that to the public networks towards each multiple, possibly on different transmission protocols tailored different are interface modules provided. Einrichtung nach Anspruch 8, dadurch gekennzeichnet, daß zu den öffentlichen Netzen hin jeweils mehrere, ggf. auf unterschiedliche Übertragungsprotokolle abgestimmte unterschiedliche Schnittstellenbaugruppen vorgesehen sind.
- 10Device according to one of claims 5 to 9, characterized, that each of the two data processing devices as a master data processing device acts and testing their programs and if necessary fixed data based on itself determined or stored in it and of the each partner computing device inquired Test and / or reference data causes. Einrichtung nach einem der Ansprüche 5 bis 9, dadurch gekennzeichnet, daß jede der beiden Datenverarbeitungseinrichtungen als Master-Datenverarbeitungseinrichtung fungiert und die Prüfung ihrer Programme und ggf. unveränderlichen Daten anhand von selbst ermittelten oder bei ihr abgespeicherten und von der jeweiligen Partner-Datenverarbeitungseinrichtung erfragten Prüf- und/oder Referenzdaten veranlaßt.
- 11A device according to claim 10, characterized, that at the individual data processing devices in addition own reference data also, different reference data stored for the partner data processing device are in need, instead of own reference data to each retrieving data processing device are to be transmitted. Einrichtung nach Anspruch 10, dadurch gekennzeichnet, daß bei den einzelnen Datenverarbeitungseinrichtungen neben eigenen Referenzdaten auch möglicherweise abweichende Referenzdaten für die Partner-Datenverarbeitungseinrichtung hinterlegt sind, die bedarfsweise anstelle der eigenen Referenzdaten an die jeweils abrufende Datenverarbeitungseinrichtung zu übermitteln sind.
- 12Device according to claim 10 or 11, characterized, that each data processing device for the examination of their Programs and possibly a fixed data with a Time stamp, a given by a law consecutive number or a random number provided request transmitted to the partner data processing device, that the partner data processing means these Identification in a requested test and / or reference data including retaining Prüfergebnistelegramm inserts and this to the received and that requesting data processing device this in addition to the partner data processing device derived test and reference data, the transmitted identification in accordance with the respective emitted identifier rated. Einrichtung nach Anspruch 10 oder 11, dadurch gekennzeichnet, daß jede Datenverarbeitungseinrichtung für die Prüfung ihrer Programme und ggf. unveränderlichen Daten eine mit einem Zeitstempel, einer nach einer vorgegebenen Gesetzmäßigkeit fortlaufenden Nummer oder einer Zufallszahl versehene Anforderung an die Partner-Datenverarbeitungseinrichtung übermittelt, daß die Partner-Datenverarbeitungseinrichtung diese Kennung in ein die angeforderten Prüf- und/oder Referenzdaten beinhaltendes Prüfergebnistelegramm einfügt und dieses an die anfordernde Datenverarbeitungseinrichtung übermittelt und daß diese neben den von der Partner-Datenverarbeitungseinrichtung stammenden Prüf- und Referenzdaten auch die übermittelte Kennung auf Übereinstimmung mit der jeweils ausgesandten Kennung bewertet.
- 13Device according to one of claims 10 to 12, characterized. that in each data processing device triggering the has made its own timer dependent upon within the fitting at least one cycle of the Prüfanstoß Partner data processing device has been received. Einrichtung nach einem der Ansprüche 10 bis 12, dadurch gekennzeichnet, daß in jeder Datenverarbeitungseinrichtung das Triggern des eigenen Timers davon abhängig gemacht ist, daß innerhalb des anliegenden Prüfzyklus mindestens ein Prüfanstoß von der Partner-Datenverarbeitungseinrichtung empfangen wurde.
- 14Device according to one of claims 5 to 13, characterized. that for each data processing device of the respective through their exclusive identifier modified release key in dedicated RAM cells is deposited. Einrichtung nach einem der Ansprüche 5 bis 13, dadurch gekennzeichnet, daß für jede Datenverarbeitungseinrichtung der durch ihre jeweilige exklusive Kennung modifizierte Freigabeschlüssel in dafür vorgesehenen RAM-Zellen hinterlegt ist.
