Security module and method for monitoring de safety of a system
Abstract
The invention relates to a security module for monitoring system security, comprising a microprocessor (120) which is interconnected with further functional units, wherein the microprocessor (120) is programmed for overlapping processing with validation of the system state in the meantime and signaling means (107 , 108). <IMAGE>

Term
Term ended
Projected expiry passed 9 June 2020, 6.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 2 independent, 18 dependent
- 1Security module for monitoring system security, comprising a first and second data processing unit (120), (150) which are connected to further functional units (114, 116, 150), characterized by . a non-volatile memory has separate areas for data, which are generated by both data processing units, that one is monitored by the other data processing unit, wherein a security function is performed, and wherein, in the event of a dynamic change of the system state, the first data processing unit (120) is programmed for overlapping processing with interim validation of the system state, wherein data maps the system state and wherein the overlapping processing consists in a mutual swapping of the data supplied by both data processing units and in an execution of a respective redundant safety function on the swapped data by the two data processing units.
- 13Method for monitoring system security by means of a security module, characterized by that the structure of the safety procedure provides for a two-stage test with system state validation, wherein the principle is distinguished between static and dynamic states of the system and wherein an overlapping processing of data takes place in the dynamic self-test, in which the integrity of the system is checked over a period of time by a pattern comparison of a definable memory area.
Independent claims2
33 paragraphs, as filed
The invention relates to a security module for monitoring system security, according to the type specified in the preamble of claim 1, and for a method for monitoring system security according to the type specified in the preamble of claim 13. Such a postal security module is particularly suitable for use in a postage meter machine Mail processing machine or computer with mail processing function suitable.
There are a variety of safeguards for protection against failures or Disruptions as well as providing a 100% availability of intelligent electronic systems known. For example, parallel computer systems for extremely high security requirements (air traffic, etc.) are used, rather for low-level applications z. B. stored results redundantly designed so as to be able to detect a malfunction or a failure and possibly also to be able to correct. In many cases, the individual safeguards are very different in nature (eg. B. Combinations of hardware and software) and must meet the respective requirement of (possibly. even partially required) security of a system to be adapted, resulting in correspondingly many dedicated individual solutions that cause high design and - under certain circumstances - also implementation costs by their individual character.
It is already known from EP 417 447 B1 to use special modules in electronic data processing systems and to equip them with means for protection against burglary in their electronics. Such modules are hereafter called security modules.
Modern franking machines, or other devices for franking mail, are provided with a printer for printing the postage stamp on the mail, with a controller for controlling the printing and peripheral components of the postage meter, with a bill unit for settling postage paid in nonvolatile memories and a unit for cryptographically securing postage data. The accounting unit and / or the unit for securing the printing of the postage fee data can be realized by a security module (EP 789 333 A2). The processor of the security module is for example an OTP (One Time Programmable), which stores sensitive data, such as cryptographic keys, read-only. An encapsulation by a safety housing provides further protection.
Further measures to protect a security module against an attack on the data stored in it were also in the non-prepublished German applications 198 16 572.2 8 entitled:<img file="EP1069492A2_D0001.tif" />Arrangement for a Security Module ", 198 16 571.4 entitled: <img file="EP1069492A2_D0002.tif" />Arrangement for access protection for security modules ", 199 12 780. 8 entitled: <img file="EP1069492A2_D0003.tif" />Arrangement for a security module ", 199 12 781.6 entitled: <img file="EP1069492A2_D0004.tif" />Method for protecting a security module and device for carrying out the method "and German Utility Model Application 299 05 219.2 entitled: <img file="EP1069492A2_D0005.tif" />Security module with status signaling "proposed. Especially a pluggable safety module can assume different states in its life cycle. It can now be distinguished whether the security module is working or is defective. The nonmanageability of the hardware billing is trusted without further control. Any other software-controlled method of operation applies only with the original programs as error-free, which must therefore be protected against manipulation.
