IP Library Granted Patent US 12,323,532
Granted Patent B2
US 12,323,532 · App. 17/423,221 · Granted Jun 3, 2025

Methods, devices and system for the security-protected provision of sets of data

Inventor: Thomas Jetzfellner (Aschheim, DE)
Assignee: Innomotics GmbH
H04L9/3247G06F21/6227G06F21/64H04L9/3236H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,532
App. No.
17/423,221
Granted
Jun 3, 2025
Kind
B2
Abstract

An ecosystem of devices that autonomously interact with one another by a blockchain is provided, to create a security-protected data processing of sensor data or measurement data for an object by a blockchain infrastructure. Fields of application include supply-chain scenarios or industrial control applications of blockchains.

Claims (181)

1. A device for calculating a cryptographic checksum for a data structure, comprising:

a capture module for capturing individual features of an object by a capture device;

a calculation module for calculating an object-specific characteristic on a basis of the individual features;

a cryptography module for providing a first cryptographic key on a basis of the individual features; and

a protection module for cryptographically protecting a data structure by way of a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by way of the first cryptographic key,

wherein the individual features are compared with a predefined reference value, and when there is a match between the predefined reference value and the individual features the first cryptographic key is released by the cryptography module.

2. The device as claimed in claim 1 , wherein:

the characteristic is calculated taking into account specified tolerance values of the individual features,

the first cryptographic key is calculated on a basis of the characteristic and the individual features, or

a second cryptographic key, which decrypts the first cryptographic key, is calculated on the basis of the characteristic and the individual features.

3. The device as claimed in claim 1 , wherein:

the data structure comprises an object data record,

the object data record specifies geometric points and interfaces at which the capture device can capture the individual features,

the object data record comprises the individual features and the object-specific characteristic in encrypted form,

the encrypted the individual features or the object-specific characteristic can be decrypted by means of the first cryptographic key or a third cryptographic key,

the object data record comprises further object-related data, the further object-related data includes at least one of: measurement values of the object, measurement values about the object, manufacturing details of the object, and whereabouts of the object,

the further object data are captured by sensors of the device for the object,

the sensors include at least one of a GPS module, temperature sensors, optical sensors, and combinations thereof which detect corresponding properties of the object.

4. The device as claimed in claim 1 , wherein:

the first cryptographic key is additionally calculated taking into account by a secret character string, and

the first cryptographic key is a private key of an asymmetric key pair or is a symmetric key.

5. The device as claimed in claim 1 , wherein:

the data structure is a transaction of a distributed database system and the cryptographic checksum is the transaction checksum,

the distributed database system is a blockchain,

the device is as a node or oracle of the distributed database system,

the cryptographic checksum is a digital signature.

6. A verification device for verifying a cryptographic checksum of a data structure, comprising:

a reception module for receiving a data structure, wherein the data structure is protected by a cryptographic checksum;

a capture module for capturing individual features of an object by a capture device;

a calculation module for calculating an object-specific characteristic on a basis of the individual features;

a cryptography module for providing a first cryptographic key on a basis of the individual features and the object-specific characteristic; and

a verification module for verifying the cryptographic checksum by the first cryptographic key,

wherein the individual features are compared with a predefined reference value, and when there is a match between the predefined reference value and the individual features the first cryptographic key is released by the cryptography module.

7. A write control module, comprising:

a communication interface for transferring messages, wherein the messages are transferred to a distributed database system;

a verification module, wherein:

the verification module loads a data write configuration that specifies conditions under which the messages are written to the distributed database system,

the verification module verifies whether the conditions for writing the messages to the distributed database system are met;

a transfer control module, wherein:

the transfer control module controls a transfer of a message to the distributed database system by the communication interface on a basis of a check result of the verification module,

wherein the message contains an object with individual features such that the individual features are comparable with a predefined reference value, and when there is a match between the predefined reference value and the individual features a first cryptographic key is releasable by a cryptography module.

8. The write control module as claimed in claim 7 , wherein:

the data write configuration stipulates that one or more specified nodes have already written messages to the distributed database system,

the conditions of the data write configuration stipulate that messages from the nodes are already available in the distributed database system.

9. The write control module as claimed in claim 7 , wherein:

the checksums of messages from one or more nodes are verified when verifying the conditions of the data write configuration,

the messages for verification are stored in the distributed database system,

the conditions which the messages are to meet for verification are determined by the data write configuration.

10. The write control module as claimed in claim 7 , wherein:

the write control module selects one or more checksum-protected messages of the distributed database system, wherein corresponding data about the corresponding messages are stored by the sending apparatus,

the write control module verifies the selected messages or some of the selected messages on a basis of the stored messages when verifying the conditions of the data write configuration.

