IP Library › Granted Patent US 11,755,719
Granted Patent B2
US 11,755,719 · App. 16/956,270 · Granted Sep 12, 2023

Interface for a hardware security module

Inventors: Hans Aschauer (Munich, DE); Rainer Falk (Poing, DE); Christian Peter Feist (Munich, DE); Daniel Schneider (Munich, DE)
Assignee: SIEMENS AKTIENGESELLSCHAFT
G06F21/53G06F21/74G06F2221/032G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,719
App. No.
16/956,270
Granted
Sep 12, 2023
Kind
B2
Abstract

The following relates to a hardware security module for usage with manufacturing devices and a method for operating the same is provided. The security module includes: a secure element, which is adapted to detect an operating mode of the hardware security module; a first interface which is adapted to receive commands for controlling the hardware security module; a central processing unit for processing application program code in a secure environment; a second interface which is adapted for receiving configuration data, wherein the second interface is activated and deactivated in dependence of the detected operating mode.

Claims (29)

1. A hardware security module for usage with manufacturing devices, comprising:

a secure element configured to detect an operating mode of the hardware security module by detecting a position of a first switch of the hardware security module which indicates whether the hardware security module is in a sealed mode or an unsealed mode, and providing a control signal in response to the detecting;

a first interface configured to receive commands for controlling the hardware security module, in both the sealed mode and the unsealed mode;

a central processing unit for processing application program code in a secure environment;

a second interface configured for receiving configuration data, wherein the second interface is activated and deactivated in dependence of the operating mode such that configuration data is received by the second interface only in the unsealed mode; and

a second switch coupled to the first interface and the second interface, wherein the control signal provided by the secure element directly controls the second switch to activate or deactivate the second interface by coupling or decoupling the second interface from the first interface.

2. The hardware security module according to claim 1 , wherein the secure element is a key controlled switch.

3. The hardware security module according to claim 1 , wherein the secure element is controlled by a command, which is received via the first interface.

4. The hardware security module according to claim 1 , wherein the first switch is a mechanical switch, located at a position on the hardware security module difficult to access.

5. The hardware security module according to claim 1 , wherein the hardware security module comprises a third interface for debugging application program code.

6. A method for operating a hardware security module in different modes, comprising a sealed mode and an unsealed mode, the method comprising:

detecting an operating mode of the hardware security module by detecting a position of a first switch of the hardware security module;

providing a control signal in response to the detecting;

activating a second interface for receiving configuration data if the unsealed mode has been detected; and

deactivating the second interface automatically if the sealed mode has been detected, during which commands are received via a first interface, wherein the second interface is deactivated by controlling a switch that decouples the second interface from the first interface;

wherein the first interface is configured to receive the commands for controlling the hardware security module, in both the sealed mode and the unsealed mode, and the second interface configured for receiving the configuration data only in the unsealed mode.

7. The method according to claim 6 , wherein the configuration data comprises data for configuring the hardware security module and comprises a security image.

8. The method according to claim 6 , wherein the second interface is deactivated logically.

9. The method according to claim 6 , wherein the second interface is deactivated physically.

10. The method according to claim 6 , wherein the second interface is deactivated in dependence of at least one sensor signal, which is/are detected locally on the hardware security module.

11. The method according to claim 6 , wherein the operating mode is only changed into the unsealed mode by a physical instruction locally on the hardware security module or logically via an unseal-command to be received via the first interface.

12. The method according to claim 6 , wherein the configuration data is deleted automatically in case the sealed mode is changed into the unsealed mode.

13. A hardware security module for usage with manufacturing devices, comprising:

a secure element configured to detect an operating mode of the hardware security module, the operating mode including an unsealed mode and a sealed mode;

a first interface configured to receive commands for controlling the hardware security module in both the sealed mode and the unsealed mode;

a central processing unit for processing application program code in a secure environment, wherein the secure element is integrated into the central processing unit and detects the operating mode automatically;

a second interface configured for receiving configuration data, wherein the second interface is activated and deactivated in dependence of the operating mode such that the second interface receives the configuration data only in the sealed mode; and

a switch coupled to the first interface and the second interface, wherein a control signal is provided by the secure element to directly control the switch to activate or deactivate the second interface by coupling or decoupling the second interface from the first interface.

14. The hardware security module according to claim 13 , wherein the hardware security module comprises a third interface for debugging application program code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2021
From: ASCHAUER, HANS; FALK, RAINER; FEIST, CHRISTIAN PETER; SCHNEIDER, DANIEL
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 056369/0981 →
Priority Claims (1)
EP 17210647 · Dec 27, 2017 · regional
Continuity (1)
Related Publication 20210224377A1 · Jul 22, 2021