The invention is based, to achieve maximum security for a security module the task. A method is to be found which, with minimal effort, provides maximum security for definable areas and functions of a system, and which is universal, ie. H. can be applied to a wide variety of electronic systems with minimal adaptation effort. The method is intended to be used, for example, in franking machines for which special security claims apply, since the monetary billing data must be unmanipulable.
The object is achieved with the features of claim 1 for an arrangement and with the features of claim 13 for a method.
A timely verified integrity of the system ensures the security of the electronic system. A modular design of the security procedure provides for a two-stage, overlapping check that basically distinguishes between static and dynamic states of the system. The non-volatile stored data, functions and patterns in memory areas are suitable for mapping a system state. Predetermined subregions of the memory may be associated with particular computing devices and the data stored therein provide an image indicative of the state of the system reached. Predetermined subregions of the memory can be assigned to specific mappings which are achieved one after the other. The validation of a system state in the case of dynamic changes is based on the overlapping processing of data from at least parts of the test pattern, function range or memory area used individually or in combination with one another. The overlapping processing consists in mutually exchanging the data supplied by the one particular data processing unit and the data supplied by another specific data processing unit, and executing a redundant safety function on the exchanged data by both data processing units. The results of redundant data processing must be comparable for an unmanipulated and error-free system. A security module for a data processing system, for example a franking machine, assumes its function, for example a settlement of the postage fees and / or its cryptographic security. The security module has a module processor and a hardware abort unit. According to the invention, the security module is characterized by its own signal means which, when directly controlled by the processor of the security module, permit a statement about the current state of the security module. The signaling of the module status is only activated when the system voltage is supplied to the safety module in order to save an internal battery. The processor may also monitor or verify the work of the hardware abort unit. It is not intended to verify the billing itself for accuracy. Also can by a <img file="EP1069492A2_D0006.tif" />Pattern comparison of a definable memory area no backward mapping of the post registers can be achieved because the checksums are formed over the data of the entire security-relevant memory area, because it is not the system availability in the foreground, but the reliable detection of malfunctions or failures and a suitable response on it, as is the case with particularly safety-sensitive, rather time-critical processes.
Advantageous developments of the invention are characterized in the subclaims or are presented in more detail below together with the description of the preferred embodiment of the invention with reference to FIGS. Show it:<dl id="dl0001"><dt>FIG. 1,</dt><dd>Perspective view of the franking machine from behind,</dd><dt>FIG. 2,</dt><dd>Block diagram of the security module,</dd><dt>FIG. 3,</dt><dd>Side view of the security module,</dd><dt>FIG. 4,</dt><dd>Top view of the security module,</dd><dt>FIG. 5,</dt><dd>Table for status signaling,</dd><dt>FIG. 6,</dt><dd>Presentation of the system integrity check for static and dynamically changeable states,</dd><dt>FIG. 7,</dt><dd>Flow chart for checking the integrity of the system,</dd><dt>FIG. 8,</dt><dd>Representation of the static test,</dd><dt>FIGS. 9 and 10,</dt><dd>Presentation of overlapping processing.</dd></dl>
FIG. 1 shows a perspective view of the franking machine from the rear. The franking machine consists of a meter 1 and a base 2. The latter is equipped with a smart card write / read unit 70, which is arranged behind the guide plate 20 and accessible from the housing upper edge 22. After switching on the franking machine by means of the switch 71, a chip card 49 is inserted from top to bottom in the insertion slot 72. A supplied standing on the edge letter 3, which rests with its surface to be printed on the guide plate is then printed according to the input data with a franking stamp 31. The letter feeding opening is bounded laterally by a transparent plate 21 and the guide plate 20.
The module is plugged into the main board of the meter meter or other suitable device. It is preferably housed within the meter housing, which is designed as a safety housing. The meter housing is advantageously constructed so that the user can still see the status display of the security module from the outside through an opening 109, wherein the opening 109 to the user interface 88, 89 of the meter 1 extends. The display is controlled directly by the module's internal processor and can not be easily manipulated from the outside. The display is constantly active in the operating state, so that the application of the system voltage Us + to the processor of the security module is sufficient to activate the display to read the module state.
