Vehicle control device
    2.
    发明授权
    Vehicle control device 失效
    车辆控制装置

    公开(公告)号:US06125309A

    公开(公告)日:2000-09-26

    申请号:US978188

    申请日:1997-11-25

    申请人: Takanori Fujimoto

    发明人: Takanori Fujimoto

    IPC分类号: F02D45/00 G05B19/042 G06F7/00

    摘要: The contents of a ROM are highly reliably changed while the ROM is attached to a substrate. A vehicle control device has an electrically programmable nonvolatile memory storing a vehicle control program. A ROM update process includes a collation in which a check is made to determine whether the updating of the ROM was correctly executed. An abnormal process ensures an output from the control device clearly is an abnormal control amount under even ordinary vehicle drive conditions.

    摘要翻译: ROM安装在基板上时,可高度可靠地改变ROM的内容。 车辆控制装置具有存储车辆控制程序的电可编程非易失性存储器。 ROM更新处理包括核对,其中进行检查以确定ROM的更新是否被正确执行。 异常过程确保在普通车辆驾驶条件下,控制装置的输出明显是异常控制量。

    EQUIPMENT MANAGEMENT SYSTEM, PROGRAMMABLE CONTROLLER AND CENTRALIZED CONTROLLER
    3.
    发明申请
    EQUIPMENT MANAGEMENT SYSTEM, PROGRAMMABLE CONTROLLER AND CENTRALIZED CONTROLLER 有权
    设备管理系统,可编程控制器和集中控制器

    公开(公告)号:US20100004758A1

    公开(公告)日:2010-01-07

    申请号:US12373629

    申请日:2006-07-13

    申请人: Hirotaka Masui

    发明人: Hirotaka Masui

    IPC分类号: G05B19/05 G05B9/02

    CPC分类号: G05B19/058 G05B2219/24155

    摘要: A centralized controller 2 controls facility equipment 3a and 3b according to a sequence control program corresponding to standard functions of the facility equipment 3a and 3b. In addition, the centralized controller 2 receives control information for controlling a unique function of the facility equipment 3a and 3b and a PIN code, which are transmitted from a programmable controller 1, and transmits, if the PIN code is a valid code, the control information to the facility equipment 3a and 3b.

    摘要翻译: 集中控制器2根据与设备设备3a和3b的标准功能对应的顺序控制程序控制设备设备3a和3b。 此外,集中控制器2接收用于控制设备设备3a和3b的独特功能的控制信息以及从可编程控制器1发送的PIN码,并且如果PIN码是有效代码,则发送控制 信息到设施设备3a和3b。

    Electronic control device
    4.
    发明申请
    Electronic control device 有权
    电子控制装置

    公开(公告)号:US20030221049A1

    公开(公告)日:2003-11-27

    申请号:US10441172

    申请日:2003-05-20

    IPC分类号: G06F012/00

    摘要: An ECU includes a microcomputer that has an integrated flash memory. An initial writing flag is set in the microcomputer before an initial writing to the flash memory. The microcomputer enters into a writing mode when the flag determines permission of data writing. When the data-writing to the flash memory is completed, the flag is cleared.

    摘要翻译: ECU包括具有集成闪存的微型计算机。 在对闪存进行初始写入之前,在微计算机中设置初始写入标志。 当标志确定数据写入的许可时,微型计算机进入写入模式。 闪存数据写入完成后,标志被清除。

    Method and system for changing safety-relevant data for a control device
    5.
    发明授权
    Method and system for changing safety-relevant data for a control device 有权
    用于改变控制装置的安全相关数据的方法和系统

    公开(公告)号:US08700914B2

    公开(公告)日:2014-04-15

    申请号:US12301197

    申请日:2007-04-26

    IPC分类号: G06F11/30 G05B19/04 G06F21/57

    摘要: A system and method for changing safety-relevant data for a control device is provided wherein an authorized user inputs new or altered safety-relevant data, which is received on a data processing installation. A first checksum for the safety-relevant data is established and stored along with the safety-relevant data in at least one data record on the data processing installation. An enable code may also be stored in the at least one data record. This enable code may be produced by a code generator and encrypted by a key module. The data processing installation then reads back the safety-relevant data from a memory in the data processing installation, thereby allowing a comparison of the received safety-relevant data and the read back safety-relevant data. A second checksum is generated in a case where the comparison resulted in no differences. The second checksum may also be stored in the at least one data record. At least one new data record containing the safety-relevant data, the encrypted enable code and the first and second checksums is created and transmitted to the control device. The new data record is checked against prior data records and prior checksums stored on a storage medium to determine that the at least one new data record is known to the control device.

