Locking and unlocking of communication interface of electronic device of motor vehicle
By generating keys based on hardware and software component identifiers and combining them with two-factor authentication, the communication interfaces of motor vehicle electronic devices are automatically locked or unlocked, solving the problem of secure access to communication interfaces after production and achieving a highly secure and convenient unlocking mechanism.
Patent Information
- Application Number
- CN202480022765.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-04-06
- Filing Date
- 2024-04-02
- Publication Date
- 2025-11-07
AI Technical Summary
In the prior art, it is difficult to achieve secure access control for the communication interfaces of electronic devices in motor vehicles after production. In particular, the troubleshooting interface requires password protection during normal operation, but convenient access is required during troubleshooting.
By generating keys using identifiers of hardware and software components based on electronic devices, combined with two-factor authentication, communication interfaces are automatically locked or unlocked to ensure that only authorized users can access them.
It achieves a high level of security for the communication interface of motor vehicle electronic devices, preventing unauthorized access, and reliably reconstructing the key for unlocking when needed.
Smart Images

Figure CN120917445A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The invention relates to a method for locking a communication interface of an electronic device of a motor vehicle and to a corresponding method for unlocking a communication interface of an electronic device of a motor vehicle. The invention also relates to a data processing device and to a computer program product. BACKGROUND
[0002] Electronic devices, for example control units or sensors, for motor vehicles can have communication interfaces for different purposes. In appropriate cases, for reasons of safety or to avoid misuse, such communication interfaces can need to be disabled immediately after production of the electronic device for normal operation. For example, this is the case with troubleshooting interfaces, also called debugging interfaces, for example JTAG interfaces. Such communication interfaces are used during production, for example for software installation of the electronic device and / or for software testing or troubleshooting of the electronic device. They are usually not needed during normal operation and can therefore be locked, in particular by password protection.
[0003] However, it can also be necessary to access the electronic device via the communication interface after production, for example for troubleshooting or for changing software stored on the electronic device or for storing or reading other data. In order to obtain access, the user can therefore need to enter the correct password.
[0004] Document US 2017 / 0090909 A1 describes a method for securely writing patch code to a memory of a SoC. A JTAG interface can be used to check the functionality of the SoC. The JTAG interface can be unlocked by entering an interface password by the SoC manufacturer. In the password-locked state, values stored in components of the SoC and / or any other functionality of the SoC cannot be modified via the JTAG interface. SUMMARY
[0005] It is an object of the invention to provide a secure access protection for a communication interface of an electronic device of a motor vehicle.
[0006] This object is achieved by the respective subject matter of the independent claims. Advantageous improvements and preferred embodiments are the subject matter of the dependent claims.
[0007] The invention is based on the idea of using a key, also referred to simply as a password, to lock the communication interface, which is derived from an identifier assigned to the respective electronic device on the one hand, but on the other hand from at least one identifier assigned to a hardware component or a software component of the computing unit, which is from the production line in which the electronic device is produced. The part-specific identifier mentioned first and the production line-specific identifier mentioned last enable the key to be reconstructed retroactively. A two-factor authentication is also implemented in order to increase security.
[0008] According to an aspect of the application, a method for locking a communication interface of an electronic device of a motor vehicle is specified, for example a computer-implemented method. In this case, a first identifier is determined, which characterizes a hardware component of a computing unit of a production line that produced the electronic device, or a software component of the computing unit. The first identifier is determined, inter alia, by means of the computing unit. A second identifier is obtained, in particular by means of the computing unit, which characterizes the electronic device, in particular uniquely. A first input value of a predetermined key derivation function is generated by means of the computing unit on the basis of the first identifier, and a second input value of the key derivation function is generated on the basis of the second identifier. A key, in particular an encryption key, is generated by means of the computing unit using the key derivation function on the basis of the first input value and the second input value. The communication interface is locked using the key, preferably automatically, in particular by means of the computing unit.
[0009] The first identifier makes it possible to clearly determine the individual hardware or software component that is characterized on the basis of knowledge of the first identifier. This can be, for example, a serial number or the like. The same applies analogously to the second identifier, such that if the second identifier is known, the individual electronic device that it characterizes can be uniquely determined. This can also be, for example, a serial number or the like.