FIG. 2 shows a block diagram of the postal security module PSM 100 in a preferred variant. The negative pole of the battery 134 is connected to ground and a pin P23 of the contact group 102. The positive pole of the battery 134 is connected to the one input of the voltage changeover switch 180 via the line 193, and the system voltage leading line 191 is connected to the other input of the voltage changeover switch 180. The battery 134 is the SL-389 / P for a life of up to 3.5 years or the SL-386 / P for a life of up to 6 years with a maximum power consumption by the PSM 100. As voltage switch 180, a commercial circuit of the type ADM 8693ARN can be used. The output of the voltage changeover switch 180 is connected via the line 136 to a voltage monitoring unit 12 and a detection unit 13. The voltage monitoring unit 12 and the detection unit 13 communicate with the pins 1, 2, 4 and 5 of the processor 120 via the lines 135, 164 and 137, 139 in communication. The output of the voltage changeover switch 180 is also applied via the line 136 to the supply input of a first memory SRAM, which becomes the non-volatile memory NVRAM 116 of a first technology through the existing battery 134. The security module communicates with the postage meter via the system bus 115, 117, 118. The processor 120 may communicate via the system bus and a modem 83 in communication with a remote data center. Billing is completed by the ASIC 150. The postal billing data is stored in non-volatile memory of different technology. At the supply input of a second memory NV-RAM 114 system voltage is applied. This is a non-volatile memory NVRAM of a second technology, (SHADOW-RAM). This second technology preferably comprises a RAM and an EEPROM, the latter automatically assuming the data contents in the event of system voltage failure. The NVRAM 114 of the second technology is connected to the corresponding address and data inputs of the ASIC 150 via an internal address and data bus 112, 113.
The ASIC 150 contains at least one hardware abort unit for the calculation of the postal data to be stored. The Programmable Array Logic (PAL) 160 accommodates access logic for the ASIC 150. The ASIC 150 is controlled by the PAL 160 logic. An address and control bus 117, 115 from the motherboard of the meter 1 is connected to corresponding pins of the logic PAL 160 and the PAL 160 generates at least one control signal for the ASIC 150 and a control signal 119 for the program memory FLASH 128. The processor 120 executes a program stored in the FLASH 128. The processor 120, FLASH 28, ASIC 12 and PAL 160 are interconnected via a module-internal system bus, which includes lines 110, 111, 126, 119 for data, address and control signals.
The RESET unit 130 is connected via the line 131 to the pin 3 of the processor 120 and to a pin of the ASIC 150. The processor 120 and the ASIC 150 are reset by a reset generation in the RESET unit 130 when the supply voltage drops.
The processor 120 internally has a processing unit CPU 121, a real time clock RTC 122, a RAM unit 124, and an input / output unit 125. The processor 120 of the security module 100 is connected via a module-internal data bus 126 to a FLASH 128 and to the ASIC 150. The FLASH 128 serves as a program memory and is supplied with system voltage Us +. For example, it is a 128 Kbyte FLASH memory type AM29F010-45EC. The ASIC 150 of the postal security module 100 delivers the addresses 0 to 7 to the corresponding address inputs of the FLASH 128 via a module-internal address bus 110. The processor 120 of the security module 100 provides via an internal address bus 111 the addresses 8 to 15 to the corresponding address inputs of the FLASH 128. The ASIC 150 of the security module 100 is in communication with the data bus 118 via the contact group 101 of the interface, with the address bus 117 and the control bus 115 of the mainboard of the meter 1.
Voltage selector 180, as output voltage on line 136 for voltage monitor 12 and memory 116, forwards that of its input voltages which is greater than the other. Due to the possibility of automatically feeding the described circuit as a function of the magnitude of the voltages Us + and Ub + with the larger of the two, during normal operation the battery 134 can be exchanged without loss of data. The real-time clock RTC 122 and the memory RAM 124 are supplied by an operating voltage via the line 138. This voltage is generated by the voltage monitoring unit 12.