    摘要翻译: 提供了一种用于改变控制装置的安全相关数据的系统和方法,其中授权用户输入在数据处理装置上接收的新的或改变的安全相关数据。 建立安全相关数据的第一个校验和,并与安全相关的数据一起存储在数据处理设备的至少一个数据记录中。 启用代码也可以存储在至少一个数据记录中。 该启用代码可以由代码生成器产生并由密钥模块加密。 然后,数据处理装置从数据处理装置中的存储器读回与安全相关的数据,从而允许对所接收的安全相关数据和回读安全相关数据进行比较。 在比较结果没有差异的情况下产生第二校验和。 第二校验和也可以存储在至少一个数据记录中。 至少一个包含安全相关数据,加密启用码以及第一和第二校验和的新数据记录被创建并发送到控制设备。 根据存储在存储介质上的先前数据记录和先前校验和来检查新数据记录,以确定控制装置已知至少一个新的数据记录。

    CHECKING A CONFIGURATION MODIFICATION FOR AN IED
    6.
    发明申请
    CHECKING A CONFIGURATION MODIFICATION FOR AN IED 审中-公开
    检查一个IED的配置修改

    公开(公告)号:US20120198226A1

    公开(公告)日:2012-08-02

    申请号:US13408755

    申请日:2012-02-29

    申请人: Wolfgang WIMMER

    发明人: Wolfgang WIMMER

    IPC分类号: G06F9/00

    摘要: Exemplary embodiments are directed to a system and method of checking, during regular operation of a Process Control PC or Substation Automation SA system, an intended configuration modification for a mission-critical IED. The IED receives, from an authenticated requestor, a modification request directed to IED configuration, parameter or setting data. The IED then checks the requested configuration modification, and rejects it in case no approval or confirmation is made by an approver independent of the requestor, and otherwise accepts and implements. The IED authenticates the approver prior to receiving the request, and stores, in a local memory, a configuration modification plausibility check provided by the approver. The stored plausibility check is then performed, by a plausibility checking unit, on the intended modification, and the latter is rejected or approved based on a result of the stored plausibility check when applied to specific circumstances of the configuration modification request.

    摘要翻译: 示例性实施例涉及在过程控制PC或变电站自动化SA系统的常规操作期间检查用于任务关键IED的预期配置修改的系统和方法。 IED从认证请求者接收到针对IED配置,参数或设置数据的修改请求。 IED然后检查所请求的配置修改,并拒绝它,以防由批准人独立于请求者作出批准或确认,否则接受和实施。 IED在接收请求之前对批准人进行认证,并在本地存储器中存储由审批人提供的配置修改合理性检查。 然后,通过真实性检查单元,对预期的修改执行存储的合理性检查,并且当应用于配置修改请求的具体情况时,基于存储的合理性检查的结果拒绝或批准后者。

    PROTECTION UNIT FOR A PROGRAMMABLE DATA-PROCESSING SYSTEM
    7.
    发明申请
    PROTECTION UNIT FOR A PROGRAMMABLE DATA-PROCESSING SYSTEM 有权
    可编程数据处理系统的保护单元

    公开(公告)号:US20080235473A1

    公开(公告)日:2008-09-25

    申请号:US12045849

    申请日:2008-03-11

    IPC分类号: G06F12/00

    摘要: A data-processing system having at least one operating memory holding operating data is provided with a protection unit having an execution environment protected from unauthorized access. At least one monitoring logic in the execution environment is connected to the operating memory for monitoring unauthorized modifications, access, or similar protection violations of the operating data stored in the operating memory and for generating an output on detection of such a protection violation. A protection logic in the execution environment holds replacement data capable of replacing the operating data and is connected to the monitoring logic for, on generation of the output, providing to the operating memory the replacement data for the operation or for a substitute operation of the data-processing system.