[0010] According to an embodiment, the first input value can be identical to the first identifier, or the first input value is derived from the first identifier according to a predetermined rule. In various embodiments, in addition to the first identifier, one or more further first identifiers of a software or hardware component of the computing unit or one or more further hardware or software components can be determined, and the first input value is derived or calculated on the basis of the first identifier and the further identifiers.
[0011] The same applies analogously to the second identifier or the second input value. Thus, the second input value can be identical to the second identifier, or is optionally derived from the second identifier and one or more further second identifiers that characterize the electronic device.
[0012] If, in addition to the first identifier, further first identifiers are used for further hardware or software components, the respective further hardware or software components can be uniquely determined from the further first identifiers. In the use of one or more further second identifiers, these can also enable the unique determination of the electronic device according to an embodiment. However, this is not always the case, such that the further second identifiers can also be ambiguous in comparison with the second identifier. For example, the further second identifiers can comprise a model identifier, a production cycle, a batch number, a production location or the like that is related to the electronic device.
[0013] The key derivation function is for example designed to derive a respective key uniquely from two separate input values, in the present case the first input value and the second input value, so that it is in this case a function of two variables. The same input values thus always result in the same key. According to an embodiment, the two input values can also be linked or combined by a calculation to generate a common input value, and the key derivation function generates the key from the common input value, so that it is in this case a function of one variable.
[0014] By means of the key locking the communication interface, the communication interface is thus placed in a locked or encrypted state, in which a user from outside the electronic device cannot access the electronic device via the communication interface. The communication interface can be unlocked, i.e. brought into an unlocked or decrypted state, by inputting a key for locking the communication interface via the communication interface or a further interface of the electronic device.
[0015] The communication interface is in particular a communication interface for wired communication between an external computing unit and a processor or a memory element or another component of the electronic device. The communication interface in particular comprises a hardware interface and / or a software interface.
[0016] Thus, by using the first identifier and the second identifier as two mutually independent factors for generating the key, the method according to the application achieves a high level of security against unauthorized or undesired access to the electronic device via the communication interface. By using the second identifier, a unique association of the generated key with the individual electronic device is achieved. The content of the first identifier is irrelevant for this and, most importantly, cannot be easily identified by a party who potentially has access to the communication interface without authorization. However, in addition, if the method according to the application is known, the key can be reliably reconstructed when the communication interface needs to be unlocked.
[0017] Furthermore, in the method according to the application, a first identifier is used, which is based on a hardware component or a software component of the computing unit for the generation of the key, which is also used to derive the input value of the key derivation function and to generate the key based thereon. In this way, the security can be further increased.
[0018] The computing unit is part of a production line for producing the electronic device. This means in particular that, before the method according to the application is carried out, steps for manufacturing the electronic device have already been carried out by means of the computing unit, for example for configuring the electronic device with software and / or for testing the software.
[0019] The computing unit can be understood in particular to mean a data processing device comprising a processing circuit. Thus, the computing unit can process data, in particular for carrying out calculation operations. Optionally, these also include operations for carrying out indexed access to data structures, for example lookup tables (LUTs).
[0020] The computing unit can in particular comprise one or more computers, one or more microcontrollers and / or one or more integrated circuits, such as one or more application-specific integrated circuits (ASICs), one or more field-programmable gate arrays (FPGAs) and / or one or more system-on-chips (SoCs). The computing unit can also comprise one or more processors, such as one or more microprocessors, one or more central processing units (CPUs), one or more graphics processing units (GPUs) and / or one or more signal processors, in particular one or more digital signal processors (DSPs). The computing unit can also comprise a physical or virtual computer group or other type of mentioned unit.
[0021] In various exemplary embodiments, the computing unit comprises one or more hardware and / or software interfaces and / or one or more storage units.
[0022] The storage unit can be configured as a volatile data storage, such as a dynamic random-access memory (DRAM) or a static random-access memory (SRAM), or a non-volatile data storage, such as a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory or a flash EEPROM, a ferroelectric random-access memory (FRAM), a magnetoresistive random-access memory (MRAM) or a phase change random-access memory (PCRAM).
[0023] According to at least one embodiment of the method for locking a communication interface, the electronic device is programmed and / or tested at least partially by means of the computing unit before the first identifier is determined, and / or the electronic device is software installed by means of the computing unit before the first identifier is determined and / or the electronic device is fault-diagnosed by means of the computing unit.
