Patents by Inventor Rainer Falk

Rainer Falk has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20240152627
    Abstract: Various embodiments of the teachings herein include a method for determining the integrity of data processing of operative data using a trusted execution environment. The method may include: presenting the trusted execution environment with input data including the operative data and test data; processing the input data to produce output data; subjecting that portion of the output data formed by the processed test data to a comparison with reference data; and using the comparison as a basis for determining the integrity of the data processing.
    Type: Application
    Filed: March 1, 2022
    Publication date: May 9, 2024
    Applicant: Siemens Aktiengesellschaft
    Inventors: Rainer Falk, Hans Aschauer, Omar Belhachemi, Christian Peter Feist, Hermann Seuschek, Thomas Zeschg
  • Publication number: 20240111268
    Abstract: A system, template, and method of managing virtual control units in an industrial automation facility are provided. The industrial automation facility includes machines. The method includes generating templates including deployment criteria for the virtual control units. Each of the virtual control units is capable of controlling at least one of the machines. The virtual control units are mapped to one or more compute nodes based on the deployment criteria. The virtual control units are instantiated on the mapped compute nodes when the controlled machines are in operation. The method includes validating that the instantiation of the virtual control units is in accordance with the templates using an attestation that confirms determined deployment parameters after deployment of the virtual control units. The machines perform the industrial process, according to control commands received from at least one of the virtual control units, when the virtual control units are validly instantiated.
    Type: Application
    Filed: September 29, 2023
    Publication date: April 4, 2024
    Inventors: Rainer Falk, Stefan Becker, Christian Peter Feist, Klaus-Peter Hofmann
  • Patent number: 11930071
    Abstract: Provided is a network adapter for unidirectional transmission of a user data stream to a bidirectional network interface, the network adapter including: a first connection unit which is physically connected to a bidirectional network interface of a first device; a second connection unit which is physically connected to a bidirectional network interface of a second device; and a terminating unit which has at least one bit transmission module and which is designed to establish a bidirectional data link to the network interface of the first device, to receive the user data stream from the first device exclusively in a unidirectional fashion via the data link, and not to send a user data stream to the first device.
    Type: Grant
    Filed: July 24, 2020
    Date of Patent: March 12, 2024
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Rainer Falk, Stefan Seltzsam, Hermann Seuschek, Martin Wimmer
  • Patent number: 11916903
    Abstract: Provided a method for setting up an authorization verification for a first device, for example a field device in an automation system, wherein the first device is configured by configuration data transmitted to the first device from a configuration module that is detachably connected to the first device and, for example, is implemented in the form of an SD card or a USB stick, having: detection of a connection of a configuration module to the first device, reading configuration module-specific device information from the configuration module, requesting configuration module-specific authorization verification for the configuration model-specific device information from the first device in an authorization device, and storing the requested configuration module-specific authorization verification on a security storage unit of the first device.
    Type: Grant
    Filed: July 9, 2019
    Date of Patent: February 27, 2024
    Assignee: SIEMENS MOBILITY GMBH
    Inventor: Rainer Falk
  • Patent number: 11914715
    Abstract: Provided is a device unit, including a module, which can configure the device unit with an operating state from among different operating states during the start-up process and/or during ongoing operation of the device unit, wherein a first protected operating state of the different operating states is designed to allow the execution of at least one operating process which can be predefined and to optionally protect the operating process by means of defined cryptographic means, wherein at least one second operating state of the different operating states is designed to deactivate the first protected operating state and to allow at least one other changeable operating process and to optionally protect the operating process by means of specifiable cryptographic means.
    Type: Grant
    Filed: October 10, 2017
    Date of Patent: February 27, 2024
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Hans Aschauer, Steffen Fries, Markus Heintel, Dominik Merli, Rainer Falk
  • Publication number: 20240039910
    Abstract: A method for authenticating a communication partner on a device is provided, in which method, in addition to a physical device implementation, there is at least one virtual device implementation allocated to the device, the method having the following steps: receiving an access authorization of a communication partner one first of these two device implementations, checking, by the first device implementation, the access authorization and if the access authorization is deemed permissible, providing an authorization verification from the first device implementation to the communication partner, and permitting an access to the second device implementation of these two device implementations by the communication partner by the authorization verification.
    Type: Application
    Filed: August 10, 2021
    Publication date: February 1, 2024
    Inventors: Rainer Falk, Steffen Fries
  • Patent number: 11882447
    Abstract: The invention relates to a computer-implemented method for connecting a network component to a network, in particular a mobile communications network, with an extended network access identifier. The method involves a receiving of the extended network access identifier from the network component via a network access server, wherein the extended network access identifier comprises at least one network access restriction for connecting the network component to the network. The method also involves a receiving of a requested user access profile from a user profile server via the network access server, wherein the user access profile comprises access authorisations for connecting the network component to the network. The network component is authenticated in the network via the network access server, if the received extended network access identifier fulfills thre access authorisations of the received user access profile.
