Patents by Inventor Rainer Falk

Rainer Falk has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11201733
    Abstract: Provided is a method for transferring data in a topic-based publish-subscribe system, including a key distribution server and a number of local client systems that can be coupled to the key distribution server, including: providing a group key by the key distribution server for a group selected from the local client systems, locally deriving a first-order sub-group key for a first-order subgroup of the group by key derivation parameters at least comprising the provided group key and a certain topic of the publish-subscribe system by means of the particular client system of the first-order sub-group, and transferring at least one message cryptographically protected by the derived first-order sub-group key between the client systems of the first-order sub-group. Differentiation within group communication according to topic by specific cryptographic keys is thereby enabled.
    Type: Grant
    Filed: September 15, 2017
    Date of Patent: December 14, 2021
    Inventors: Steffen Fries, Rainer Falk
  • Publication number: 20210365313
    Abstract: A method and a device for a reaction-free and integrity-protected synchronization of log data between at least one first network and a second network is provided. The log data is copied by means of a monitoring device upon being transmitted from devices to a first log server in the first network. Metadata of the log data is additionally generated in a first managing unit, the metadata including time information, integrity information, origin information, and/or completeness information. The copied log data and the corresponding metadata are transmitted to the second network via a unidirectional coupling unit in a reaction-free manner. The lot data is checked and ordered chronologically in the second network using the metadata. Thus, a synchronized copy of the log data from the first network is promptly provided in the second network.
    Type: Application
    Filed: September 27, 2018
    Publication date: November 25, 2021
    Inventors: Rainer Falk, Matthias Seifert, Martin Wimmer
  • Patent number: 11184151
    Abstract: Apparatuses for a set of cryptographically protected and filtered and also sorted transaction data records of a link of a blockchain and to a method for forming a set of the sorted transaction data records is provided. One aspect is an apparatus for providing a set of cryptographically protected and filtered transaction data records from a set of integrity-checked and semantically sorted transaction data records of a link of a blockchain, which link is formed in particular using the method of providing at least one such link of a blockchain and coupling to a filtering device that ascertains the set of filtered transaction data records from the set of checked and semantically sorted transaction data records of the blockchain by using a filter criterion, and outputting the ascertained set of filtered transaction data records.
    Type: Grant
    Filed: July 9, 2018
    Date of Patent: November 23, 2021
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventor: Rainer Falk
  • Patent number: 11177952
    Abstract: A method for the disclosure of at least one cryptographic key used for encrypting at least one communication connection between a first communication subscriber and a second communication subscriber in which, in a publish-subscriber server, at least one of the communication subscribers logs on as a publishing unit and at least one monitoring device logs on as a subscribing unit, and in a subsequent negotiation of a cryptographic key by the publishing unit, automatically the negotiated cryptographic key is supplied from the publishing unit to the publish-subscribe server, the negotiated cryptographic key is transmitted from the publish-subscribe server to the at least one subscribing unit, and the encrypted communication connection from the subscribing unit is decrypted using the cryptographic key is provided. The following also relates to a corresponding system.
    Type: Grant
    Filed: January 16, 2019
    Date of Patent: November 16, 2021
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Steffen Fries, Rainer Falk
  • Publication number: 20210349443
    Abstract: Methods for the computer-supported creation and execution of a control function are provided. The control function can be implemented in particular for a specific technical system, for example an automation system, and can in particular be cryptographically protected by a blockchain. In particular, the methods are suitable for a specific technical system, for example an automation system.
    Type: Application
    Filed: December 18, 2017
    Publication date: November 11, 2021
    Inventor: Rainer Falk
  • Patent number: 11171922
    Abstract: A VPN box is connected upstream of a field device. The VPN box uses a secret cryptographic key of the field device for authentication when setting up a VPN tunnel and/or when setting up a cryptographically protected communication link.
    Type: Grant
    Filed: September 5, 2011
    Date of Patent: November 9, 2021
    Assignee: Siemens Mobility GmbH
    Inventors: Rainer Falk, Steffen Fries
  • Publication number: 20210342363
    Abstract: A block formation device and to a node device for a distributed database system, each having a unit for receiving a timing clock pulse from a time source and determining time slices of prescribed length on the basis of the timing clock pulse is provided. The block formation device is configured to select transactions to be confirmed precisely once within a respective time slice from unconfirmed transactions provided in the database system, to form an unconfirmed block from the selected unconfirmed transactions and to provide the unconfirmed block in the database system. The node device is configured to store a chain of confirmed blocks representing a transaction log of the database system; and, within a respective time slice, to confirm precisely one from unconfirmed blocks provided in the database system in the time slice precisely once and to add it to the chain of confirmed blocks.