[0024] The mentioned steps can be seen as part of the production of the electronic device. These can be carried out at least partially via the communication interface. In this case, the computing unit is thus connected to the electronic device via the communication interface and can then, for example, remain connected to the electronic device in order to automatically lock the communication interface using the key.
[0025] According to at least one embodiment, the communication interface is a troubleshooting interface of the electronic device.
[0026] In the case of such a troubleshooting interface, which is also referred to as a debug interface, the use of the application is particularly advantageous, since these can be used in the case of warranty or in the case of an error occurring on site in order to be able to access the electronic device again after its actual production.
[0027] For example, the troubleshooting interface is standardized in accordance with the industry standard IEEE 1149.1, commonly referred to as JTAG (Joint Test Action Group).
[0028] According to at least one embodiment, the second identifier is determined on the basis of a serial number of the electronic device.
[0029] For example, the second identifier can be identical to the serial number of the electronic device, or the second identifier can be determined on the basis of the serial number and additional component-specific information.
[0030] On the one hand, the serial number of the electronic device is suitable for uniquely determining the electronic device, on the other hand, the serial number is usually electronic or analog, for example in the form of a string or an optically or electronically readable code, and is present on the electronic device even after actual production has been completed.
[0031] According to at least one embodiment, the first identifier is determined on the basis of a serial number of a hardware component of the computing unit and / or on the basis of a serial number of a software component of the computing unit.
[0032] The hardware component can be, for example, a main circuit board (also referred to as motherboard), the computing unit or a data memory of the computing unit, for example an SSD drive or an HDD drive. The software component can be, for example, an operating system or a firmware, for example a BIOS firmware, of the computing unit.
[0033] For example, the serial number of the hardware component or the software component can be read and determined automatically by the computing unit itself, so that the security of the method can be further improved.
[0034] According to at least one embodiment, a further first identifier is determined, in particular by means of the computing unit, which characterizes a further hardware component of the computing unit or a further software component of the computing unit. The first input value is generated on the basis of the first identifier and the further first identifier.
[0035] For example, in further embodiments, more than just one further first identifier can be determined and processed accordingly in a similar manner. The first identifier and the further first identifier can be concatenated with one another or linked to one another via a logical operation, such as an XOR operation or any other rule, in order to generate the first input value. In this way, the security of the key is further improved.
[0036] According to at least one embodiment, the key is generated with a bit length of at least 32 bits or at least 64 bits. A high degree of security can thus be achieved.
[0037] According to at least one embodiment, the electronic device is a sensor for a motor vehicle or an electronic control unit for a motor vehicle.
[0038] The electronic control unit ECU can also be configured as a zone control unit ZCU or a domain control unit DCU.
[0039] The sensor can be, for example, an environmental sensor, such as a camera, a lidar system, a radar system, or an ultrasonic sensor system, or other sensors for a motor vehicle, such as a steering angle sensor, an acceleration sensor, an inertial measurement unit, IMU, etc.
[0040] Electronic control units and sensors for motor vehicles are partly highly safety-relevant components, which must be reliably protected against unwanted or unauthorized access and must still be able to be accessed authorizedly after production. The present invention has a particularly advantageous effect in this respect.
[0041] According to at least one embodiment of the method, at least one history data set is provided on a storage device. Each history data set of the at least one history data set contains a respective history identification information for a hardware component or a software component of the computing unit and a production cycle associated with the history identification information. In particular, a most recent history identification information of a most recent history data set of the at least one history data set is read from the storage device by means of the computing unit. The most recent history identification information is associated with a most recent production cycle. A most recent history first input value is determined based on the most recent history identification information.
[0042] A hash value is generated based on the first input value, in particular by means of the computing unit, using a predefined hash function. Based on the most recent history first input value, in particular by means of the computing unit, another hash value is generated using the hash function. It is checked, in particular by means of the computing unit, whether the hash value matches the other hash value. If the hash value does not match the other hash value, another history data set is stored on the storage device, in particular by means of the computing unit. The further history data set contains the first input value and a production time period associated with the first input value, or the further history data set contains the first identifier and a production time period associated with the first identifier.