    Type: Grant
    Filed: August 2, 2019
    Date of Patent: January 23, 2024
    Assignee: Siemens Aktiengesellschaft
    Inventor: Rainer Falk
  • Publication number: 20240022591
    Abstract: Various embodiments of the teachings herein include an attestation component configured to attest a cloud-based execution environment. The cloud-based execution environment comprises at least one application instance and a project plan assigned to the at least one application instance. The attestation component may include: a determination component configured to determine at least one piece of trustworthiness information indicating a trustworthiness of the cloud-based execution environment and of the at least one application instance; and a linking component configured to establish a link between the trustworthiness information and the project plan.
    Type: Application
    Filed: July 5, 2023
    Publication date: January 18, 2024
    Applicant: Siemens Aktiengesellschaft
    Inventors: Christian Peter Feist, Rainer Falk, Stefan Becker, Klaus-Peter Hofmann
  • Patent number: 11856106
    Abstract: Provided is a method for secure configuration of a device, having the following steps:—ascertaining a block chain data structure based on a cryptocurrency, wherein the block chain data structure has at least one block containing transaction data;—ascertaining at least one transaction belonging to the transaction data, the transaction having a piece of device configuration information;—examining the block chain data structure; and—configuring the device on the basis of the piece of device configuration information on successful examination. A complex independent examination by the device or an entity associated with the device is dispensed in an advantageous manner. The complex step of examination of the actual transaction is transferred to the block chain network and the client merely needs to validate a block chain data structure on the basis of a stability of the block chain.
    Type: Grant
    Filed: July 4, 2017
    Date of Patent: December 26, 2023
    Inventor: Rainer Falk
  • Patent number: 11853049
    Abstract: Monitoring the integrity of industrial automation systems is provided. For example, a negative impact on integrity caused by unauthorized access should be identified. This is made possible by comparing state data which describe the operating state of the industrial automation system, with sensor data which describe an environmental influence of the automation system.
    Type: Grant
    Filed: June 7, 2018
    Date of Patent: December 26, 2023
    Inventors: Steffen Fries, Rainer Falk
  • Patent number: 11838280
    Abstract: A detection device which is suitable for receiving a service within a network assembly is provided, having the following: means for providing cryptographic security at or above the transport level of the communication protocol levels which can be used in the network assembly for at least one first existing communication connection between the detection device and a network access device which is arranged in the network assembly and which can be used to monitor data detected by the detection device and/or control an additional device within the network assembly using the data detected by the detection device, means for generating and/or determining network access configuration data for at least one additional second communication connection, which is to be cryptographically secured below the transport level, between the detection device and the network access device, means for providing the generated and/or determined network access configuration data to the network access device.
    Type: Grant
    Filed: July 27, 2022
    Date of Patent: December 5, 2023
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Rainer Falk, Steffen Fries
  • Patent number: 11805110
    Abstract: Provided is a method for transmitting data packets over a network from a sender to a receiver via a communication link consisting of at least one transmission section, via which the data packet is transmitted from a sender node to a receiver node, the method having the following steps for at least one transmission section: first security information, which includes information about a cryptographic protective function used in the transmission of the data packet via an adjacent transmission section, is assigned to the data packet by the sender node, the data packet having the assigned security information is transmitted to the receiver node of the transmission section, the security information is checked in the receiver node against a preset guideline, and at least one measure is provided in accordance with the result of the check.
    Type: Grant
    Filed: March 6, 2020
    Date of Patent: October 31, 2023
    Inventors: Rainer Falk, Kai Fischer, Steffen Fries, Andreas Furch, Markus Heintel, Niranjana Papagudi Subrahmanyam, Tolga Sel
  • Patent number: 11783039
    Abstract: A method for verifying an execution environment provided by a configurable hardware module, where the execution environment is used for execution of at least one hardware-application, includes receiving a hardware-application 16. The hardware-application includes configuration data describing an instantiation as a hardware-application component on the configurable hardware module. A received hardware-application is instantiated as the hardware-application component in the execution environment. The execution environment of the configurable hardware module that executes the hardware-application component in the respective execution environment is analyzed by an instantiated hardware-application component. The hardware application component communicates with a characterizing unit providing characterizing parameters for the execution environment of the configurable hardware module.
    Type: Grant
    Filed: February 25, 2020
    Date of Patent: October 10, 2023
    Assignee: Siemens Aktiengesellschaft
    Inventors: Hans Aschauer, Rainer Falk, Christian Peter Feist, Steffen Fries, Aliza Maftun, Hermann Seuschek, Thomas Zeschg
  • Publication number: 20230308260
    Abstract: Various embodiments of the teachings herein include an apparatus for receiving cryptographically protected communication data. In some examples, the apparatus includes: a key generator for generating session keys; a receive module with a signal link to the key generator and configured to receive and decrypt cryptographically protected communication data into plaintext information using the session keys; and a check module with a signal link to the receive module and configured to subject the plaintext information to a check for context information characterizing a communication context of the encrypted communication data. The apparatus restricts action of the receive module depending on a result of the check.
