US 11,914,715 B2
Device unit suitable for operation in a protected and/or open operating state and associated method
Hans Aschauer, Munich (DE); Steffen Fries, Baldham (DE); Markus Heintel, Munich (DE); Dominik Merli, Mertingen (DE); and Rainer Falk, Poing (DE)
Assigned to SIEMENS AKTIENGESELLSCHAFT, Munich (DE)
Appl. No. 16/466,869
Filed by SIEMENS AKTIENGESELLSCHAFT, Munich (DE)
PCT Filed Oct. 10, 2017, PCT No. PCT/EP2017/075719
§ 371(c)(1), (2) Date Jun. 5, 2019,
PCT Pub. No. WO2018/103915, PCT Pub. Date Jun. 14, 2018.
Claims priority of application No. 16202905 (EP), filed on Dec. 8, 2016.
Prior Publication US 2020/0089890 A1, Mar. 19, 2020
Int. Cl. G06F 21/57 (2013.01); G06F 21/10 (2013.01)
CPC G06F 21/575 (2013.01) [G06F 21/572 (2013.01); G06F 21/577 (2013.01); G06F 21/107 (2023.08); G06F 2221/2105 (2013.01)] 13 Claims
OG exemplary drawing
 
1. A device unit comprising a module that configures the device unit with one operating state from various operating states when the device unit is booted and/or during ongoing operation of the device unit;
wherein a first protected operating state of the various operating states is designed to permit an execution of at least one predeterminable operating procedure and to protect it, using defined cryptographic means,
wherein a second operating state of the various operating states is designed to permit at least one changeable operating procedure and to protect it, using predefinable cryptographic means,
wherein when the operating state is intended to be protected during a boot procedure and/or during ongoing operation of the device unit, integrity protection measures for booting and for ongoing operation are provided by the module, the integrity protection measures comprise device authentication and device integrity attestation;
wherein the module is able to freeze a software state loaded by the user that is not authorized by the device manufacturer, wherein the software state loaded by the user is recorded in a reference database during the freeze; and
wherein a third operating state of the device unit is designed to simultaneously permit the first and the second operating states executing simultaneously in a combined mode.