[0043] In particular, each history data set also contains a corresponding history first input value or a respective history first identifier for a key derivation function as the respective history identification information. In the former case, the most recent history first input value is determined by reading it out of the corresponding most recent history data set. In the latter case, the most recent history first identifier is read out of the respective most recent history data set, and based thereon, the most recent history first input value is determined, in particular as explained above with regard to the generation of the first input value.
[0044] The historical identification information thus directly or indirectly characterizes a historical hardware component or a historical software component of the computing unit, which existed in the computing unit within the respective associated production cycle. The most recent historical production cycle can be understood in such a way that no more recent production cycle is present in the historical data of the at least one historical data set. The most recent historical data set is then the historical data set which contains the most recent production cycle, and the most recent historical identification information is the historical identification information contained in the most recent historical data set.
[0045] The storage device is in particular a storage device which is arranged outside the computing unit, which in particular represents a secure, access-restricted environment.
[0046] If the hash value matches the additional hash value, this means that the first input value matches the most recent historical first input value, or the first identifier matches the most recent historical first identifier. This means that the hardware component or the software component of the computing unit characterized by the first identifier or by the first input value corresponds to the software component or the hardware component of the computing unit characterized by the most recent historical first input value or the most recent historical identifier.
[0047] Correspondingly, it can be ensured that when reconstructing the password for unlocking the communication interface of the electronic device using the at least one historical data set on the storage device, all necessary information is stored on the storage device. If this is not the case, i.e. if the hash value does not match the further hash value, the method of locking the communication interface or generating the key can be interrupted until a further historical data set is stored on the storage device and the respective test step can be carried out again. Then, when this test is carried out again, the hash value matches the further hash value.
[0048] In particular, the hash value is generated independently of the most recent historical first input value or only on the basis of the first input value. Similarly, the additional hash value is generated independently of the first input value or only on the basis of the most recent historical input value.
[0049] The hash function is in particular a cryptographic hash function, for example a SHA-2 function, in particular a SHA-256 function.
[0050] For application cases or application scenarios which can lead to the method and are not explicitly described here, it can be specified according to the method which error messages are to be output and / or which request for user feedback is to be input and / or which default settings are to be set and / or which predetermined initial state is to be set.
[0051] According to a further aspect of the application, a method for unlocking a communication interface of an electronic device of a motor vehicle is specified, wherein the electronic device has been locked by means of the method for locking a communication interface according to the application. According to the method for unlocking the communication interface, at least one historical data set is provided on a storage device, in particular an external storage device, wherein each historical data set of the at least one historical data set contains a corresponding historical identification information and a production cycle associated with the historical identification information. A device identifier characterizing the electronic device having the communication interface to be unlocked is determined, and on the basis of the device identifier, in particular by means of a further computing unit, a production cycle of the electronic device having the communication interface to be unlocked is determined.
[0052] On the basis of the production cycle thus determined, one of the historical data sets, in particular the historical data set corresponding to the production cycle determined on the basis of the device identifier, in particular by means of the further computing unit, is selected. On the basis of the historical identification information of the selected historical data set, a historical first input value for a key derivation function is generated, in particular by means of the further computing unit. On the basis of the device identifier, a current second input value for the key derivation function is generated, in particular by means of the further computing unit. Using the key derivation function, a key is reconstructed on the basis of the historical first input value and the current second input value, in particular by means of the further computing unit. Using the reconstructed key, the communication interface is unlocked, in particular by means of the further computing unit.
[0053] With regard to the historical identification information, the historical first input value and its relationship to the historical identifier, reference is made to the above-described method for locking the communication interface.
[0054] In this way, the possibility of unlocking the communication interface is specified, wherein it is not necessary to store the key itself, but rather it can be reliably reconstructed for all production cycles and accordingly all associated electronic devices.
[0055] For application cases or application scenarios which can lead to the method and which are not explicitly described here, it can be specified according to the method which error messages are to be output and / or which request for user feedback is to be input and / or which default settings are to be set and / or which predetermined initial state is to be set.
[0056] According to a further aspect of the application, a data processing device is specified, which has a computing unit which is configured to carry out the method for locking a communication interface of an electronic device of a motor vehicle according to the application.
[0057] According to a further aspect of the application, a further data processing device is specified, which has a further computing unit, wherein the further computing unit is configured to carry out the method for unlocking a communication interface of an electronic device of a motor vehicle according to the application.