- 15Device according to one of claims 5 to 14, characterized, that the two data processing devices at the end their failure disclosure time incident reports to the respective connected or protected PUBLIC data network to transfer. Einrichtung nach einem der Ansprüche 5 bis 14, dadurch gekennzeichnet, daß die beiden Datenverarbeitungseinrichtungen beim Ablauf ihrer Ausfalloffenbarungszeit Störungsmeldungen an das jeweils angeschlossene geschützte bzw. offentliche Datennetz übermitteln.
- 16Device according to one of claims 5 to 15, characterized, that the data processing devices in a room with access authorization are housed. Einrichtung nach einem der Ansprüche 5 bis 15, dadurch gekennzeichnet, daß die Datenverarbeitungseinrichtungen in einem Raum mit Zugangsberechtigung untergebracht sind.
- 17Device according to one of claims 5 to 16, characterized, that the data processing system at least one file to Logging of classified signally harmless Telegrams and means for at least quantitative has reviewed these telegrams. Einrichtung nach einem der Ansprüche 5 bis 16, dadurch gekennzeichnet, daß die Datenverarbeitungsanlage mindestens eine Datei zur Protokollierung der als signaltechnisch unbedenklich eingestuften Telegramme und Mittel zur mindestens mengenmäßigen Bewertung dieser Telegramme aufweist.
- 18Device according to one of claims 5 to 17, characterized, that the data processing system and / or the data processing means Error reporting files rejected for logging Telegrams are assigned. Einrichtung Nach einem der Ansprüche 5 bis 17, dadurch gekennzeichnet, daß der Datenverarbeitungsanlage und/oder den Datenverarbeitungseinrichtungen Fehlermeldedateien zur Protokollierung zurückgewiesener Telegramme zugeordnet sind.
Independent claims18
38 paragraphs, as filed
The invention relates to a method according to the preamble of claim 1 and to a method of this applying means.
For the operation of electronic interlocking systems used which graphically the process states the grounds on monitors represent and commands from operators to the appropriate technology forward (company publication Siemens AG, Order No .: A19100 / V100 / B412 from the year 1992 'Safety for railways. The electronic interlocking "). Each system receives messages to at least the associated electronic interlocking and releases a Zugnummern-alarm system, a Zuglenksystems and other Techniques. For interlocking operations with responsibility for security be tested for completeness and correctness Message pictures required and handled a defined operating procedure (EP 0120339 B1).
To the "outside" to avoid any negative effects of the channels of communication are between components to handle the defined previously "closed" operating procedures, ie there is no direct connection to a public data network. Because of these closed channels of communication, it is previously impossible process secured message pictures or operating procedures from the outside by means of intelligent traffic (Hackers) to change.
Unlike the aforementioned constellation of a self-contained Data processing system in the future operational data from z. B. ground control computer-assisted, Zugüberwachungen and reporting and surveillance systems for cost reasons, at least in part on public Data networks have to be conducted. To view this data in the protected The field of electronic interlockings and control centers feed, is a coupling to be protected the Area required with the public data network. These Coupling is to be executed so that no safety from the outside Actions in the switchboard or the control center can be made.
The object of the present invention, a method is claimed specify the preamble of claim 1, which in the Location is all influences from outside on the to protecting internal data network to a data processing system To prevent the security implications of the of could have there process to be controlled events; it is further object of the invention to provide a means by of this method can be implemented technically.
The inventive method is through the preamble and listed in the characterizing part of claim 1 in features. It is based on the consideration filter out through a filtering process all telegrams and make them ineffective, that do not reliably considered fail can be classified harmless. Successful attacks to the data network of security-related data processing system are then possible only when the switching means to implement the filter functions, including the defective switch means for testing and monitoring procedures are or, if this filter functions can be circumvented. This is avoided by the invention in that of externally supplied data telegrams in a first device encrypted and in a second, with the first in Series-connected device can be decrypted, and that the measures provided for in the two institutions means Filtering the data telegrams and for functional testing of filters are dual-channel and constantly on compliance compare. By encrypting and decrypting the Data is taken to ensure that data telegrams which one of these bypass functions, at the latest by the safety Data processing system are reliably detected can; comparing the implemented in the individual units Programs or educated about the programs Test data with predetermined reference values and with the relevant Data and reference values of the respective other unit covers malfunctions within the units reliably on.
Advantageous embodiments of the inventive method are given in the subclaims 2 to 4. FIG.