    摘要翻译: 具有保存操作数据的至少一个操作存储器的数据处理系统具有保护单元,该保护单元具有防止未授权访问的执行环境。 执行环境中的至少一个监控逻辑连接到操作存储器,用于监视存储在操作存储器中的操作数据的未经授权的修改,访问或类似的保护违反,并且用于在检测到这种保护违规时生成输出。 执行环境中的保护逻辑保持能够替换操作数据的替换数据,并且连接到监控逻辑,以便在产生输出时向操作存储器提供用于操作的替换数据或数据的替换操作 处理系统。

    Signature process
    8.
    发明授权
    Signature process 有权
    签名过程

    公开(公告)号:US06816971B2

    公开(公告)日:2004-11-09

    申请号:US09792053

    申请日:2001-02-26

    IPC分类号: G06F1700

    摘要: In a process for ensuring the data integrity of software for influencing operation of a control unit of a motor vehicle, a pair of keys is provided for encrypting and decrypting electronic data. The first key is stored for access by a control unit in the motor vehicle, and software which is to be imported is signed by means of the second key. The signed software is imported into the memory of the control unit and the signature of the software is checked by means of the first key. The signature is accepted if the check has a positive result.

    摘要翻译: 在确保用于影响机动车辆的控制单元的操作的软件的数据完整性的过程中,提供了一对用于加密和解密电子数据的键。 第一个键被存储以供机动车辆中的控制单元访问,并且将要通过第二个键签署要导入的软件。 签名的软件被导入到控制单元的存储器中,并通过第一个键检查软件的签名。 如果支票有正面结果,则签名被接受。

    METHOD AND SYSTEM FOR CHANGING SAFETY-RELEVANT DATA FOR A CONTROL DEVICE
    9.
    发明申请
    METHOD AND SYSTEM FOR CHANGING SAFETY-RELEVANT DATA FOR A CONTROL DEVICE 有权
    用于更改用于控制设备的安全相关数据的方法和系统

    公开(公告)号:US20090313481A1

    公开(公告)日:2009-12-17

    申请号:US12301197

    申请日:2007-04-26

    IPC分类号: G06F12/14 G05B19/042

    摘要: A system and method for changing safety-relevant data for a control device is provided wherein an authorized user inputs new or altered safety-relevant data, which is received on a data processing installation. A first checksum for the safety-relevant data is established and stored along with the safety-relevant data in at least one data record on the data processing installation. An enable code may also be stored in the at least one data record. This enable code may be produced by a code generator and encrypted by a key module. The data processing installation then reads back the safety-relevant data from a memory in the data processing installation, thereby allowing a comparison of the received safety-relevant data and the read back safety-relevant data. A second checksum is generated in a case where the comparison resulted in no differences. The second checksum may also be stored in the at least one data record. At least one new data record containing the safety-relevant data, the encrypted enable code and the first and second checksums is created and transmitted to the control device. The new data record is checked against prior data records and prior checksums stored on a storage medium to determine that the at least one new data record is known to the control device.

    摘要翻译: 提供了一种用于改变控制装置的安全相关数据的系统和方法,其中授权用户输入在数据处理装置上接收的新的或改变的安全相关数据。 建立安全相关数据的第一个校验和,并与安全相关的数据一起存储在数据处理设备的至少一个数据记录中。 启用代码也可以存储在至少一个数据记录中。 该启用代码可以由代码生成器产生并由密钥模块加密。 然后,数据处理装置从数据处理装置中的存储器读回与安全相关的数据,从而允许对所接收的安全相关数据和回读安全相关数据进行比较。 在比较结果没有差异的情况下产生第二校验和。 第二校验和也可以存储在至少一个数据记录中。 至少一个包含安全相关数据,加密启用码以及第一和第二校验和的新数据记录被创建并发送到控制设备。 根据存储在存储介质上的先前数据记录和先前校验和来检查新数据记录,以确定控制装置已知至少一个新的数据记录。