[0058] According to another aspect of the present application, a computer program having commands is specified, wherein the commands, when executed by a data processing device, in particular a data processing device according to the present application, cause the data processing device to perform the method according to the present application for locking a communication interface of an electronic device of a motor vehicle.
[0059] For example, the commands can exist as program code. The program code can be provided, for example, as binary code or as assembler and / or as source code in a programming language, for example C, and / or as a program script, for example Python.
[0060] According to another aspect of the present application, a further computer program having further commands is specified, wherein the further commands, when executed by a further data processing device, in particular a further data processing device according to the present application, cause the further data processing device to perform the method according to the present application for unlocking a communication interface of an electronic device of a motor vehicle.
[0061] For example, the further commands can exist as program code. The program code can be provided, for example, as binary code or as assembler and / or as source code in a programming language, for example C, and / or as a program script, for example Python.
[0062] According to a further aspect of the present application, a computer-readable storage medium is specified, which stores a computer program according to the present application or a further computer program according to the present application.
[0063] The computer program, the further computer program and the computer-readable storage medium can each be regarded as a computer program product having commands or further commands.
[0064] Further features of the present application result from the claims, the figures and the description of the figures. The features and combinations of features mentioned above in the description and below in the description of the figures and / or shown in the figures can be included in the present application not only in the combinations specified in each case, but also in other combinations. In particular, embodiments which do not have all the features of the original claim and combinations of features can also be included in the present application. Furthermore, embodiments and combinations of features which go beyond or differ from the combinations of features set out in the reverse references of the claims can be included in the present application. BRIEF DESCRIPTION OF DRAWINGS
[0065] The present application is explained below in more detail on the basis of specific exemplary embodiments and associated schematic drawings. In the drawings, identical or identically functioning elements can be provided with the same reference signs. The description of identical or identically functioning elements can not necessarily be repeated with respect to different figures.
[0066] In the drawings, schematically shown is:
[0067] Figure 1 A flow chart showing an exemplary embodiment of a method for locking a communication interface of an electronic device of a motor vehicle according to the present application is shown;
[0068] Figure 2 A flow chart showing another exemplary embodiment of a method for locking a communication interface of an electronic device of a motor vehicle according to the present application is shown; and
[0069] Figure 3 A flow chart showing another exemplary embodiment of a method for unlocking a communication interface of an electronic device of a motor vehicle according to the present application is shown. DETAILED DESCRIPTION
[0070] Figure 1 A schematic flow chart showing an exemplary embodiment of a method for locking a communication interface of an electronic device 1, for example a control unit or a sensor, of a motor vehicle according to the present application is shown.
[0071] The electronic device 1 is produced in a production line having a computing unit 2, for example a programming station. By means of the computing unit 2, for example a software installation and / or troubleshooting of the electronic device 1 is performed and / or the electronic device is tested by means of the computing unit 2.
[0072] The electronic device 1 has a communication interface, in particular a troubleshooting interface, for example a JTAG interface, which can be locked or unlocked by means of an encryption key.
[0073] In a step 100, a first identifier 3 is determined, in particular by means of the computing unit 2, which characterizes a hardware component, for example an SSD memory or a main circuit board, which characterizes the computing unit 2 or a software component, for example an operating system or a firmware, which characterizes the computing unit 2. For example, the first identifier 3 can be a serial number of the hardware component or the software component. Optionally, at least one further first identifier can be determined, which characterizes at least one further hardware component and / or at least one further software component of the computing unit 2.
[0074] In a step 120, the computing unit 2 obtains a second identifier 4, which characterizes the electronic device 1, for example a serial number of the electronic device 1. The computing unit 2 can determine the second identifier 4 automatically, for example when the second identifier 4 is electronically stored on the electronic device 1, or a user can provide the second identifier to the computing unit 2 by means of an input device, for example a keyboard or an optical reader or an RFID reader. Optionally, the optical reader or the RFID reader can also be positioned such that the second identifier 4 can thus be read automatically.
