Siemens LOGO! Know-How Protection: Locking Programs to a Memory Card
Siemens LOGO! logic modules (6ED1052-xBA8) ship with a User Password that prevents unauthorized editing, but they expose a separate anti-theft control called Know-How Protection. Know-How Protection binds an executable program to a LOGO! Memory Card so that the program only runs while the card remains plugged in, and the program cannot be uploaded back to LOGO!Soft Comfort without the correct PIN. This reference explains the underlying memory model, the exact configuration steps in LOGO!Soft Comfort, the deployment consequences (one card per deployed LOGO!), and the recovery paths when a card is lost or removed.
The official system manual is the Siemens LOGO! 8 System Manual (Entry ID 109744387); the product page is at siemens.com/logo.
1. Problem Definition: Program Theft on Field-Installed LOGO! Modules
Standard password protection on the LOGO! 8 generation (6ED1052-xBA8) covers a different threat than program theft. Setting a User Password stops an operator from opening the program, modifying a timer constant, or erasing the block from the LOGO!Soft Comfort editor, but it does not stop a knowledgeable technician from connecting an Ethernet or USB cable, performing a LOGO! → PC upload, and replaying the resulting .lsc or .lma file on a different, identically equipped LOGO!. For a machine builder, an integrator, or an OEM shipping duplicate equipment, the unprotected upload path is a real revenue-loss vector.
Know-How Protection is Siemens' answer to that vector. It is implemented at the LOGO!Soft Comfort → Memory Card transfer layer, not at the on-line editor. The protection is enforced in two ways: (a) the running program is the copy on the card, and (b) the upload function from the LOGO! to the PC refuses to read a know-how-protected block back to an editable project.
2. LOGO! Memory Architecture and Program Storage
Every LOGO! 8 base module contains two on-board non-volatile regions plus an external card slot. The CPU executes the program stored in the on-board EEPROM when the slot is empty. The moment a programmed Memory Card is inserted, the LOGO! compares the on-board program with the card program; if they differ, the card program wins and is copied to the on-board EEPROM. If the card contains a know-how-protected program, the on-board copy is locked in the same state and the card must remain present for the program to remain executable across a power cycle.
| Region | Volatile? | Capacity | Holds Know-How Protected Program? |
|---|---|---|---|
| On-board EEPROM (LOGO! 8) | No | 850 program blocks (LOGO! 8.0/8.1); up to 4,000 blocks (LOGO! 8.3/8.4) | Yes (mirror only — upload blocked) |
| On-board RAM | Yes | Process image, retentive markers, run-time web data | No |
| LOGO! Memory Card (6ED1056-1BA00-0AA0) | No | 256 KB; one full program | Yes (authoritative copy) |
| LOGO! Battery Card (6ED1056-6XA00-0AA0) | No (with CR2032 cell) | Same as Memory Card + RTC retention | Yes (preferred for long-life field units) |
| LOGO! SoftCard (6ED1056-5CA00-0AA0) | No | Older 0BA5/0BA6 only | Not supported on 0BA8 |
Removing the card from a running LOGO! does not stop execution immediately — the on-board EEPROM copy continues to run. After a power cycle, however, the LOGO! looks for the card, fails to find it, and reports "No Program" on the built-in display. This is the practical theft barrier: the unit is bricked for program purposes until the original card returns.