    Type: Application
    Filed: March 22, 2023
    Publication date: September 28, 2023
    Applicant: Siemens Aktiengesellschaft
    Inventor: Rainer Falk
  • Publication number: 20230308266
    Abstract: Various embodiments of the teachings herein include a method for onboarding an IoT device (3) of a manufacturer, in a manner secure against quantum computer attacks, in an infrastructure of a customer by means of a first server (1) of a manufacturer domain of the manufacturer and a second server (2) of a customer domain of the customer. In some embodiments, three authenticated and encrypted communication channels and a key encapsulation method are used to provide a device certificate of the customer domain for the IoT device on the IoT device.
    Type: Application
    Filed: March 28, 2023
    Publication date: September 28, 2023
    Applicant: Siemens Aktiengesellschaft
    Inventors: Andreas Furch, Hans Aschauer, Fabrizio De Santis, Rainer Falk, Malek Safieh, Daniel Schneider, Florian Wilde, Thomas Zeschg
  • Patent number: 11764975
    Abstract: A method for validating a digital user certificate of a user by a checking device is provided. The user certificate is protected by a digital signature with an issuer key of an issuance location which issues the user certificate. The method has the steps of: receiving the user certificate in the checking device, checking the user certificate using a certificate path positive list with at least one valid certificate path which is provided to the checking device by at least one positive path server, and confirming the validity of the user certificate if the issuer key of the user certificate can be traced back to a root certificate according to one of the valid certificate paths of the certificate path positive list. Also provided is a system, a checking device, a user device, a positive path server, and a computer program product which are designed to carry out the method for validating a digital user certificate.
    Type: Grant
    Filed: December 11, 2019
    Date of Patent: September 19, 2023
    Inventors: Rainer Falk, Steffen Fries
  • Patent number: 11755719
    Abstract: The following relates to a hardware security module for usage with manufacturing devices and a method for operating the same is provided. The security module includes: a secure element, which is adapted to detect an operating mode of the hardware security module; a first interface which is adapted to receive commands for controlling the hardware security module; a central processing unit for processing application program code in a secure environment; a second interface which is adapted for receiving configuration data, wherein the second interface is activated and deactivated in dependence of the detected operating mode.
    Type: Grant
    Filed: November 14, 2018
    Date of Patent: September 12, 2023
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Hans Aschauer, Rainer Falk, Christian Peter Feist, Daniel Schneider
  • Publication number: 20230244472
    Abstract: Various embodiments of the teachings herein include a configuration device for determining an update configuration for a software update for a technical installation. The device may include: a module to acquire operating parameters of a production process of a technical installation, including configuration parameters of the technical installation; a module to load software updates for one or more elements of the technical installation; a module to use the operating parameters and the software updates as a basis for determining an update configuration for the software updates; and a module to transfer the update configuration and/or the software updates to an update server. The update server controls and/or monitors and/or records the software update of the one or more elements of the technical installation on the basis of the update configuration.
    Type: Application
    Filed: June 7, 2021
    Publication date: August 3, 2023
    Applicant: Siemens Aktiengesellschaft
    Inventors: Armin Amrhein, Stefan Becker, Rainer Falk, Axel Pfau
  • Patent number: 11662702
    Abstract: Provided is a method for producing a product by a machine tool, wherein the control information and/or production data of a machine tool, such as a milling machine, injection molding machine, welding robot, laser cutter or 3D printer, is protected or cryptographically encrypted such that unauthorized copying or modifying is prevented, including the steps: producing product by the machine tool taking into consideration control information which controls the production of the product; generating production data by the machine tool during production of the product, wherein the production data describes the production of the product; providing protection information to the machine tool, which indicates which of the production data is to be protected, and defines a protection method for the production data which is protected; and protecting that production data which, according to the protection information, is to be protected, by the protection method defined by the protection information.
    Type: Grant
    Filed: November 15, 2018
    Date of Patent: May 30, 2023
    Inventors: Omar Belhachemi, Rainer Falk, Christian Peter Feist, Kai Fischer, Daniela Friedrich, Steffen Fries, Markus Heintel
  • Patent number: 11658943
    Abstract: Provided is a detection device which is suitable for receiving a service within a network assembly, having the following:—means for providing cryptographic security at or above the transport level of the communication protocol levels which can be used in the network assembly for at least one first existing communication connection between the detection device and a network access device which is arranged in the network assembly and which can be used to monitor data detected by the detection device and/or control an additional device within the network assembly using the data detected by the detection device,—means for generating and/or determining network access configuration data for at least one additional second communication connection, which is to be cryptographically secured below the transport level, between the detection device and the network access device,—means for providing the generated and/or determined network access configuration data to the network access device.
    Type: Grant
    Filed: October 9, 2017
    Date of Patent: May 23, 2023
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Rainer Falk, Steffen Fries