[0075] In step 140, the computing unit 2 generates a first input value for the predetermined key derivation function on the basis of the first identifier 3. If the at least one further first identifier has been determined, the computing unit 2 generates the first input value on the basis of the first identifier 3 and on the basis of the at least one further first identifier. For example, the computing unit 2 can concatenate or link the first identifier 3 with the at least one further first identifier by means of a logical operation, for example an XOR operation, in order to generate the first input value, or convert it into the first input value by means of a further operation. The computing unit 2 generates a second input value for the key derivation function on the basis of the second identifier 4
[0076] In step 160, the computing unit 2 applies the key derivation function to the first input value and the second input value, thereby generating a key. In step 180, the communication interface is locked using the key, in particular automatically by means of the computing unit 2. In particular, the computing unit 2 is connected to the communication interface or a further communication interface of the electronic device 1 for this purpose.
[0077] Figure 2 A schematic flow chart of another exemplary embodiment of the method according to the application for locking a communication interface is shown based on an embodiment according to Figure 1
[0078] First, step 100 is also carried out here. At least one historical data set is stored on a storage device 5, which is in particular arranged externally to the computing unit 2. For the sake of simplicity, it is assumed in the following that the storage device stores several such historical data sets; in the case of a single historical data set, the procedure is analogous. Each of the historical data sets contains a respective historical identification information for a hardware component or a software component of the computing unit 2 and a production cycle associated with the historical identification information. This can relate to different hardware components or software components for different production cycles, however, the hardware components or software components always have the same function in the computing unit 2. It is therefore still referred to as “the” hardware component or “the” software component.
[0079] In particular, the production cycles are unique, such that they can be uniquely ordered in chronological order. One of the production cycles is therefore uniquely the most recent production cycle. The associated historical data set is referred to as the most recent historical data set, and its historical identification information is referred to as the most recent historical identification information 6. In step 200, the computing unit 2 reads the most recent historical identification information from the storage device 5.
[0080] In step 220, the computing unit 2 determines a recent history first input value for the key derivation function based on the recent history identification information 6. For example, the history data set's history identification information can be identical to the first history input value. Alternatively, the history identification information can each contain a history first identifier and optionally at least one further history first identifier, similar to described above with respect to the first identifier and the at least one further first identifier. Then, the recent history first input value is similar to described above with respect to the first input value, the history first identifier and optionally the at least one further history first identifier from the recent history identification information 6.
[0081] In step 240, the computing unit 2 generates a hash value 8 based on the first input value using a predetermined hash function, and in step 260, the computing unit 2 generates another hash value 7 based on the recent history first input value using the hash function.
[0082] In step 260, the computing unit 2 checks whether the hash value 8 matches the other hash value 7. If this is the case, steps 120 to 180 are performed as described above. Otherwise, in step 280, the computing unit 2 stores another history data set on the storage device 5, which contains the first input value and the production cycle associated with the first input value, or which contains the first identifier and the production cycle associated with the first identifier. Then, this other history data set is the recent history data set.
[0083] This allows to identify a change of a hardware component or a software component that would lead to a different first input value. Then, the lock of the communication interface can be cancelled first, and for example an error message or a warning message can be issued. Then, steps 100 and 200 to 260 can be repeated. Since the hash value 8 matches the additional hash value 7, steps 120 to 180 can be performed as described above.
[0084] Figure 3 A schematic flow chart illustrating an exemplary embodiment of a method for unlocking a communication interface of an electronic device 1 according to the present application is shown, which electronic device 1 has been locked by means of a method according to the present application as described in Figure 1 and Figure 2 .
[0085] In step 300, a further computing unit 9, different from the computing unit 2, obtains a device identifier 10 of the electronic device 1, which corresponds to the second identifier. In step 320, the further computing unit 9 determines the production cycle of the electronic device 1 based on the device identifier 10. In step 340, the further computing unit 9 selects one of the historical data sets that contains the production cycle of the electronic device 1. Based on the historical identification information of the selected historical data set, the further computing unit 9 generates a historical first input value for the key derivation function and, based on the device identifier 10, a current second input value for the key derivation function, similar to what has been described above with respect to the first input value and the second input value.
[0086] In step 360, the further computing unit 9 reconstructs the key 11 using the key derivation function based on the historical first input value and the current second input value. In step 380, the communication interface is unlocked using the reconstructed key 11.
[0087] As described, in particular with reference to the figures, the application enables secure access protection of a communication interface of an electronic device of a motor vehicle. In particular, the application generates a component-specific key that does not need to be stored and that can be reconstructed if necessary.