    Type: Application
    Filed: August 22, 2019
    Publication date: November 4, 2021
    Inventor: Rainer Falk
  • Patent number: 11165773
    Abstract: A network device, including two interfaces for connecting to an access-protected access point of a data network and to a network component which is to be allowed access to the data network via the access point is provided. The network device is designed to be authenticated at the access point using authentication data when the access point is connected and the network component is connected and to allow the connected network component to access the data network via the access point in the event of a successful authentication at least for network components which satisfy one or more specified criteria.
    Type: Grant
    Filed: May 31, 2016
    Date of Patent: November 2, 2021
    Inventors: Hendrik Brockhaus, Jens-Uwe Bußer, Rainer Falk
  • Patent number: 11159492
    Abstract: An apparatus for adapting authorization information for a terminal is provided. The apparatus has a communication unit for communicating with the terminal, the communication unit being configured to carry out the communication as a test communication using an encryption protocol, a checking unit for checking a configuration of the encryption protocol on the terminal, and a control unit for adapting the authorization information for the terminal on the basis of a result of the check. A corresponding method for adapting authorization information for a terminal is also proposed. The proposed apparatus makes it possible to check the options supported by a terminal in an encryption protocol. In this case, the check can be carried out, in particular, using an encrypted communication connection which could not be monitored by a firewall.
    Type: Grant
    Filed: November 14, 2016
    Date of Patent: October 26, 2021
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventors: Rainer Falk, Steffen Fries
  • Publication number: 20210326441
    Abstract: An object of the disclosure is to simplify security enhancements based on trusted computing. For this, a first data processing apparatus configured to operate in accordance with one or more platform configuration is provided. The first data processing apparatus includes an attestation processor, a network interface, and a data storage device for storing validation data. The attestation processor is configured to establish attestation data that is indicative of a current platform configuration. The validation data facilitates a validity check of integrity data, which includes the attestation data. The first data processing apparatus is configured to provide the integrity and validation data.
    Type: Application
    Filed: April 12, 2019
    Publication date: October 21, 2021
    Inventor: Rainer Falk
  • Publication number: 20210321256
    Abstract: The invention relates to a computer-implemented method for connecting a network component to a network, in particular a mobile communications network, with an extended network access identifier. The method involves a receiving of the extended network access identifier from the network component via a network access server, wherein the extended network access identifier comprises at least one network access restriction for connecting the network component to the network. The method also involves a receiving of a requested user access profile from a user profile server via the network access server, wherein the user access profile comprises access authorisations for connecting the network component to the network. The network component is authenticated in the network via the network access server, if the received extended network access identifier fulfills thre access authorisations of the received user access profile.
    Type: Application
    Filed: August 2, 2019
    Publication date: October 14, 2021
    Inventor: Rainer Falk
  • Publication number: 20210314775
    Abstract: Provided is a method for setting up access authorization for a subscriber apparatus to access a subnetwork of a mobile radio network, wherein the subnetwork is administrated by a mobile radio administration apparatus and the access authorization for the subscriber apparatus to access the subnetwork is checked by an access apparatus of the mobile radio network, wherein—access authorization to access the subnetwork is requested for the subscriber apparatus from the mobile radio administration apparatus by a local administration apparatus,—a subnetwork authorization token is assigned to the subscriber apparatus by the mobile radio administration apparatus and transmitted to the subscriber apparatus, wherein the subscriber apparatus is authorized to access the subnetwork only if the subnetwork authorization token is transmitted from the subscriber apparatus to the subnetwork during an access request and is confirmed as valid.
    Type: Application
    Filed: June 5, 2019
    Publication date: October 7, 2021
    Inventors: Rainer Falk, Steffen Fries, Joachim Walewski
  • Patent number: 11134072
    Abstract: Provided is a method for checking a safety rating of a first device with the aid of an associated digital certificate, including the steps: sending the digital certificate having an identifier of a safety rating from the first device to a second device, checking the identifier of the safety rating with respect to a predefined safety rule by means of the second device, executing safety measures in accordance with the result of checking the safety rules.
    Type: Grant
    Filed: December 22, 2016
    Date of Patent: September 28, 2021
    Inventors: Rainer Falk, Steffen Fries
  • Publication number: 20210297415
    Abstract: Provided a method for setting up an authorization verification for a first device, for example a field device in an automation system, wherein the first device is configured by configuration data transmitted to the first device from a configuration module that is detachably connected to the first device and, for example, is implemented in the form of an SD card or a USB stick, having: detection of a connection of a configuration module to the first device, reading configuration module-specific device information from the configuration module, requesting configuration module-specific authorization verification for the configuration model-specific device information from the first device in an authorization device, and storing the requested configuration module-specific authorization verification on a security storage unit of the first device.