3. Protection Mechanisms Overview
LOGO!Soft Comfort V8.x exposes three independent locks. They can be combined; they are not mutually exclusive.
| Mechanism | Where Set | Blocks Edit? | Blocks Upload? | Requires Card? | Recoverable Without Secret? |
|---|---|---|---|---|---|
| User Password | LOGO!Soft Comfort → File → Properties → Password, or directly on the LOGO! display | Yes | No | No | No (factory reset clears it, but also clears program) |
| Know-How Protection | LOGO!Soft Comfort → Card write dialog, "Activate Know-How Protection" checkbox | No (independent) | Yes | Yes | No (without PIN, program cannot be lifted from card or LOGO!) |
| Card PIN (write protection) | LOGO!Soft Comfort Card menu → "Set Password" | Yes (read-back) | No (still uploads to a blank project) | Yes | No (forgotten PIN = bricked card) |
4. Password Protection: Edit Lock, Not Theft Lock
The User Password is a 4-character alphanumeric string (digits 0–9 and letters A–F only, due to the LOGO! numeric display) stored locally on the LOGO! 8 base module. It is set in two equivalent ways:
- From the LOGO! display: navigate to Setup → Password, enter a 4-char code, confirm.
- From LOGO!Soft Comfort during download: tick "Protect with password" and enter the same 4-char string; the editor will write it to the LOGO! on the next transfer.
With the password set, the LOGO! rejects any subsequent download from LOGO!Soft Comfort that does not include the matching password. The password blocks three operations: opening the project on the LOGO! (modifying parameters in the display), erasing the program from the LOGO! display menu, and any PC → LOGO! download of a different program. It does not block the LOGO! → PC upload (Tools → Transfer → Upload from LOGO!), and it does not stop the Memory Card from being read by a second LOGO!. A determined operator can copy the program out of the LOGO!, transfer it to a memory card, and clone the system. For theft defense, password protection is necessary but not sufficient.
5. Know-How Protection: Card-Locked Program Execution
Know-How Protection is implemented as a flag and a 4-character PIN stored on the Memory Card itself. The sequence is:
- Open the project in LOGO!Soft Comfort.
- Build the project to its final form (including all VM mapping, UDF blocks, and web editor configuration if used).
- Open Tools → Transfer → PC → LOGO! Card (or the equivalent toolbar icon).
- In the card write dialog, enable "Activate Know-How Protection" and assign a 4-character PIN.
- Insert the card into the target LOGO!. The LOGO! detects the protected program, refuses to upload it back to LOGO!Soft Comfort, and uses the card's program as the running image.
From that point, the following operations are blocked on the receiving LOGO!:
- Tools → Transfer → Upload from LOGO!: the editor returns "Know-how protection is active" and refuses to receive a usable project.
- LOGO! display menu: program blocks are visible only as opaque references; constants and block parameters are hidden.
- Inserting the card into a second LOGO!: the program will run, but the second LOGO! cannot upload it either, so cloning requires an unprotected card (which does not exist, because the program only exists on the protected card).
- Direct card-to-card copy using the LOGO!Soft Comfort card reader: the protected program cannot be exported to an editable
.lsc/.lmawithout the PIN.
6. Configuring Know-How Protection Step-by-Step in LOGO!Soft Comfort
This procedure is written against LOGO!Soft Comfort V8.4 (6ED1058-0BA08-0YA1) on a Windows 10/11 PC. Earlier V8.x versions are functionally identical; menu labels may differ slightly. Refer to the LOGO! 8 system manual for legacy UI paths.
Prerequisites:
- LOGO!Soft Comfort V8.0 or later (matches LOGO! 8 hardware generation).
- One blank LOGO! Memory Card (6ED1056-1BA00-0AA0) per deployed target.
- USB or Ethernet connection to the source LOGO! (for the initial project download if not authored offline).
- PC-based card reader (Siemens USB reader or compatible SC card reader).
- Service notebook with a project PIN store ready.
Procedure:
- Author or open the target project. Verify it online against a development LOGO! before writing to the card.
- Select Tools → Options → Transfer (or press F5) to open the transfer panel.
- Insert the Memory Card into the PC card reader. LOGO!Soft Comfort detects it in the dropdown.
- Click PC → LOGO! Card. The card write dialog opens.
- Tick "Activate know-how protection for this card".
- Enter a 4-character PIN twice. Siemens allows digits 0–9 and letters A–F only. Recommended: use a random 4-character hex string, not a memorable 4-digit number, and store it in the project vault.
