摘要:
A multi-domain resource (208) access control mechanism uses a single access control system to manage access by users to resources that belong to multiple domains. A first server for a first domain (242) transmits a data token to a client seeking access to a resource in a second domain. The client transmit the data token to a second server (262) in the other domain. The second server uses the data token to verify that the user is authentic, that is, authorized to access resources protected by the access control system (220).
摘要:
Disclosed is an input unit (EE) for a field device, comprising a detection unit (EF) for an electronic identification of a user, making it possible to unambiguously identify the user.
摘要:
An industrial automation system comprises a security access device, an industrial automation device, a user interface, and a security interface. The user interface is configured to provide a user with access to data stored inside the industrial automation device. The security interface is configured to receive information from the access device and, based on the information received from the access device, to provide authorization for the user to access the data stored inside the industrial automation device using the user interface.
摘要:
The invention relates to a method for operating a control device (2), especially for controlling or adjusting a function of a motor vehicle. The control device (2) comprises a programmable memory device (1). Control or adjustment occurs by executing a computer program (PO) which is at least partially stored in the memory device (1) and by using data (DO) which is at least partially stored in the memory device (1). If a modification occurs in the computer program (PO) stored in the memory device (1) or if the data stored in the memory device (1) is modified, said modified computer program (PI) can only be executed and/or the modified data stored in the storage device (1) can only be used if the modified computer program (PI) and/or modified data is/are successfully verified in order to offer as efficient protection as possible against manipulation of the contents of the memory device (1) by an unauthorised person.
摘要:
The invention relates to a process automation system wherein process appliances (1 to 6) carry out pre-determined functions in terms of the process automation and interchange functional and/or appliance-related data (23, 24) with the process automation system, at least one part of the data (23, 24) being interchanged in an encoded manner.
摘要:
Zur Regelung und/oder der Steuerung des Betriebs einer Anlage (7) werden zu schützende Applikationsdaten verschlüsselt in einem externen Speicher (1) abgelegt und bei Start der Anlage (7) in einen internen Arbeitsspeicher (4) eines Steuergerätes eingelesen. Während dieses Einlesevorgangs werden die verschlüsselten Daten mit einem Entschlüsselungskode entschlüsselt. Zur Verschlüsselung wird ein Verschlüsselungskode verwendet, der so gestaltet ist, daß Kenntnis des Entschlüsselungskodes keinen Rückschluß auf den Verschlüsselungskode erlaubt. Durch diese doppelten Schlüssel ist sichergestellt, daß zu schützende Applikationsdaten einerseits manipulationssicher verschlüsselt werden können und andererseits im normalen Betrieb entschlüsselte Daten ohne Laufzeitprobleme verwendet werden können.
摘要:
A secure front-end communication system which couples a plurality of actively redundant process control computers to a computer network. The system includes a front end computer which is capable of establishing time limited communication contracts with one or more computer entity on the computer network. Each time limited communication contract is based upon an acceptable response to the transmission of an unpredicable signal from the front end computer, such as an encrypted transformation of a pseudo-random number generated by the front end computer. A security table is used to identify the network entities that are permitted to send write command messages to the process control computers to which the front end computer is connected. The front end computer also includes at least one permissive table which is used to determine whether a write command message from the network entity should be transmitted to the process control computer for which the message was intended.
摘要:
A control apparatus for an automobile is provided with a system manager (1), which initiates and manages the operation of units for controlling and operating various devices and accessories installed in the automobile. The system manager (1) is coupled with a card unit (13), in which a card is inserted. Such a card has an identification code of a user and a code indicating that the card is registered in advance. The system manager (1) has a list of codes of cards registered. If a card inserted is confirmed to be correct and valid by the ID and the registration code, the system manager (1) executes a predetermined processing operation and produces a set-up instruction signal. Upon receipt of this set-up instruction signal, the control units (19-35) for the devices and accessories are initiated.