WO2026017373 - VERFAHREN ZUM ZUGRIFF EINER VIRTUELLEN RECHENEINHEIT AUF EINE HARDWARESICHERHEITSEINHEIT IN EINER RECHENEINHEIT
National phase entry is expected:
Publication Number
WO/2026/017373
Publication Date
22.01.2026
International Application No.
PCT/EP2025/067832
International Filing Date
25.06.2025
Title **
[German]
VERFAHREN ZUM ZUGRIFF EINER VIRTUELLEN RECHENEINHEIT AUF EINE HARDWARESICHERHEITSEINHEIT IN EINER RECHENEINHEIT
[English]
METHOD FOR A VIRTUAL COMPUTING UNIT TO ACCESS A HARDWARE SECURITY UNIT IN A COMPUTING UNIT
[French]
PROCÉDÉ PERMETTANT QU'UNE UNITÉ INFORMATIQUE VIRTUELLE ACCÈDE À UNE UNITÉ DE SÉCURITÉ MATÉRIELLE DANS UNE UNITÉ INFORMATIQUE
Applicants **
ROBERT BOSCH GMBH
Inventors
POHL, Christopher
STUMPF, Frederic
Priority Data
102024206800.4
19.07.2024
DE
Application details
| Total Number of Claims/PCT | * |
| Number of Independent Claims | * |
| Number of Priorities | * |
| Number of Multi-Dependent Claims | * |
| Number of Drawings | * |
| Pages for Publication | * |
| Number of Pages with Drawings | * |
| Pages of Specification | * |
| * | |
| Number of Office Actions | * |
| * | |
International Searching Authority |
EPO
* |
| Recordal of a Change of the Applicant's Name/Address |
Change of Applicant's Name and Address
* |
| Type of Assignment |
The Standard Agent's Assignment
* |
| Applicant's Legal Status |
Legal Entity
* |
| * | |
| * | |
| * | |
| * | |
| * | |
| Entry into National Phase under |
Chapter I
* |
| Patent Delivery |
Send the Letters Patent by Courier
* |
| Translation |
|
* The data is based on automatic recognition. Please verify and amend if necessary.
** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.
Quotation for National Phase entry
| Country | Stages | Total | |
|---|---|---|---|
| China | Filing, Examination, Granting | 2025 | |
| EPO | Filing, Examination, Granting | 8147 | |
| Japan | Filing, Examination, Granting | 2174 | |
| South Korea | Filing, Examination, Granting | 2050 | |
| USA | Filing, Examination, Granting | 5340 |

Total:
19,736
Contact Us
Abstract[German]
Die Erfindung betrifft ein Verfahren zum Zugriff einer virtuellen Recheneinheit (1110) auf eine Hardwaresicherheitseinheit (1300), wobei in einer Recheneinheit (1000) eine erste Ausführungsumgebung (1100) und eine zweite Ausführungsumgebung (1200) implementiert sind, wobei in der ersten Ausführungsumgebung (1100) Anwendungen mit einer ersten Sicherheitsstufe ausführbar sind und wobei in der zweiten Ausführungsumgebung (1200) Anwendungen mit einer zweiten Sicherheitsstufe ausführbar sind, die höher ist als die erste Sicherheitsstufe, wobei in der ersten Ausführungsumgebung (1100) mehrere virtuelle Recheneinheiten (1110) implementiert sind, wobei in jeder dieser virtuellen Recheneinheiten (1110) jeweils Anwendungen (1111) mit der ersten Sicherheitsstufe ausführbar sind, wobei die Recheneinheit (1000) eine Hardwaresicherheitseinheit (1300) aufweist, wobei die Hardwaresicherheitseinheit (1300) dazu eingerichtet ist, Sicherheitsanwendungen auszuführen, wobei das Verfahren die folgenden Schritte umfasst ein Senden einer Zugriffsanfrage von einer jeweiligen Anwendung (1111) einer jeweiligen anfragenden virtuellen Recheneinheit (1110) für einen jeweiligen Zugriff an die Hardwaresicherheitseinheit (1300); Bestimmen von Identifikationsinformationen bezüglich der jeweiligen anfragenden virtuellen Recheneinheit (1110) durch eine Identifikationsbestimmungseinheit (1230) in der zweiten Ausführungsumgebung (1200); Übermitteln der Zugriffsanfrage zusammen mit den bestimmten Identifikationsinformationen durch eine Übermittlungseinheit (1250) an die Hardwaresicherheitseinheit (1300); Ausführen des jeweiligen Zugriffs in der Hardwaresicherheitseinheit (1300) abhängig von den bestimmten Identifikationsinformationen derart, dass der Zugriff gemäß einem für die jeweilige anfragende virtuelle Recheneinheit (1110) vorgegebenen Zugriffsumfang erfolgt.[English]
The invention relates to a method for a virtual computing unit (1110) to access a hardware security unit (1300), wherein a first execution environment (1100) and a second execution environment (1200) are implemented in a computing unit (1000), wherein applications having a first security level can be executed in the first execution environment (1100), and wherein applications having a second security level, which is higher than the first security level, can be executed in the second execution environment (1200), wherein a plurality of virtual computing units (1110) are implemented in the first execution environment (1100), wherein applications (1111) having the first security level can be executed in each of these virtual computing units (1110), wherein the computing unit (1000) has a hardware security unit (1300), wherein the hardware security unit (1300) is configured to execute security applications, wherein the method comprises the following steps: sending an access request from an application (1111) of a requesting virtual computing unit (1110) for access to the hardware security unit (1300); determining identification information relating to the requesting virtual computing unit (1110) by means of an identification determination unit (1230) in the second execution environment (1200); transmitting the access request together with the determined identification information to the hardware security unit (1300) by means of a transmission unit (1250); carrying out the access in the hardware security unit (1300) depending on the determined identification information in such a way that the access takes place in accordance with an access scope specified for the requesting virtual computing unit (1110).[French]
L'invention concerne un procédé permettant qu'une unité informatique virtuelle (1110) accède à une unité de sécurité matérielle (1300), un premier environnement d'exécution (1100) et un second environnement d'exécution (1200) étant implémentés dans une unité informatique (1000), des applications ayant un premier niveau de sécurité pouvant être exécutées dans le premier environnement d'exécution (1100), et des applications ayant un second niveau de sécurité, qui est supérieur au premier niveau de sécurité, pouvant être exécutées dans le second environnement d'exécution (1200), une pluralité d'unités informatiques virtuelles (1110) étant implémentées dans le premier environnement d'exécution (1100), des applications (1111) ayant le premier niveau de sécurité pouvant être exécutées dans chacune de ces unités informatiques virtuelles (1110), l'unité informatique (1000) ayant une unité de sécurité matérielle (1300), l'unité de sécurité matérielle (1300) étant configurée pour exécuter des applications de sécurité, le procédé comprenant les étapes suivantes : envoyer une demande d'accès par une application (1111) d'une unité informatique virtuelle demandeuse (1110) pour accéder à l'unité de sécurité matérielle (1300) ; déterminer des informations d'identification relatives à l'unité informatique virtuelle demandeuse (1110) au moyen d'une unité de détermination d'identification (1230) dans le second environnement d'exécution (1200) ; transmettre la demande d'accès conjointement avec les informations d'identification déterminées à l'unité de sécurité matérielle (1300) au moyen d'une unité de transmission (1250) ; effectuer l'accès dans l'unité de sécurité matérielle (1300) en fonction des informations d'identification déterminées de telle sorte que l'accès a lieu conformément à des limites d'accès spécifiée pour l'unité informatique virtuelle demandeuse (1110).