- Click Write. The card write LED on the reader flashes; the operation takes 10–30 s for a typical project (under 8 kB block count).
- Insert the protected card into the target LOGO! 8 base module. Power cycle. The display should show Card Program, then Run.
- On the target LOGO!, navigate to Card → Card → Card Program to confirm the know-how lock is reported as ON.
Verification:
- With the protected LOGO! connected to LOGO!Soft Comfort, attempt Tools → Transfer → Upload from LOGO!. Expected response: "The program is know-how protected. Upload not possible."
- Remove the card, cycle power. The LOGO! should display "No Program" on the home screen. Re-insert the card and cycle power: the program should re-appear and start within 2 s.
- Insert the card into a second LOGO! of the same family (for example, a LOGO! 8.3 12/24 RCE) and repeat the upload attempt. Expected response: identical refusal. The program runs, but is non-extractable.
7. Card-to-LOGO! Transfer Workflow and Field Deployment
The deployment flow for a fleet of machines is intentionally one-card-per-machine. The card is the carrier of the protected program; the LOGO! is the runtime. The integrator workflow is:
Each fielded machine consumes one card. For a fleet of 50 units, plan for 50 cards (6ED1056-1BA00-0AA0, list price roughly €25–30 each in 2024) plus a single development unit. The cards are not re-useable for a different program without first clearing them in LOGO!Soft Comfort, which requires the original PIN — so an unauthorized holder cannot re-purpose a card to attack a different program.
8. Operational Constraints and Failure Modes
| Failure Mode | Symptom | Cause | Recovery |
|---|---|---|---|
| Card removed, no program | LOGO! display shows "No Program" | Operator pulled the card or it vibrated out of the slot | Re-insert the original card, power cycle |
| Card replaced with blank | LOGO! runs no program, but EEPROM copy still present until next power cycle | Maintenance replaced with wrong card | Restore original card; if lost, only re-authoring recovers the system |
| Forgot PIN | Card write fails with "Invalid PIN", cannot edit or re-issue | PIN not stored in project vault | No recovery; program is effectively lost. Re-author from documentation. |
| Card damaged | LOGO! reports "Card Error" or "Unknown Card" | Mechanical or ESD damage | Order replacement card (6ED1056-1BA00-0AA0), re-write from a non-protected backup if one exists, or re-author |
| LOGO! firmware older than card | LOGO! shows "Incompatible program version" | Card was written for LOGO! 8.4, inserted into 8.0 base module | Match firmware generations, or rewrite card with matching version |
| Card write-protect switch engaged | LOGO!Soft Comfort reports "Card is write-protected" | Mechanical slide on the SD card in LOCK position | Slide switch to UNLOCK and retry |
9. Multi-Unit Fleet Deployment Strategies
For a fleet of identical machines, three strategies are common, ranked by their trade-off between theft protection and operational flexibility.
Strategy A — One protected card per machine (recommended for OEM ship-out): Each machine receives one card with its know-how protected program. The OEM keeps the master unprotected .lsc file sealed in a vault. The integrator cannot clone the machine without the master, and the field operator cannot lift the program because both the card and the LOGO! refuse upload. This is the highest protection at the cost of a card per unit.
Strategy B — Single unprotected master + factory-programmed LOGO! modules: Program each LOGO! at the bench with a User Password only, no know-how protection. The card is not shipped with the unit. Field service can re-flash with a non-protected copy, but only if they obtain the master file. This is the standard approach for in-house equipment where the integrator trusts the operator population.
Strategy C — Hybrid: User Password on the LOGO!, know-how protection on a card that lives in the OEM's office: The machine runs from the on-board EEPROM (unprotected), the integrator's card never leaves the office. The on-board copy can be uploaded by anyone with the User Password, so this is the weakest strategy. Use only when machines are inside a locked customer facility with no risk of off-site theft.
