Secure patch updates for programmable memories
US-2017090909-A1 · Mar 30, 2017 · US
US10402190B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10402190-B2 |
| Application number | US-201815994229-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 31, 2018 |
| Priority date | May 31, 2017 |
| Publication date | Sep 3, 2019 |
| Grant date | Sep 3, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The invention relates to a method for authorized updating of first operating software of a field device which is used in an automation technology installation, wherein an authentication test of second operating software for the field device is performed, which second operating software is signed by means of a first private key associated with the installation, wherein, within the scope of the authentication test, the signature, generated by the first private key, of the second operating software is authenticated by means of a first public key associated with the installation, and wherein, in the event that the authentication test has been performed successfully, the first operating software located on the field device is at least partially replaced by the second operating software.
Opening claim text (preview).
The invention claimed is: 1. A method for an authorized updating of a first operating software of a field device used in an automation technology installation, comprising: signing a second operating software for the field device using a first private key associated with the installation; executing an authentication test of the second operating software, wherein the authentication test includes authenticating a signature of the second operating software generated by the first private key using a first public key associated with the installation, and upon a successful authentication test, at least partially replacing the first operating software located on the field device by the second operating software, wherein the first operating software and the second operating software each comprise a first component and a second component, wherein the second component of the first operating software and the second component of the second operating software each include functions which influence the field device with respect to its measuring function including a time coordination of a measurement value detection, and wherein the at least partial replacing of the first operating software by the second operating software includes replacing the first component of the first operating software with the first component of the second operating software. 2. The method according to claim 1 , further comprising: signing the second operating software using the first private key only when the second operating software receives an approval from an installation operator. 3. The method according to claim 1 , further comprising: signing the second operating software by the field device manufacturer using a second private key. 4. The method according to claim 3 , wherein the authentication test includes authenticating a signature generated by the second private key using a second public key. 5. The method according to claim 1 , wherein the first operating software and the second operating software each comprise a first component and a second component, wherein the at least partial replacing of the first operating software by the second operating software includes replacing the second component of the first operating software with the second component of the second operating software. 6. The method according to claim 1 , wherein the first operating software and the second operating software each comprise a first component and a second component, wherein the at least partial replacing of the first operating software by the second operating software includes replacing the first component of the first operating software with the first component of the second operating software and replacing the second component of the first operating software with the second component of the second operating software. 7. The method according to claim 6 , wherein only the second component of the second operating software is signed, and wherein the authentication test includes authenticating only the signature of the second component of the second operating software. 8. The method according to claim 1 , wherein the first component of the first operating software and the first component of the second operating software each include security functions, HMI functions, GUI functions, and/or an interface to a superordinate unit. 9. The method according to claim 1 , wherein the first component and the second component of the first operating software or the second operating software are distributed to separate processing units of the field device.
Revocation or update of secret information, e.g. encryption key update or rekeying · CPC title
Secure firmware programming, e.g. of basic input output system [BIOS] · CPC title
Program or device authentication · CPC title
Incremental updates; Differential updates · CPC title
using techniques specially adapted for alterable solid state memories, e.g. for EEPROM or flash memories · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.