Claims
1. A method for locking a communication interface of an electronic device (1) of a motor vehicle, wherein - a first identifier (3) is determined, which characterizes a hardware component of a computing unit (2) of a production line, in which the electronic device (1) is produced, or which characterizes a software component of the computing unit (2); - a second identifier (4) is obtained, which characterizes the electronic device (1); - a first input value for a predetermined key derivation function is generated by the computing unit (2) based on the first identifier (3) and a second input value for the key derivation function is generated by the computing unit (2) based on the second identifier (4); - a key is generated by the computing unit (2) using the key derivation function based on the first input value and the second input value; and - the communication interface is locked using the key. The determination of the first identifier (3) and / or the software installation of the electronic device and / or the troubleshooting of the electronic device (1) by means of the computing unit (2) is at least partially preceded by programming and / or testing of the electronic device (1) by means of the computing unit (2).
2. The method of claim 1, wherein, The communication interface is a troubleshooting interface of the electronic device (1).
3. The method according to any of the preceding claims, wherein, The second identifier (4) is determined based on a serial number of the electronic device (1).
4. The method according to any one of the preceding claims, wherein, The first identifier is determined based on a serial number of a hardware component of the computing unit (2) and / or based on a serial number of a software component of the computing unit (2).
5. The method according to any of the preceding claims, wherein, The software component is an operating system of the computing unit (2) or a firmware of the computing unit (2), and / or wherein the hardware component is a main circuit board of the computing unit (2) or a data memory of the computing unit (2).
6. The method of any of the preceding claims, wherein, 7. The method according to any one of the preceding claims, wherein - a further first identifier is determined, which characterizes a further hardware component of the computing unit (2) or a further software component of the computing unit (2); and - the first input value is generated based on the first identifier and the further first identifier. The key is generated with a bit length of at least 32 bits or at least 64 bits.
8. The method of any of the preceding claims, wherein, The electronic device is a sensor for the motor vehicle or an electronic control unit for the motor vehicle.
9. The method according to any of the preceding claims, wherein, 10. The method according to any one of the preceding claims, wherein - at least one historical data set is provided on a storage device (5), wherein each historical data set of the at least one historical data set contains corresponding historical identification information for the hardware component or the software component of the computing unit (2) and a production period associated with the historical identification information; - a most recent historical identification information (6) of a most recent historical data set of the at least one historical data set is read from the storage device (5), wherein the most recent historical identification information (6) is associated with a most recent production period; - a most recent historical first input value is determined based on the most recent historical identification information; - a hash value (8) is generated based on the first input value using a predetermined hash function; - a further hash value (7) is generated based on the most recent historical first input value (6) using the hash function; - if the hash value (7) does not match another hash value (8), storing another historical data set on the storage device (5), the other historical data set containing the first input value and the production cycle associated with the first input value, or containing the first identifier and the production cycle associated with the first identifier.
11. The method of claim 10, wherein, Each of the at least one historical data set contains: - a respective historical first input value of the key derivation function; or - a respective historical first identifier, as respective historical identification information.
12. A method for unlocking a communication interface of an electronic device (1) of a motor vehicle, the communication interface being locked by the method according to any one of claims 1 to 9, wherein - at least one historical data set is provided on a storage means (5), wherein each of the at least one historical data set contains corresponding historical identification information and a production cycle associated with the historical identification information; - a device identifier (10) characterizing the electronic device (1) is determined; - a production cycle of the electronic device (1) is determined based on the device identifier (10); - one of the historical data sets is selected based on the production cycle of the electronic device (1); - a historical first input value for a key derivation function is generated based on the historical identification information of the selected historical data set; - a current second input value for the key derivation function is generated based on the device identifier (10); - a key (1) is reconstructed based on the historical first input value and the current second input value using the key derivation function; and - the communication interface is unlocked using the reconstructed key (11).
13. A data processing device having a computing unit (2), the computing unit (2) being configured to perform the method according to any one of claims 1 to 11.
14. A data processing device having a further computing unit (9), the further computing unit (9) being configured to perform the method according to claim 12.
15. A computer program product having commands which, when executed by a data processing device, cause the data processing device to perform the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Secure patch updates for programmable memories
US20170090909A1