So is not according to the teaching of claim 2 in successfully completed audit testing necessary repeated be until the failure disclosure time has expired; only then the connection is in the data network of the safety-relevant Data processing system separated. These Measure ensures that only briefly existing interference no lasting impact on the operation of have safety-related data processing system.
In order to prevent that after the separation of the connection public data network by disconnecting the two filter devices unintentional restarting of these filters can take place, as z. B. during a temporary power failure conceivable, according to the teaching of claim 3 to take certain measures that the separation of the connection make irreversible the public data network. For the re-commissioning of the facilities are certain operator actions required. If these service actions out, so is a security algorithm for provided that available in two units Data are different from each other, so that the comparison operation those implemented in two units and programs fixed data are not successfully concluded can. According to a particularly advantageous embodiment defined in claim 4 Mode of the invention are the measures for restarting and operating the two Units of both the involvement of an operator as well to make use of an anchored in the units logic depends, so that unintentional restarting the Units and inadvertent operation of the units reliably ruled out.
A device for implementing the method according to the invention in a suitable industrial structure is in claim 5 specified; advantageous embodiments and further developments this device can be found in the claims 6 to 18th
In the functional test of the technical components of the device are according to the teaching of claim 6, those components included that of the filtering process itself and to Modification involved data for backup purposes; these are the programs implemented in the units and fixed data, each with reference data or independently acquired data for compliance must be examined.
For redundancy, can according to the teaching of claim 7 doubled units for serial processing incoming be provided telegrams, these systems according to claims 8 and 9 have separate interface modules, which can be left to different transmission protocols can be adjusted. This is an unwanted coupling the redundant systems excluded.
According to the teaching of claim 10, to the units independently on the presence of the predetermined monitor test and purpose of each of the Partner unit corresponding data abfordern; such tasks cycled off and must be within a certain Failure disclosure time be concluded. After Teaching of claim 11, the individual units beside with the applicable reference values also different from those contain reference values of the other unit and then transmit for test purposes to the other unit. These measures may have different configuration data in both units, for example by different Communication services of both units for functional testing the units are taken into account ..
According to the teaching of claim 12 to the between units transmitted requirements and Prüfergebnistelegramme be provided with certain identifiers that a unique allow assignment of each data belonging together.
If according to the teaching of claim 13, retriggering a is timer made dependent on the associated unit within a certain amount of time needed by the respective Neighboring unit a Prüfanstoß receives, ensures that also the other entity of a performance test subjects and the associated timer to limit Failure disclosure time is drawn. The shared storage a release key and this release key modifying exclusive identification in a volatile Memory according to claim 14 results in that both Units in this volatile memory different data are deposited. If this data by any deleted transactions, so be due to the different computing Back exclusive identifiers for both units different Test data generated, as indicated by data comparing the two units can be determined and the interruption of the Connection to the public data network performs.
The envisaged by the teaching of claim 15 Information of connected networks is recognizing there the occurring disorder enable the option, the Troubleshooting cause.
By using separate NICs of clause of claim 16 for the individual units is a decoupling given of these units. If according to the teaching of Claim 17 of at least quantitative evaluation of the delivered, as non-safety critical identified telegrams is performed, it is possible, in time for the Filling up the memory of the security-related data processing system Additional supply of data messages to stop. By this measure is achieved that by outer, non-security operations availability the data processing system is not critical under a Value can be lowered; such safety-critical Data telegrams could also by an unauthorized Source such. As by a hacker, come with the aim of Data processing in the safety-related data processing system to block. The Drove an error message file according to claim 18 makes it possible from the time count of telegram rejections close to any unauthorized access attempts.
The invention is described below with reference to the drawing explained in more detail. The drawing shows schematically an Operations control center BLZ for controlling the train in intercourse a track area of a railway network. The operations control center is connected via an internal data network ID in conjunction with electronic interlocking CBI that zBaus of operators the operations control center out can be controlled. For this purpose, certain data telegrams from the control center transmitted to the electronic interlockings, the these telegrams then in Stella instructions for the track elements implement the grounds. The electronic interlockings guarantee thereby the safety of railway operations by ensure that asked not mutually exclusive routes be and that all directly in a driveway or indirectly included infrastructure elements on their freedom and Busy state are monitored. The electronic Interlockings in turn inform the control center the state of the process they control elements.