    Type: Application
    Filed: July 9, 2019
    Publication date: September 23, 2021
    Inventor: Rainer Falk
  • Patent number: 11128551
    Abstract: A method and transmission apparatus for direct and feedback-free transmission of log messages from at least one first network into a second network is provided. Log messages are transmitted individually and directly. The log messages in the first network are monitored by a monitoring device and transmitted into the second network via a one-way data transmission unit. The transmission is thus carried out feedback-free and with integrity protected. Additionally, a log server having a line loop is provided. Local messages are transmitted via the line loop and filtered, monitored by a monitoring device and transmitted directly to a second log server in the second network via the one-way data transmission unit Thus, efficient transmission of log messages into a second network for real-time analysis is achieved.
    Type: Grant
    Filed: September 25, 2018
    Date of Patent: September 21, 2021
    Inventors: Rainer Falk, Matthias Seifert, Martin Wimmer
  • Publication number: 20210286906
    Abstract: Provided is a memory device for transmitting data between at least two computer devices, which are assigned to different network zones, which memory device contains at least one memory unit for storing data, at least two interfaces which lead towards the exterior and to which a respective one of the external computer devices can be connected for reading and/or writing data, and at least one control unit which is designed in such a way as to establish access rights to the data of the memory unit as a function of at least two of interfaces which lead towards the exterior. Thus, for example a data transmission can be established exclusively from a first computer device to a second computer device.
    Type: Application
    Filed: June 27, 2017
    Publication date: September 16, 2021
    Inventors: Steffen Fries, Martin Wimmer, Rainer Falk
  • Patent number: 11106828
    Abstract: Provided is a method and apparatus for providing a cryptographic security function for the operation of a device, and to an associated computer program (product). The method for providing a cryptographic security function for the operation of a device carries out the following steps: receiving a request to provide such a security function, providing an interface to a point providing such a security function, said point being called a trust anchor, wherein said interface determines context information in accordance with the application initialing the request, providing the requested security function for the application initiating the request, wherein the determined context information influences the provision of said security function.
    Type: Grant
    Filed: March 7, 2017
    Date of Patent: August 31, 2021
    Inventors: Rainer Falk, Dominik Merli, Stefan Pyka
  • Patent number: 11095444
    Abstract: Automatically and dynamically ascertaining by means of autoconfiguration whether used or activated and usable cipher suites and/or key lengths are sufficiently strong for current cryptographic protection of the control communication and/or other service access by virtue of 1) “cipher-suite”-based/-specific information available in the network/system being called up to ascertain reference cipher suites and/or 2) block chain information available in the network/system, containing data records referred to as “proof of work” for solving complex computation tasks, being called up or ascertained, with the ascertainment of block chain difficulty parameters as key length estimation parameters to ascertain appropriate reference key lengths, in particular reference minimum key lengths required for cryptoalgorithms, and 3) the ascertained reference cipher suites and/or the reference key lengths ascertained by the key length estimation parameters being compared with the used or activated and usable cipher suites and/or k
    Type: Grant
    Filed: January 11, 2018
    Date of Patent: August 17, 2021
    Assignee: SIEMENS AKTIENGESELLSCHAFT
    Inventor: Rainer Falk
  • Publication number: 20210224377
    Abstract: The following relates to a hardware security module for usage with manufacturing devices and a method for operating the same is provided. The security module includes: a secure element, which is adapted to detect an operating mode of the hardware security module; a first interface which is adapted to receive commands for controlling the hardware security module; a central processing unit for processing application program code in a secure environment; a second interface which is adapted for receiving configuration data, wherein the second interface is activated and deactivated in dependence of the detected operating mode.
    Type: Application
    Filed: November 14, 2018
    Publication date: July 22, 2021
    Inventors: Hans Aschauer, Rainer Falk, Christian Peter Feist, Daniel Schneider
  • Publication number: 20210226776
    Abstract: Signal, data transmission, and/or encryption units generating a cryptographic code using a cryptographic key before writing to a pseudorandom noise buffer memory. The PRN code generator comprises a first processor generating a PRN code from initial data using a cryptographic key. A second processor generates sections of the PRN code for integrity check purposes through computation using the same cryptographic key and initial data. Within the PRN code generator and before temporary storage of the PRN code in the buffer memory, there is a comparison device for comparing at least one duplicated section of the PRN code sequence cryptographically generated by the first processor with the section computed by the second processor. A blocking, stop and/or alarm function is activated in the comparison device and triggered on the basis of a predefined degree of matching between the section obtained through duplication and the computed section.
    Type: Application
    Filed: January 14, 2021
    Publication date: July 22, 2021
    Applicant: Siemens Aktiengesellschaft
    Inventor: Rainer Falk