The battery of the franking machine fed in the rest periods outside normal operation in the aforementioned manner, the real-time clock 122 with date and / or time registers and / or the static RAM (SRAM) 124 which holds security-related data. When the voltage of the battery drops below a certain limit during battery operation, circuit 12 connects the feed point for RTC and SRAM to ground. That is, the voltage at the RTC and the SRAM is then at 0V. This causes the SRAM 124, the example contains important cryptographic keys, is deleted very quickly. At the same time, the registers of RTC 122 are cleared and the current time and date are lost. This action prevents a potential attacker from stopping the postage meter internal clock 122 by manipulating the battery voltage without losing any security related data. Thus, it is prevented that he bypasses security measures, such as Sleeping Mode (EP 660 268 A2) or Long Time Watchdog (will be explained with reference to Figure 5).
For example, the circuit of the voltage monitoring unit 12 is dimensioned so that any drop in the battery voltage on the line 136 below the specified threshold of 2.6 V will cause the circuit 12 to respond. Simultaneously with the indication of the undervoltage of the battery, the circuit 12 changes into a self-holding state in which it remains even when subsequently increasing the voltage. It also provides a status signal 164. The next time the module is switched on, the processor can query the state of the circuit (status signal) and thus and / or via the evaluation of the contents of the erased memory, conclude that the battery voltage has in the meantime fallen below a certain value. The processor may reset the monitoring circuit 12, ie "make sharp. The latter responds to a control signal on line 135.
The line 136 at the input of the battery top 12 also supplies a detection unit 13 with operating or battery voltage. The processor 120 queries the state of the detection unit 13 via the line 139 or the detection unit 13 is triggered by the processor 120 via the line 137 or set. After setting, a static check is made for connection. For this purpose, ground potential is queried via a line 192, which is present at terminal P4 of the interface of the postal security module PSM 100 and can only be interrogated if the security module 100 is inserted correctly. When plugged security module 100 ground potential of the negative pole 104 of the battery 134 of the postal security module PSM 100 is placed on the port P23 of the interface 8 and is thus interrogated at port P4 of the interface via the line 192 of the detection unit 13. At the pins 6 and 7 of the processor 120 lines are connected, which form a conductor loop 18 only in one, for example, to the motherboard of the meter 1, plugged security module 100. For dynamically checking the state of the connectedness of the postal security module PSM 100 on the mainboard of the meter 1, the processor 120 generates changing signal levels at quite irregular time intervals to the pins 6, 7 and looped them back through the loop.
The processor 120 is equipped with the input / output unit 125, whose terminals are pins 8, 9 for outputting at least one signal for signaling the state of the security module 100. At the pins 8 and 9 are I / O ports of the input / output unit 125 to which module-internal signaling means are connected, for example, colored light emitting diode LED's 107, 108th These signal the module state in a plugged onto the motherboard of the meter 1 security module 100 through an opening 109 in the meter housing. The safety modules can assume different states in their life cycle. So must eg to detect whether the module contains valid cryptographic keys. Furthermore, it is also important to distinguish whether the module is working or is defective. The exact type and number of module states depends on the implemented functions in the module and on the implementation.