For certain interference situations it is provided that from the operations control center from taking into account certain safeguards to the security features of the positioners may be past acted on individual infrastructure elements. This can eg. B. then be necessary if due to a faulty reported vacancy detection individual track sections occupied are, although they were actually moved clear long. In this case, a dispatcher in the control center the relevant sections of track by issuing a respective command telegram freely report the alternative. The Dispatcher has the responsibility for the admissibility this measure assume what also documented for this purpose becomes. Furthermore, interference of light signals are conceivable through which there is no rule journey terms more blank turn. If the connection of such drive concepts allowed, then the CTC to the or the affected light signals turn a substitute signal aspect and thus facing the passage of a train at a stop Signal permit. This process too is the responsibility the dispatcher, and its validity is no longer checked by the signal box.
As long as the control center and controlled by it Interlockings an insular outwardly data network ID communicate with each other, can security attacks and availability of railway operations largely excluded will. It is different if the control center and the intended to cooperate with interlocking components of public Data networks are connected. Such couplings there will be in the future, because the paths for cost reasons at least certain data exclusively or optionally via will relate personal computers and workstations in signal technology Senses are not safe and may also to communicate to another, completely unknown Third-party systems, which in turn may connect to public have networks. Such non-underwriting Computers can z. B. for Rechnerzugüberwachung RZÜ that be used ZL train steering and the train number ZN, the right have no effect on the security of electronic Interlockings, but at best on their availability, namely, when a result of faulty messages from there a train is diverted. This deflection is done regularly but the responsibility of an electronic signal box, the the admissibility of that program instructions and the safety railway operation guaranteed. Likewise, it is in Future fault messages from other ST interlockings out or type of the individual process elements z. B above the integrated power train IN or ISDN to public Data networks are provided. In this public Data networks have any other external systems access, their orientation and texture nobody knows. On the public data network and attackers (hackers) H Access, which for some reason always bent on have to penetrate into protected data networks and there for Disruptions to worry. To recognize such a jammer, it is sufficient not that the supplied data to be protected network data telegrams analyze after their source back and just to allow such messages happen from the authorized Services originate because of the possibility can not be ruled is that the jammer already with their programs and data have taken root in these authorized services or will settle, and then no longer reliable as a disturber are visible.
From the prior art (EP 0120339 B1), it is known for performing fitting process control orders according to their Structurally classified into those that control operations concern and those concerning auxiliary operations. Orders for control operations are as backup environment harmless to evaluate, because they act on the signal box, in turn, the safety for the execution of the Operation takes over; Auxiliary operations, however, are safety-related Orders that the interlocking past on the grounds Act. The invention makes use of the known per se Distinction of telegrams in those with backup environment relevant content and those with backup environment harmless content to Choose, to prevent that from the outside by unauthorized persons on the process elements of the Grounds can be acted: only those telegrams from the outside to the protected data network of the security-related data processing system allowed which are classified as harmless backup environment. This can coming from outside influences intentional or unintentional theoretically not affect safety-critical have applications. This is true but only as long as the externally applied telegrams actually also respect their structural reliability in safety critical and acceptable telegrams can be distinguished. The is at least not the case if the data telegrams have the possibility in the evaluation device by in further fed long direction to the protected data network and / or if the funds earmarked for evaluating the telegrams Facilities are not fully functional.
To exclude such misconduct and possible disturbances be seen, the invention provides for several measures before whose common application but only the sought Purpose can be reached.
For sealing off the protected data network of security-related Data processing system is a so-called. Security translator system ST between the protected data network and the public data network to which a number of authorized but services connected and unknown external systems are. The security system consists of translator two substantially identical data processing devices PC1 and PC2 (security translator), the internal a Point-to-point connection IV are connected in series. The two security translators are in marketable technology realized and example as workstations or personal computer designed; but they can also in safety technology be implemented as they specifically for the control safety-relevant processes in the railway signaling is used. The operating systems of the two security translators include manufacturer no communications services (These services are only updated on the user side) or from the manufacturer provided communications services all the user side unneeded Services removed. So the user knows about the actual existing services communication, without having to fear that there in its security systems translator services him are unknown and whose function he does not know. Such services were only bloat the operating system and to not be predictable reactions associated security translators lead. In the adopted Embodiment, for the operating systems of the two BS security translators PC1 and PC2 three communication services D1 to D3 provided and implemented, while all other services are eliminated; this eliminated or not existing services are elliptical with a cross over the Symbol of the other services in.