11. The write control module as claimed in claim 7 , wherein the data write configuration conditions comprise one, more or a combination of the following parameters:

a time window that must be observed for messages to be verified or selected,

the nodes are specified by the corresponding node information,

the messages of the corresponding nodes must comprise a specified content,

the checksums of the messages to be verified must meet specified cryptographic conditions.

12. A transmission apparatus for controlling a transmission of a message, comprising:

a message data capture module, wherein

the message data capture module reads a priority data record with a priority from a message,

the message data capture module reads a destination of the message,

the priority is assigned transmission parameters for the message transmission;

a determination module, wherein

the determination module generates a message control data record for controlling the transfer of the message on a basis of the destination and the priority,

the message control data record is assigned to the message,

a transfer module, wherein

the transfer module transmits the message to a node of a distributed database system depending on the message control data record,

the node is specified by the message control data record,

wherein the message contains an object with individual features such that the individual features are comparable with a predefined reference value, and when there is a match between the predefined reference value and the individual features a first cryptographic key is releasable by a cryptography module.

13. The transmission apparatus as claimed in claim 12 , wherein

the message control data record comprises a route over a plurality of nodes of the distributed database system,

to ascertain the route, the transmission time of messages between the nodes is transferred by the nodes to the transmission apparatus and, the corresponding transmission times are taken into account when ascertaining the message control data record,

the route for example is determined on a basis of the result of the check.

14. The transmission apparatus as claimed in claim 12 , wherein

the message control data record comprises configuration data,

the configuration data are determined on a basis of the result of a check,

there is verification as to whether the message is transferred in such a way that it observes the specifications of the priority or transmission parameters,

the transfer module is configured in such a way that a separate communication channel to the destination is set up to transfer the message.

15. The transmission apparatus as claimed in claim 12 , wherein

a confirmation transaction is stored in the distributed database system after the destination has received the message.

16. The transmission apparatus as claimed in claim 12 , wherein

the message control data record additionally comprises a preconfigured data record which at least partially specifies the transfer path of the message to the destination.

17. The transmission apparatus as claimed in claim 12 , wherein

the priority data record with the priority is specified by the sensor device and the message comprises a data structure, and

checksums are transaction checksums and the distributed database system is a blockchain and the message is a validated or unvalidated transaction of a distributed database system.

18. A system, comprising:

a generation module for generating messages for an object, wherein the message for example comprises a priority data record with a priority and a data structure;

a device for calculating a cryptographic checksum for the data structure, comprising:

a capture module for capturing individual features of the object by means of a capture device;

a calculation module for calculating an object-specific characteristic on a basis of the individual features;

a cryptography module for providing a cryptographic key on a basis of the individual features and the object-specific characteristic;

a protection module for cryptographically protecting the data structure by a cryptographic checksum, wherein the protection module calculates the cryptographic checksum by the cryptographic key;

a write control module, comprising:

a communication interface for transferring messages, wherein the messages are transferred to a distributed database system;

a verification module, wherein

the verification module loads a data write configuration that specifies conditions under which the messages are written to the distributed database system,

the verification module verifies whether the conditions for writing the messages to the distributed database system are met;

a transfer control module, wherein

the transfer control module controls a transfer of a message to the distributed database system by the communication interface on a basis of a check result of the verification module,

a transmission apparatus for controlling a transmission of the message via a plurality of nodes, comprising:

a message data capture module, wherein

the message data capture module reads a priority data record with a priority from a message,

the message data capture module reads a destination of the message,

the priority is assigned transmission parameters for the message transmission;

a determination module, wherein

the determination module generates a message control data record for controlling the transfer of the message on the basis of the destination and the priority,

the message control data record is assigned to the message,

a transfer module, wherein

the transfer module transmits the message to a node of a distributed database system depending on the message control data record,

the node is specified by the message control data record,

the communication interface transmits a message by the transmission apparatus.

19. A method of computer-aided calculation of a cryptographic checksum, the method comprising:

capturing individual features of an object by a capture device;

calculating an object-specific characteristic on a basis of the individual features;

providing a first cryptographic key on a basis of the individual features and the object-specific characteristic; and

cryptographically protecting a data structure by means of a cryptographic checksum, wherein the cryptographic checksum is calculated by the first cryptographic key;

comparing the individual features with a predefined reference value; and

releasing the first cryptographic key when there is a match between the predefined reference value and the individual features.

20. A method of computer-aided verification of a cryptographic checksum, the method comprising:

receiving a data structure, wherein the data structure is protected by a cryptographic checksum;

capturing individual features of an object by means of a capture device;

calculating an object-specific characteristic on a basis of the individual features;

providing a first cryptographic key on a basis of the individual features and the object-specific characteristic; and

verifying the cryptographic checksum by the first cryptographic key;

comparing the individual features with a predefined reference value; and

releasing the first cryptographic key when there is a match between the predefined reference value and the individual features.