FIG. 3 shows the mechanical structure of the security module in side view. The security module is designed as a multi-chip module, ie several functional units are interconnected on a printed circuit board 106. The security module 100 is potted with a hard potting compound 105, wherein the battery 134 of the security module 100 is arranged outside of the potting compound 105 on a printed circuit board 106 interchangeable. For example, it is potted with a potting material 105 that the signal means 107, 108 protrudes from the potting material at a first location and that the circuit board 106 projects with the inserted battery 134 laterally of a second location. The circuit board 106 also has battery contact terminals 103 and 104 for connecting the poles of the battery 134, preferably on the component side above the circuit board 106th It is envisaged that for the attachment of the postal security module PSM 100 on the motherboard of the meter 1, the contact groups 101 and 102 below the circuit board 106 (trace side) of the security module 100 are arranged. The user circuit ASIC 150 is via the first contact group 101 - in a manner not shown - in communication with the system bus of a control device 1 and the second contact group 102 serves to supply the security module 100 with the system voltage. If the security module is plugged onto the motherboard, then it is preferably arranged within the meter housing in such a way that the signal means 107, 108 near an opening 109 or projects into this. The meter housing is thus advantageously designed so that the user can still see the status of the security module from the outside. The two light emitting diodes 107 and 108 of the signal means are controlled via two output signals of the I / O ports to the pin 8, 9 of the processor 120. Both light-emitting diodes are housed in a common component housing (bi-polar LED), which is why the dimensions or the diameter of the opening can remain relatively small and is of the order of magnitude of the signal means. In principle, three different colors can be displayed (red, green, orange), depending on the LEDs are controlled individually or simultaneously. To distinguish the state of the LEDs are also individually or together flashing if necessary alternately flashing controlled, so that a plurality of different states can be distinguished in which at least one of the LEDs is activated.
FIG. 4 shows a plan view of the postal security module. The potting compound 105 surrounds a first part of the circuit board 106 in a cuboid, while a second part of the circuit board 106 for the replaceably arranged battery 134 remains free of potting compound. The battery contact terminals 103 and 104 are covered by the battery here.
According to a self-explanatory table for status signaling shown in FIG. 5, a large number of possible status indications emerge. A green LED 107 signals an OK state 220, but a lit LED 108 signals an error state 230 as a result of an at least static self-test. The result of such a known self-test can not be falsified because of the direct signaling via the LEDs 107, 108. For example, in the event that, in the meantime, the keys stored in the security module were lost, the ongoing check in dynamic mode would detect the error and signal the status 240 with orange LED's lit. After switching off / on, booting is required, otherwise no other operation can be performed. The case in which the installation of a key was forgotten in the manufacture is signaled as state 260, for example with a green blinking LED 107. Also, the case that a long time watchdog timer has expired is signaled to status 250 by a red flashing LED. The long time watchdog timer has expired if the data center has not been contacted for a long time, for example to recharge a credit. State 250 is also reached when the security module is disconnected from the meter. Additional status displays for states 270, 280, 290 are optionally provided for various further tests.
FIG. 6 shows a representation of the integrity check of the system for statically and dynamically changeable states. A deactivated system in state 200, after being switched on, transitions via transition Start 201 into state 210, in which a static self-test is performed by the safety module as soon as the operating voltage is present. In transition 202, where the self-test gives an OK if the result is correct, the state 220 LED green is reached. Starting from the latter state, a repeated static self-test and a dynamic self-test can be performed if necessary. Such a transition 203 or 206 leads either back to the state 220 LED green at OK or to the state 240 LED orange at a fault. The latter is possibly due to a Recover attempt. by switching off (transition 211) and restarting the device (transition 201) can be corrected. Static errors are not recoverable. From state 210, in which the switched-on device carries out a static self-test, a transition 204 to state 230 LED red exists in the event of an error. At any time, when the device is in the state 220 LED green, a static self-test carried out on demand in the event of an error can lead via a transition 205 to the state 230 LED red. Starting from state 220 LED green, further transitions 207, 208, 209, not shown, can be signaled to the further states 270 (signaled with orange flashing LEDs), 280 (with red flashing / orange flashing LEDs) and 290 (with green flashing / orange flashing LEDs signals).