Each security translator PC1, PC2 includes a filter function F, in which the structure of the public from the data network via the communications services delivered D1 to D3 Data telegrams z. B. based on data stored in files Telegram samples is evaluated. Let the filter functions F only those telegrams happen reliably considered fail be recognized harmless; refer such data especially to planning measures such as providing certain resources, schedule information, train numbers and similar. All data telegrams that are not reliable are recognized as signally harmless, be deleted. Such data may actually safety-critical its data, but also-safety data only were not recognized as such. In the opposite direction from the protected Data network of the data processing system derived Data telegrams pass through two security translators unfiltered and access the public data network.
Because it must be assumed that data telegrams, the filter function F z. B. the security translators PC1 by a kind Bypass BP could handle without the filter function itself fails, the invention provides a number of measures to exclude or recognition from such operations. These measures consist first of all in the already described doubling between the protected and the public data network insert security translator PC1, PC2 and their Series circuit via an internal point-to-point connection IV. The externally supplied data messages are not analyzed only in terms of their structure and filtered, but also changed several times. So contains the in data transfer direction first security translator PC1 encryption function V and their subsequent security translator PC2 decryption function E, in which the Encryption of the first security translators PC1 again is reversed. By this measure, and the point-to-point connection the two security translators is achieved, that externally supplied data, either through a Bypass BP from the input to the output of one or the other security coupling translators, either encrypted be or decrypted. Such telegrams are not to vote on their substance and are of the to protected data processing system discarded. failing the Encryption or decryption function in the one or other security translator, so it is also to appropriate tangled telegrams, the latest of the recognized safety-related data processing system and can be eliminated.
In order to detect whether the security translator PC1 and PC2 realized implemented filtering capabilities of properly be that filter programs filter functions in two data processing devices to a cyclic test ZP subjected. This should cyclic test Malfunctions are detected. leave Such malfunctions itself through the series connection of filter functions not uncover the was z. B. the filter function of the security translators fail PC2, so would the security translators PC1 mask this error, because they analyze the make the upcoming vote for telegrams first has been. The error occurred was then not recognized and the filter function of the security translators remain PC1 occurring at a later time error possibly undetected. Thus, the possibility is given, that actually dangerous commands from outside the protected data network of security-related data processing system could arrive.
By cyclic tests in two data processing devices PC1 and PC2, the filter programs are scanned. There are held through its programs according to an algorithm test data and test data constituted these are internal to the individual data processing devices with a reference memory stored Referenzprüfdaten compared. This happening for the first time during commissioning of safety-related Data processing system and later at each Restarting the system. During operation, the filter functions the two data processing devices also checked cyclically, although with only an internal examination a stored in the individual data processing devices Reference Date and cross-checking, provided the filter functions of both security translators is. To this end abuts z. B. the security translator PC1 over the data service D2 cyclic filter function test the security translator PC2. This causes the function test its own filter function and gives the case found test data and / or stored in their corresponding reference data over the data service to the D2 abfordernde security translator PC1. This compares transmitted result telegrams with their own test data. ensure Vergleicherfunktionen V in both security translators both for internal comparison of test data with reference data and for the external reference such data. There the result of comparison operations is safety-related, must be checked periodically and the comparison functions. This is also accomplished via the cyclic tests ZP. These cyclic tests are also the Vergleicherprogramme test data formed with internal Reference values, but also with the corresponding test data the relevant partner data processing device to match must be examined.
The permissible cycle time sequence for the cyclic tests ZP certainly z. B. from the used by the hardware Data processing devices specific error disclosure time MTBF, the z. B. is reduced by a factor of 1000 and the permissible failure disclosure time each security translators indicates. A typical value for such a failure disclosure time is just one hour, at the latest every Hour if a test procedure for testing the function of the filter and Comparison functions to be successfully concluded. Is a been completed, such a comparison is positive, too Start the function test in the relevant security translator tucked up timer, the switching time of the agreed Failure disclosure time corresponding to reset and starts not to run again Performs an inspection at a positive result, then the timer is not reset. Instead, the attempt is again made to to get a positive test result by again the current Test data on the filter and the comparison programs formed and or with each to comparative testing Reference data are compared. If within the allowable Failure disclosure time no positive comparison result reached, continue, possibly at different times in both security translators from the timer and cause that the respective associated security translator irreversibly shut down; hereupon will be discussed in more detail below.
