IP Library Granted Patent US 11,783,039
Granted Patent B2
US 11,783,039 · App. 17/438,618 · Granted Oct 10, 2023

Method for verifying an execution environment used for execution of at least one hardware-application provided by a configurable hardware module

Inventors: Hans Aschauer (Munich, DE); Rainer Falk (Poing, DE); Christian Peter Feist (Munich, DE); Steffen Fries (Baldham, DE); Aliza Maftun (Munich, DE); Hermann Seuschek (Munich, DE); Thomas Zeschg (Munich, DE)
Assignee: Siemens Aktiengesellschaft
G06F21/57G06F21/76G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,783,039
App. No.
17/438,618
Granted
Oct 10, 2023
Kind
B2
Abstract

A method for verifying an execution environment provided by a configurable hardware module, where the execution environment is used for execution of at least one hardware-application, includes receiving a hardware-application 16 . The hardware-application includes configuration data describing an instantiation as a hardware-application component on the configurable hardware module. A received hardware-application is instantiated as the hardware-application component in the execution environment. The execution environment of the configurable hardware module that executes the hardware-application component in the respective execution environment is analyzed by an instantiated hardware-application component. The hardware application component communicates with a characterizing unit providing characterizing parameters for the execution environment of the configurable hardware module. The analyzed execution environment of the configurable hardware module is verified as admissible for execution of the hardware-application component if the analyzed execution environment matches the characterizing parameters provided by the characterizing unit.

Claims (33)

1. A method for verifying an execution environment provided by a configurable hardware module, wherein the execution environment in the configurable hardware module is used for execution of at least one hardware-application, the method comprising:

receiving, by the configurable hardware module, the hardware-application, wherein the hardware-application comprises configuration data describing an instantiation as a hardware-application component on the configurable hardware module;

instantiating the received hardware-application as the hardware-application component in the execution environment of the configurable hardware module;

analyzing, by the instantiated hardware-application component, the execution environment of the configurable hardware module that executes the hardware-application component in the respective execution environment, wherein the hardware application component communicates with a characterizing unit providing characterizing parameters for the execution environment of the configurable hardware module; and

verifying the analyzed execution environment of the configurable hardware module as admissible for execution of the hardware-application component when the analyzed execution environment matches the characterizing parameters provided by the characterizing unit,

wherein the hardware-application component changes into a hardware operation mode when the analyzed execution environment does not match the characterizing parameters provided by the characterizing unit, the hardware operation mode comprising:

changing the hardware operation mode of the hardware-application component into error modus, debugging modus, or error modus and debugging modus; and

repeating the verifying.

2. The method of claim 1 , wherein further comprises:

limiting functionality of the hardware-application component; or

deactivating the functionality of the hardware-application component.

3. The method of claim 2 , wherein the characterizing unit comprises characterizing parameters specifying the reconfiguration region of the configurable hardware module.

4. The method of claim 3 , wherein the characterizing unit is included in the configurable hardware module.

5. The method of claim 2 , wherein the characterizing unit comprises characterizing parameters specifying at least one partial reconfiguration region of the reconfiguration region of the configurable hardware module.

6. The method of claim 5 , wherein the characterizing unit is included in the hardware-application component.

7. The method of claim 1 , wherein the execution environment of the configurable hardware module comprises a reconfiguration region of a configurable hardware module, at least one partial reconfiguration region of the reconfiguration region of the configurable hardware module, or a combination thereof.

8. The method of claim 1 , wherein the configurable hardware module comprises a field programmable gate array, an application specific integrated circuit, or an application specific standard product.

9. The method of claim 1 , wherein the characterizing unit comprises a physical unclonable function, a ring oscillator, or a ring oscillator-physical unclonable function.

10. The method of claim 9 , wherein the characterizing parameter comprises a reference-value used for calculating a hamming-distance of changing bits.

11. The method of claim 10 , wherein the reference-value is encrypted or signed with a hardware-application component specific key by the hardware-application component.

12. The method of claim 9 , wherein the characterizing parameter comprises a reference-value including bits with a defined stable or instable state.

13. The method of claim 9 , wherein the characterizing parameter comprises a challenge-response-list.

14. The method of claim 9 , wherein the characterizing parameter comprises an encrypted key generated by the hardware-application component.

15. An apparatus for verifying an execution environment provided by a configurable hardware module, wherein the execution environment in the configurable hardware module is used for execution of at least one hardware-application, the apparatus comprising:

a processing unit configured to:

provide the hardware-application, wherein the hardware-application comprises configuration data describing the instantiation as a hardware-application component on the configurable hardware module;

instantiate a provided hardware-application as the hardware-application component in the execution environment of the configurable hardware module;

receive a result from analysis of the execution environment of the configurable hardware module that executes the hardware-application component processed by an instantiated hardware-application component, wherein the hardware-application component is in communication with a characterizing unit providing characterizing parameters for the execution environment of the configurable hardware module; and

verify the analyzed execution environment of the configurable hardware module as admissible for execution of the hardware-application component based on a received result when the analyzed execution environment matches the characterizing parameters provided by the characterizing unit,

wherein the hardware-application component is configured to change into a hardware operation mode when the analyzed execution environment does not match the characterizing parameters provided by the characterizing unit, the hardware operation mode comprising:

change of the hardware operation mode of the hardware-application component into error modus, debugging modus, or error modus and debugging modus;

and

 repetition of the verification.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2021
From: ASCHAUER, HANS; FALK, RAINER; FEIST, CHRISTIAN PETER; FRIES, STEFFEN; MAFTUN, ALIZA; SEUSCHEK, HERMANN; ZESCHG, THOMAS
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 058168/0772 →
Priority Claims (1)
EP 19162488 · Mar 13, 2019 · regional
Continuity (1)
Related Publication 20220188418A1 · Jun 16, 2022