Figure 7 shows a flow chart for checking the integrity of the system. The microprocessor CPU 121 is programmed by a corresponding program stored in the flash 128 to execute such aforementioned self-tests, wherein after the start 299, in a first step 300 a power on self-test is performed and then in step 301 it is asked whether the power on Self-test has resulted in an OK. If so, then in step 302, the green LED 107 is controlled to be lit by the microprocessor CPU 121 via an I / O port 125. Otherwise, in step 303, the red LED 108 is lit by the microprocessor CPU 121 via an I / O port 125 lit. Step 302 branches to query 304, in which it checks whether a further static check is required. If this is the case, the method branches back to step 300. Otherwise, at least one register operation is performed in steps 305-307 and then branched to query 308, in which it is checked whether the current state is valid or not. is proper. During the register operation or subsequently, a dynamic check is performed. If it is improper or faulty, then branch from query step 308 to step 315 and both the green LED 107 and the red LED 108 are lit by the microprocessor CPU 121 via an I / O port 125 lit. Thus, the overall impression that the LED's light up orange. Subsequent to the query step 308, in a satisfactory actual state in steps 309-314, a dynamic calculation and subsequently a saving of the results is carried out. The last step branches back to font 302. This results in a two-stage test on demand. For the dynamic calculation, it is sufficient if for the check by the microprocessor CPU 121 only sub-functions are tracked time-shifted on the same or on another computing method, whereby of course both calculation methods for the same check result OK or DEFECT or ERROR must lead.
In a system with the memory area M and a multiplicity of functions F, a safety-relevant subarea M to be defined in terms of size or scope should be provided<img file="EP1069492A2_D0007.tif" /> and F<img file="EP1069492A2_D0008.tif" /> be protected against malfunctions and failures. For this purpose, the safety-relevant functions F<img file="EP1069492A2_D0009.tif" />, as far as they are not exclusively on the memory area M anyway<img file="EP1069492A2_D0010.tif" /> work, designed so that they clear test marks (pattern) of their (successful) mode of action in the system on the memory area M<img file="EP1069492A2_D0011.tif" /> depict. The security procedure now fundamentally differentiates between two different system states: the static, in which the content of the memory area M<img file="EP1069492A2_D0012.tif" /> not changed and the dynamic, in which a change of the memory area M<img file="EP1069492A2_D0013.tif" /> he follows. The safety procedure is characterized on the one hand by the fact that, during the static state in a time-recurring sequence, a check of the integrity of the system (more precisely of the system components M<img file="EP1069492A2_D0014.tif" /> and F<img file="EP1069492A2_D0015.tif" />) is performed by entering through a one-way mathematical function (eg the hash method) <img file="EP1069492A2_D0016.tif" />Pattern "C2 of the memory area M<img file="EP1069492A2_D0017.tif" /> which is compared with the currently valid stored pattern C1 (which was first generated and validated by a system initialization). This has the advantage that even with arbitrarily different sources M<img file="EP1069492A2_D0018.tif" /> A manageable format for Cx is generated, thus enabling efficient processing. In the event of inequality of Patterns C2 and C1 during the first static system state, the previously defined and desired response is generated by the security method to a malfunction or failure or manipulation of the system. Now interesting is the consideration of the second, dynamic system level, in which the memory contents M<img file="EP1069492A2_D0019.tif" /> by at least one of the functions F<img file="EP1069492A2_D0020.tif" /> caused, changes. In this case, the security method according to the invention provides for overlapping processing with validation of the system state taking place in the meantime. For this purpose, the memory area M<img file="EP1069492A2_D0021.tif" /> redundant and contains at least two in nature and extent and - in the static state - also from the content corresponding figures M1<img file="EP1069492A2_D0022.tif" /> and M2<img file="EP1069492A2_D0023.tif" /> in the form of data stored in sub-memory areas M<sub>1</sub>'and M<sub>2</sub>'are stored. Through the security procedure, the address management of the subareas M<sub>1</sub><img file="EP1069492A2_D0024.tif" /> and M<sub>2</sub><img file="EP1069492A2_D0025.tif" /> to M<sub>x</sub><img file="EP1069492A2_D0026.tif" /> of the area M<img file="EP1069492A2_D0027.tif" /> made such that at least always the last current and validated state -. M1<img file="EP1069492A2_D0028.tif" /> - in memory area M<sub>1</sub>'is available. To a changed state -. M2<img file="EP1069492A2_D0029.tif" /> - in memory area M<sub>2</sub>It is intended, as a first possibility, in particular if foreign influence of the system can be excluded by third parties, to validate the currently changing process from the function range F<img file="EP1069492A2_D0030.tif" /> - z. F1<img file="EP1069492A2_D0031.tif" /> - to carry out several times, in order to have been formed in the meantime <img file="EP1069492A2_D0032.tif" />Pattern "Cx over the data in the area M<sub>2</sub><img file="EP1069492A2_D0033.tif" /> as well as the comparison of the respectively buffered pattern results, the new state M2<img file="EP1069492A2_D0034.tif" /> as validated to take over and the state M1<img file="EP1069492A2_D0035.tif" /> Consequently, to override by the subsequent changes release. Another possibility is that the security method has its own intelligence to perform at least some functions from F<img file="EP1069492A2_D0036.tif" /> To execute so in the first step, a fleeting mirror image of M2<img file="EP1069492A2_D0037.tif" /> and then the associated mirror pattern Cx for comparison with the <img file="EP1069492A2_D0038.tif" />Original "to produce.