In the cyclic testing to uncover malfunctions within the individual security translators, apart from the Check the filter and compare programs and the testing certain in the individual security translators backed unchangeable parameters be included. These parameters represent configuration data PD1 and PD2 in the accompanying Save the security translators are deposited. they may be different translators security for both because z. B. the communication services of the two operating systems can be interpreted in different ways. If these configuration data actually differ, in both security translators the configuration data of both security translators to deposit, where z. B. if the security translator PC2 reference data from the security translator PC1 retrieves, there deposited the security translator PC2 Reference data are received and vice versa.
Each of the two security translators acts PC1 and PC2 as the master security translator for triggering the cyclic test its programs and fixed data. Come in positive control of the programs and unchanging Data drawn test data within the failure disclosure time is not reached, in one of the security translators have malfunctioned. It is thus not ensured that the malfunctioning security translator actually shuts down due to the detected error. is yet to be explained by a mechanism, however, ensured that the partner-security translator, who is presumed to still should be functional, from occurring the function error is informed. This security translator turns off reliably, thereby preventing, that data from the open data network to the protected data network can reach.
The positive conclusion of the cyclical testing of a security translators can except from checking the filtering and comparison programs and the fixed data dependent be made that within the Ausfalloffenharungszeit by partner-security translator an impetus to determine received or reference data - and transferring test has been. Omits a security translator this offense, eg. B. because its timer expires after the failure disclosure time is so recognizes the partner-security translator, this at the company fail to Prüfaufforderung and turns then from itself.
An advantageous embodiment of the inventive security translator provides that the data processing devices for examining their programs and unchanging Data each one with a time stamp, with an after predetermined regularity determined number or a random number provided request to the respective Partner security translator convey and that this the each transmitted identification together with the requested Test or reference data to the requesting security translator transmitted. There is by evaluating the identifications, together with the request and the response to the request were received, an unambiguous assignment of the test and Reference data possible.
If one or both security translators of security translator systems have shut down in the event of a fault, is ensure that they can not start up again, without that this personnel authorized the restart of security translators causes and thus re-opening the security systems translator consciously permits. This should be done at least the two security translators of security translator system to be housed in a space of a special admission required. Such a space also includes other tampering with the security translator system from. To put the security translator system has the operator on both security translators PC1 and PC2 make a separate operator action, namely enter a specific identifier that follows is called enabling key FS. This identifier is z. B. from a plurality of bits comprising byte for both security translators equals, or of several Bytes. The presence of the release key, and thus the Admission to the operation of both security translators in During cyclic check regularly checked by the data the release key in a certain way in the test data the filter and compare programs and the invariable Data are included. Turns one of the security translators from in case of failure, it is the in his volatile memory Enrolled release key deleted. This is the considered security translator the revoked operating license because the relevant information have disappeared in the test data. But as they both security translators off due to interference and their release key could delete, is the presence of matching Release key alone is not sufficient to an unintentional restart of the security translator system to prevent. On the one hand the need to Release key in both security translators identical be so during the cyclic test matching test data formed for the programs and configuration data can be; on the other hand, this data must but be different, because there is otherwise an automatic activation the security translator system could come. The Invention therefore provides the to be deposited by the operator in each case identical enabling key through an automatic when entering or storing with an exclusive connect identifier for the relevant security translator, For example, with a host number, the security for both is different translators. In order to differ stored in designated storage by the identifiers modified release key markedly from each other. In the processing of the release key to form the Test data on the programs and the fixed data be through the security translators from the modified Release keys accompanying each exclusive identifiers again eliminated, so that with respect to the test data again be coincident release key. For both security translators are, however, only matching, in the cyclic test should be included enabling key ago, when the operator actually both release key has entered agree, this release key were automatically modified by the exclusive identifiers and then these identifiers by the automatic re were removed. Missing at one or two security translator of the release key input by the operator or the exclusive identifier, so direct the security translators by calculating back the exclusive identifiers from the input keys, even if the input key is deleted are therefore not present, different data out and reflect the results of arithmetic operations in the cyclical Tests a. So that it can not become a positive Completion of the cyclic tests come and compound between the data to be protected network and the public Data network is separated. The drop of the operator predetermined release key together with the exclusive Identifiers in a volatile memory has the different Representations of modified so formed Release key also has the advantage that due to external Influences caused data corruption in both memories come in different ways to effect by there overwrite or delete different bits. Even with a complete cancellation of the release key and / or the exclusive identifiers it comes through in the two security translators held recalculation of exclusive IDs from the removable data from the memories to different test data in both security translators and thus locking up the protected data network over the public data network.