21. A method of computer-aided control of a data transfer, the method comprising:

transferring messages, wherein the messages are transferred to a distributed database system;

verifying a data write configuration, wherein:

the data write configuration specifies conditions under which the messages are written to the distributed database system,

verifying whether the conditions for writing the messages to the distributed database system are met;

transferring the messages to a distributed database system by a communication interface, wherein:

the transfer is controlled on a basis of a check result of verifying the data write configuration, wherein

the messages each contain an object with individual features such that the individual features are comparable with a predefined reference value, and when there is a match between the predefined reference value and the individual features a first cryptographic key is releasable by a cryptography module.

22. A method of computer-aided control of a transmission of messages via a plurality of nodes, the method comprising:

reading a message of a priority data record with a priority of a message, wherein:

a destination of the message is read,

the priority is assigned transmission parameters for the message transmission;

determining a message control data record for controlling the transfer of the message on a basis of the priority and the destination, wherein:

the message control data record is assigned to the message,

transmitting the message to a node of a distributed database system depending on the message control data record, wherein:

the node is specified by the message control data record, and

wherein the message contains an object with individual features such that the individual features are comparable with a predefined reference value, and when there is a match between the predefined reference value and the individual features a first cryptographic key is releasable by a cryptography module.

23. A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method of computer-aided calculation of a cryptographic checksum, the method comprising:

capturing individual features of an object by a capture device;

calculating an object-specific characteristic on a basis of the individual features;

providing a first cryptographic key on a basis of the individual features and the object-specific characteristic; and

cryptographically protecting a data structure by means of a cryptographic checksum, wherein the cryptographic checksum is calculated by the first cryptographic key;

comparing the individual features with a predefined reference value; and

releasing the first cryptographic key when there is a match between the predefined reference value and the individual features.

24. A provision device for a computer program product, wherein the provision device stores or provides the computer program product, wherein the computer program product comprises a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method of computer-aided calculation of a cryptographic checksum, the method comprising:

capturing individual features of an object by a capture device;

calculating an object-specific characteristic on a basis of the individual features;

providing a first cryptographic key on a basis of the individual features and the object-specific characteristic; and

cryptographically protecting a data structure by means of a cryptographic checksum, wherein the cryptographic checksum is calculated by the first cryptographic key;

comparing the individual features with a predefined reference value; and

releasing the first cryptographic key when there is a match between the predefined reference value and the individual features.

25. A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method of computer-aided calculation of a cryptographic checksum, the method comprising:

receiving a data structure, wherein the data structure is protected by a cryptographic checksum;

capturing individual features of an object by means of a capture device;

calculating an object-specific characteristic on a basis of the individual features;

providing a first cryptographic key on a basis of the individual features and the object-specific characteristic; and

verifying the cryptographic checksum by the first cryptographic key;

comparing the individual features with a predefined reference value; and

releasing the first cryptographic key when there is a match between the predefined reference value and the individual features.

26. A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method of computer-aided calculation of a cryptographic checksum, the method comprising:

transferring messages, wherein the messages are transferred to a distributed database system;

verifying a data write configuration, wherein:

the data write configuration specifies conditions under which the messages are written to the distributed database system,

verifying whether the conditions for writing the messages to the distributed database system are met;

transferring the messages to a distributed database system by a communication interface, wherein:

the transfer is controlled on a basis of a check result of verifying the data write configuration, wherein

the messages each contain an object with individual features such that the individual features are comparable with a predefined reference value, and when there is a match between the predefined reference value and the individual features a first cryptographic key is releasable by a cryptography module.

27. A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method of computer-aided calculation of a cryptographic checksum, the method comprising:

reading a message of a priority data record with a priority of a message, wherein:

a destination of the message is read,

the priority is assigned transmission parameters for the message transmission;

determining a message control data record for controlling the transfer of the message on a basis of the priority and the destination, wherein:

the message control data record is assigned to the message,

transmitting the message to a node of a distributed database system depending on the message control data record, wherein:

the node is specified by the message control data record, and

wherein the message contains an object with individual features such that the individual features are comparable with a predefined reference value, and when there is a match between the predefined reference value and the individual features a first cryptographic key is releasable by a cryptography module.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2023
From: SIEMENS AKTIENGESELLSCHAFT
To: INNOMOTICS GMBH
Reel/Frame 065612/0733 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2021
From: JETZFELLNER, THOMAS
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 058182/0131 →
Priority Claims (1)
EP 19152115 · Jan 16, 2019 · regional
Continuity (1)
Related Publication 20220070006A1 · Mar 3, 2022
References Cited (33)
US 10193695B1 · Endress · 2019 [cited by examiner]
US 20120254322A1 · Majeti · 2012 [cited by examiner]
US 20150172056A1 · Meunier et al. · 2015 [cited by applicant]
US 20150269570A1 · Phan et al. · 2015 [cited by applicant]
US 20160300234A1 · Moss-Pultz · 2016 [cited by examiner]
US 20180255131A1 · Stöcker et al. · 2018 [cited by applicant]
US 20180276600A1 · Fuller et al. · 2018 [cited by applicant]
US 20190220831A1 · Rangarajan · 2019 [cited by examiner]
US 20210081938A1 · Falk · 2021 [cited by applicant]
CN 108288157A · 2018 [cited by applicant]
CN 108351998A · 2018 [cited by applicant]
EP 2887333A1 · 2015 [cited by applicant]
EP 3340213A1 · 2018 [cited by applicant]
EP 3382616A1 · 2018 [cited by applicant]
International Search Report and Written Opinion in related PCT Patent Application No. PCT/EP2019/081613 dated Mar. 23, 2020. 23 pages. [cited by applicant]
European Search Report in related European Patent Application No. 19152115.2 dated Jul. 1, 2019. 13 pages. [cited by applicant]
Extended European Search Report in related European Patent Application No. 19152115.2 dated Jul. 19, 2019. 20 pages. [cited by applicant]
Examination Report in related European Patent Application No. 19152115.2 dated Dec. 17, 2019. 4 pages. [cited by applicant]
Examination Report in related European Patent Application No. 19152115.2 dated May 26, 2020, 8 pages. [cited by applicant]
Clarkson, William, et al., “Fingerprinting Blank Paper Using Commodity Scanners,” Security and Privacy, 2009 30th IEEE Symposium on, IEEE, Piscataway, NJ, USA, pp. 301-314, XP031515112, ISBN: 978-0-7695-3633-0; pp. 302-… [cited by applicant]
DeJean, Gerald et al., “RF-DNA: Radio-Frequency Certificates of Authenticity,” Cryptographic Hardware and Embedded Systems—CHES 2007; [Lecture Notes in Computer Science], Springer Berlin Heidelberg, Berlin, Heidelberg, … [cited by applicant]
Unknown, et al., “Resource Fairness and Prioritization of Transactions in Permissioned Blockchain Systems (Industry Track),” Proceedings of the 19th International Middleware Conference Industry on, Middleware '18, pp. 4… [cited by applicant]
GitHub/ “The Ethereum Book Project/Mastering Ethereum,” https://github.com/ethereumbook/ethereumbook, Stand May 10, 2017; 2017; 3 pages. [cited by applicant]
Diedrich, Henning, “Ethereum: Blockchains, Digital Assets, Smart Contracts, Decentralized Autonomous Organizations,” CreateSpace Independent Publishing Platform, Sep. 8, 2016 // ISBN-10: 1523930470 // ISBN-13: 978-15239… [cited by applicant]
Antonopoulos, Andreas M., “Mastering Bitcoin: Unlocking Digital Cryptocurrencies,” O'Reilly Media, Dec. 2014, 282 pages. [cited by applicant]
Chen et al., “An Overview of Quality of Service Routing For Next-Generation High-Speed Networks: Problems and Solutions,” IEEE Network, IEEE Service Center, New York, NY, US, vol. 12, No. 6, pp. 64-79, XP000873129, ISSN… [cited by applicant]
Needham, Roger M., et al. “Using encryption for authentication in large networks of computers,” ACM: Communications of the ACM, vol. 21, No. 12, Dec. 1978; 1978; 8 pages. [cited by applicant]
Anderson, Ross “Security Engineering. A Guide to Building Dependable Distributed Systems,” Wiley; Jan. 2001; 200. 600 pages. [cited by applicant]
Baird, Leemon “The Swirlds Hashgraph Consensus Algorithm: Fair, Fast, Byzantine Fault Tolerance,” Swirlds Tech Report SWIRLDS-TR-2016-01; 2016; 28 pages. [cited by applicant]
Baird, Leemon “Overview of Swirlds Hashgraph,” Swirlds; 2016; 4 pages. [cited by applicant]
Blockchainhub: “Blockchain Oracles”, https://blockchainhub.net/blockchain-oracles/; 2018; 5 pages. [cited by applicant]
Liu Han et al:; “S-gram: Towards Semantic-Aware Security Auditing for Ethereum Smart Contracts”; ACM/IEEE International Conference on Automated Software Engineering (ASE ⋅18); Sep. 3-7, 2018; Montpellier; France. ACM, N… [cited by applicant]
Fang Weidong et al:; “Cyber Security in Blockchain: Threats and Countermeasures”; Dec. 31, 2018; China Academic Journal Electronic Publishing House. [cited by applicant]