Based on an example shown in Figure 8, the method will be explained in detail. A saved pattern C1 was first generated and validated by a system initialization. By a mathematical one-way function, a pattern C2 of the memory area M<img file="EP1069492A2_D0039.tif" /> and the functions F 'generated and compared in step 301 with the currently valid, stored pattern C1. In the event of a fault, the microprocessor 120 controls the LED signaling with a red light (font 303).
The dynamic self-test is explained with reference to FIG. 9, which shows a representation of the overlapping processing. Steps 305 and 306 of the integrity check of the system shown in Figure 7 may be split into sub-steps. The memory area M<img file="EP1069492A2_D0040.tif" /> is redundant as memory area M<img file="EP1069492A2_D0041.tif" /> executed, both in nature and extent and - in the static state - also correspond to the data content ago, which illustrates the sub-step 305a. Otherwise there is an error, ie the figures M1<img file="EP1069492A2_D0042.tif" /> and M1<img file="EP1069492A2_D0043.tif" /> do not match. From sub-step 305a via sub-step 305b, both memory areas M1 ', M1<img file="EP1069492A2_D0044.tif" /> treated separately by a respective safety function F1 ', F1<img file="EP1069492A2_D0045.tif" /> is executed, which changes the data content, so that in sub-steps 305c, the maps M2<img file="EP1069492A2_D0046.tif" /> and M2<img file="EP1069492A2_D0047.tif" /> arise. By interchanging the pictures M2<img file="EP1069492A2_D0048.tif" /> and M2<img file="EP1069492A2_D0049.tif" /> and execution of each another safety function F2 ', F2<img file="EP1069492A2_D0050.tif" /> on the exchanged pictures M2<img file="EP1069492A2_D0051.tif" /> and M2<img file="EP1069492A2_D0052.tif" /> In the sub-steps 305d, an overlap in the form of the images M3 arises<img file="EP1069492A2_D0053.tif" /> from F2<img file="EP1069492A2_D0054.tif" />(M2<img file="EP1069492A2_D0055.tif" />) and M3'from F2 '(M2<img file="EP1069492A2_D0056.tif" />). In sub-step 306, the images M3<img file="EP1069492A2_D0057.tif" /> and M3<img file="EP1069492A2_D0058.tif" /> compared. An error occurs when the pictures M3 'and M3<img file="EP1069492A2_D0059.tif" /> do not correspond. In principle, a large number of such sub-steps 305x can be executed with overlapping safety-relevant sub-memory areas. The microprocessor 120 is programmed to perform overlapping processing of at least a portion of the functional scope used for subsequent validation in the event of dynamic changes in the system state and, if appropriate, to perform the validation of the system state multiple times in intermediate steps.