Each security translator, of the self by deleting Input key and / or turn the power off, adapted corresponding fault messages either to the protected data network or to the public to transmit data network. For this purpose, the two security translators via separate NICs with the one or the other data network completely decoupled connected. Further, it is possible that a security translator, an appropriate fault message also to the respective Partner security received translator. this happens on the point to point connection between two IV security translators, which in turn completely decoupled is of the two networks to which the security translators Act.
Advantageous it may be, if the data processing system or the security translators supplied to them and classified as signally harmless telegrams Rate least quantitatively. In this way, in time before blocking the memory functions of the data processing system by bridged externally telegrams a decoupling of the two networks will be made before the resources of the security-related data processing system are exhausted. Such se signally acceptable Telegrams can unintentionally incorrect addressing, but also wanted by hackers in the public networks be imported with the ulterior motive, then the security Data processing system inoperative to make.
The chronological review of rejected / deleted messages allows any hacker attacks on the protected to identify data network and suitable countermeasures to take.
For redundancy, it may be advantageous, in addition to a first security translator system, one or more additional such, consisting of two security translators security translator systems provide. These redundant systems are either to turn to each other in parallel, by a ensure appropriate coordination is that only one the security translator system is effective, or else is a leading operating system and a translator Reserve Translator system, of which the reserve-translator system is only active if the operating system leading translator is inoperable. In any case, the security translators the redundantly provided security system translator via separate interface modules to the two data networks to join, said interface modules possibly even on different transport protocols for public Data network can be tuned.
The inventive method for partitioning of safety-related Data processing equipment against unwanted and illegal Interference from other data networks is out wherever applicable with advantage, where a clear distinction can be between data telegrams with security-sensitive and with no security-sensitive content. The protected Data processing system can for controlling be used any given process.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| AU2017312380B2 | Cited by | Australia | Search report |
| WO2018033318A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11529983B2 | Cited by | United States of America | Search report |
| RU2719094C1 | Cited by | Russian Federation | Search report |
| WO9726731A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
7 members in 3 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19742330 | Germany | A | |
| 19742330 | Germany | A | |
| 19742330 | Germany | – | |
| 19742330 | – | – | – |
| DE1997142330 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| DE19742330C1 | Germany | C1 | |
| EP0909692A2This record | European Patent Office (EPO) | A2 | |
| EP0909692A3 | European Patent Office (EPO) | A3 | |
| EP0909692B1 | European Patent Office (EPO) | B1 | |
| AT289554T | Austria | T | |
| ATE289554T1 | Austria | T1 | |
| DE59812590D1 | Germany | D1 |
35 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Fr: translation not filedEN | EN | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: ep patent (uk) treated as always having been void in accordance with gb section 77(7)/1977 [no translation filed]GBV | GBV | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Corresponds to:REF | REF | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Designation fees paidAT CH DE FR GB IT LI NLAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Information provided on ipc code assigned before grant7B 61L 27/00 A, 7H 04L 29/06 B, 7H 04L 9/00 B, 7B 61L 21/00 BRIC1 | RIC1 | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0909692
- Publication, DOCDB
- 0909692
- Publication, EPODOC
- EP0909692
- Application
- 98250319
- Application, DOCDB
- 98250319
- Application, EPODOC
- EP19980250319
Titles3
- German
- Verfahren zum Abschotten sicherheitsrelevanter Datenverarbeitungsanlagen gegen Beeinflussungen aus anderen Datennetzen sowie hierzu geeignete Einrichtung
- English
- Method for barricading security related data processing systems against influence of other data networks and apparatus for carrying out the method
- French
- Procédé pour barricader des systèmes de traitement de données relatifs à la sécurité intrinsique contre l'influence d'autres réseaux de données ainsi que dispositif approprié
Classification
- CPC, 4
- H04L63/0209
- H04L63/123
- H04L63/1441
- B61L27/70
- IPC, 4
- B61L21 00
- B61L27 00
- H04L9 00
- H04L29 06
Designated states25
- Contracting states, 19
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Extension states, 6
- Albania
- Lithuania
- Latvia
- North Macedonia
- Romania
- Slovenia