Attestation of a cloud-based execution environment for project planning
Various embodiments of the teachings herein include an attestation component configured to attest a cloud-based execution environment. The cloud-based execution environment comprises at least one application instance and a project plan assigned to the at least one application instance. The attestation component may include: a determination component configured to determine at least one piece of trustworthiness information indicating a trustworthiness of the cloud-based execution environment and of the at least one application instance; and a linking component configured to establish a link between the trustworthiness information and the project plan.
1 . An attestation component configured to attest a cloud-based execution environment, wherein the cloud-based execution environment comprises at least one application instance and a project plan assigned to the at least one application instance, the attestation component comprising:
a determination component configured to determine at least one piece of trustworthiness information indicating a first trustworthiness of the cloud-based execution environment and a second trustworthiness of the at least one application instance;
wherein the second trustworthiness reflects memory contents of the at least one application instance and represents a determination that associated software was loaded as expected and not manipulated; and
a linking component configured to establish a link between the trustworthiness information and the project plan;
wherein the at least one piece of trustworthiness information comprises: a hash value of a kernel or a hash value of a binary of a server of the cloud-based execution environment and/or of the at least one application instance.
2 . The attestation component as claimed in claim 1 , wherein the link is configured as: a reference, a cryptographic hash value, and/or a Uniform Resource Identifier for the project plan.
3 . The attestation component as claimed in claim 1 , wherein an execution of the project plan requires a result of a check of the at least one piece of trustworthiness information.
4 . The attestation component as claimed in claim 1 , further comprising a checking unit configured to perform a check of the at least one piece of trustworthiness information and to produce a result of the check.
5 . The attestation component as claimed in claim 1 , wherein the at least one piece of trustworthiness information comprises: a hash value of a configuration file of a server of the cloud-based execution environment and/or of the at least one application instance.
6 . The attestation component as claimed in claim 1 , wherein the at least one piece of trustworthiness information comprises information relating to: a state of the cloud-based execution environment and/or of the at least one application instance, an environmental condition of the cloud-based execution environment and/or of the at least one application instance, and/or an event in relation to the cloud-based execution environment and/or the at least one application instance.
7 . The attestation component as claimed in claim 1 , wherein the at least one piece of trustworthiness information has a cryptographic signature.
8 . The attestation component as claimed in claim 1 , wherein the at least one piece of trustworthiness information comprises client information, wherein the client information relates to a creator of the project plan.
9 . The attestation component as claimed in claim 1 , further comprising a provisioning component, configured to provide the trustworthiness information to the project plan.
10 . The attestation component as claimed in claim 1 , wherein the project plan is configured as: a program for a memory-programmable logic controller, a program for a human-machine interface device, and/or a program for an input/output module.
11 . The attestation component as claimed in claim 1 , wherein the project plan is configured to be used by: an automation component, a manufacturing facility, a production system, and/or an automation system.
12 . The attestation component as claimed in claim 1 , formed within the cloud-based execution environment and/or formed isolated from the at least one application instance.
13 . A method for attesting a cloud-based execution environment including at least one application instance and a project plan assigned to the at least one application instance, the method comprising:
determining at least one piece of trustworthiness information indicating a first trustworthiness of the cloud-based execution environment and a second trustworthiness of the at least one application instance;
wherein the second trustworthiness reflects memory contents of the at least one application instance and represents a determination that associated software was loaded as expected and not manipulated;
establishing a link between the trustworthiness information and the project plan; and
transmitting the trustworthiness information, resulting in attestation of the cloud-based execution environment for the project plan;
wherein the at least one piece of trustworthiness information comprises: a hash value of a kernel or a hash value of a binary of a server of the cloud-based execution environment and/or of the at least one application instance.