In Figure 10, overlapping processing is shown in combination with overlapping checksums and / or overlapping operations. The dynamic self-test can be carried out according to the safety requirements in a great variety of variations. It is contemplated that the microprocessor (120) is programmed to perform overlapping processing on dynamic changes of the system state of at least a portion of the functional scope or test pattern used. Subsequently, the validation always takes place. It is intended to perform the overlapping processing of at least parts of the test pattern used, the scope of functions or memory area in combination with each other for subsequent validation.
It is clear that can be realized alone by the design of the environment and type of security process arbitrarily high security requirements that allow based on the same basic idea different configurations. Thus, for example, by correspondingly many sub-areas Mx<img file="EP1069492A2_D0060.tif" /> to ensure that the security procedure does not turn out to be a performance bottleneck, even with temporarily very fast process steps. A further advantageous embodiment of the idea is based on the fact that changes of sub-ranges of M<sub>x</sub><img file="EP1069492A2_D0061.tif" />, M<sub>x</sub><img file="EP1069492A2_D0062.tif" />, M<sub>x</sub>'<img file="EP1069492A2_D0063.tif" />, ..., M<sub>x</sub>* can only be executed after requesting a write permission to the security procedure. It is also advantageous that the existing system processor is used to perform the security procedure, but this does not preclude that the entire security process in <img file="EP1069492A2_D0064.tif" />Silicon "poured ASIC is feasible or, in the case of particularly high security requirements, the security process is implemented by its own, particularly access-protected processor.
It is noteworthy that the method described makes it possible, without providing any conclusions about the existing data stock or the existing functionality of an electronic system, to carry out the validation with regard to the system integrity of freely definable system areas and functions without gaps.
According to the invention, the data processing system, in particular a franking machine, but the security module can also have a different design, which makes it possible, for example, it can be plugged into the motherboard of a personal computer that drives a commercial printer as a PC meter.
The invention is not limited to the present embodiment, since obviously other other arrangements or embodiments of the invention can be developed or used, which - based on the same basic idea of the invention - are encompassed by the attached claims.
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0417447B1 | Cites | European Patent Office (EPO) | Applicant |
| EP0762338A2 | Cites | European Patent Office (EPO) | Search report |
| EP0789333A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0859340A2 | Cites | European Patent Office (EPO) | Search report |
| DE19816571A1 | Cites | Germany | Applicant |
| DE19816572A1 | Cites | Germany | Applicant |
| DE19912780A1 | Cites | Germany | Applicant |
| DE19912781A1 | Cites | Germany | Applicant |
| DE29905219U1 | Cites | Germany | Applicant |
| US4253158A | Cites | United States of America | Search report |
5 members in 3 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 19928061 | Germany | A | |
| 19928061 | Germany | – | |
| 19928061 | – | – | – |
| DE1999128061 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| DE19928061A1 | Germany | A1 | |
| EP1069492A2This record | European Patent Office (EPO) | A2 | |
| US6351220B1 | United States of America | B1 | |
| DE19928061C2 | Germany | C2 | |
| EP1069492A3 | European Patent Office (EPO) | A3 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| Designation fees paidAKX | AKX | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1069492
- Publication, DOCDB
- 1069492
- Publication, EPODOC
- EP1069492
- Application
- 250184
- Application, DOCDB
- 00250184
- Application, EPODOC
- EP20000250184
Titles3
- German
- Sicherheitsmodul zur Überwachung der Systemsicherheit und Verfahren
- English
- Security module and method for monitoring de safety of a system
- French
- Module et méthode de sécurité pour la surveillance de sécurité d'un système
Classification
- CPC, 10
- G06F21/57
- G06F2207/7219
- G07B17/00733
- G07B2017/00233
- G07B2017/00258
- G07B2017/00322
- G07B2017/00338
- G07B2017/00395
- G07B2017/00403
- G07B2017/00967
- IPC, 2
- G07B17 00
- G06F21 57
Designated states3
- Contracting states, 2
- Liechtenstein
- Sweden
- Extension states, 1
- Slovenia