10. Diagnostics, Error States, and Recovery
LOGO!Soft Comfort and the LOGO! display surface specific error conditions related to know-how protection. The most useful diagnostics:
- "Know-how protection is active" on upload attempt: the LOGO! is running a protected program. The editor cannot lift it.
- "Password incorrect" on card write: the PIN entered does not match the PIN on the card. The card is unchanged.
- "Card is write-protected": the card's mechanical write-protect switch (present on 6ED1056-1BA00-0AA0) is in the locked position. Slide it to unlock before re-writing.
- "Card Program" + "No Program" alternating on display: card and on-board program differ and the LOGO! is in a transitional state. Power cycle clears it.
- "No Card" on display: the slot is empty. The LOGO! will continue to run from the on-board EEPROM copy if present, or stop with "No Program" on next power cycle.
For deeper diagnostics on the Ethernet-equipped variants (LOGO! 12/24 RCE and 230 RCE), the built-in web server exposes machine state over HTTP. A field engineer can confirm card presence remotely rather than dispatching a technician to read the LOGO! display.
11. Comparison: Password vs Know-How Protection
| Property | User Password | Know-How Protection | Combined (recommended) |
|---|---|---|---|
| Stops casual edit | Yes | No (independent) | Yes |
| Stops upload (LOGO! → PC) | No | Yes | Yes |
| Stops card cloning | No | Yes | Yes |
| Requires memory card | No | Yes | Yes |
| Recovery if secret lost | Factory reset (loses program) | No recovery | Factory reset, re-issue from master vault |
| Best fit | Preventing operator tampering with parameters | Preventing program theft in shipped equipment | OEM ship-out with high IP value |
| Per-unit hardware cost | €0 | €25–30 (one card) | €25–30 (one card) |
The combined setup is what Siemens recommends in the LOGO! 8 system manual (Entry ID 109744387) for any unit that leaves the integrator's premises. The User Password gates display-side tampering with timers, counters, and threshold values; the know-how protected card gates cloning of the program logic itself.
12. Frequently Asked Questions
Can I enable know-how protection without a memory card?
No. The card is the only legal storage that LOGO!Soft Comfort writes a protected program to. Without a card, the on-board EEPROM accepts only unprotected programs, and those are uploadable. The card slot is part of the trust boundary.
What happens to the LOGO! if the protected card is removed?
The on-board EEPROM copy continues to run for the current power-on. After a power cycle, the LOGO! reports "No Program" and the unit is inoperable until the original card is re-inserted. This is the intended theft-deterrent behavior.
Can a know-how protected program be copied to a second LOGO!?
The card can be physically moved to a second LOGO! and the program will run on it. Both LOGO! modules will refuse to upload the program back to LOGO!Soft Comfort. The PIN is required to re-edit or to read the program into a new card, so an attacker cannot redistribute the program in editable form from a single deployed card.
Is know-how protection available on LOGO! 8.0 or only newer versions?
It is available on all LOGO! 8 (6ED1052-xBA8) base modules from 8.0 onward, but the LOGO!Soft Comfort editor must match the LOGO! generation. Use LOGO!Soft Comfort V8.x for LOGO! 8 hardware. The earlier LOGO! 0BA6 generation does not support know-how protection; for those units, password protection is the only option.
What is the cost of one protected deployment per machine?
One LOGO! Memory Card (6ED1056-1BA00-0AA0) is required per machine. The list price in 2024 is approximately €25–30. For a 50-unit fleet, budget €1,250–1,500 in cards alone, plus the engineering time to write 50 protected cards. This is the structural cost of the strongest anti-theft scheme available on LOGO! 8.
Can I set a user password in addition to know-how protection?
Yes, and Siemens recommends it. Enable know-how protection on the card AND set a user password on the LOGO! base module. The card-level protection blocks program extraction; the LOGO!-level password blocks operator parameter edits via the display. Both can be set independently through LOGO!Soft Comfort.