System and method for securing diagnostic requests for a motor vehicle computer
By using a combination solution of locking key and storage key in a motor vehicle computer, the problem of insufficient security of diagnosis requests by motor vehicle computers in the prior art is solved, and multi-level security control and security measures to adapt to different life cycle stages are realized.
Patent Information
- Application Number
- CN202080054749.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-07-30
- Filing Date
- 2020-07-07
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2040-07-07
AI Technical Summary
The prior art is difficult to achieve sufficient security in diagnostic requests for motor vehicle computers, especially in the case of different safety levels and diagnostic tools.
By using the first lock key and the second lock key in the on-board storage memory of the motor vehicle computer, and using the corresponding storage key in the storage memory of the diagnostic tool and the remote server, secure control of the diagnostic request is achieved. Specific steps include comparing the keys to determine access to the diagnostic tool and implementing different key verification policies at different life cycle stages of the vehicle.
Multi-level safety control of computer diagnostic requests for motor vehicles is realized, meeting the needs of different safety levels, and providing appropriate safety measures in the environment changes of the vehicle from manufacturing to end users.
Smart Images

Figure CN114175706B_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to a system and method for securing diagnostic requests for a motor vehicle computer. Background Art
[0002] Communication between a motor vehicle computer and a remote diagnostic tool uses a communication protocol (Unified Diagnostic Services (UDS)), which is specified in the standard ISO14229-1 and developed into standards ISO14230-3 and ISO15765-3. This is an international standard, not a manufacturer's proprietary standard. This communication protocol is used in almost all new computers manufactured by original equipment suppliers of automobile manufacturers. The vehicle computer controls various functions in the vehicle, including in particular electronic fuel injection, engine control, transmission, anti-lock braking system, door locking, braking, etc. Therefore, access to the computer should be secured.
[0003] The diagnostic tool can communicate with any control unit installed in a vehicle in which the Unified Diagnostic Services (UDS) is activated. Modern vehicles have a diagnostic interface for out-of-vehicle diagnosis, which can connect a computer or a diagnostic tool to the vehicle's bus system, on which all the vehicle's computers are connected. Therefore, messages defined in the standard of the Unified Diagnostic Services (UDS) can be sent to the controller, and the controller should provide the predefined Unified Diagnostic Services (UDS). Thus, it is possible to consult the fault memory of different control units or update these different control units by means of a new operating system software (firmware).
[0004] Each automobile manufacturer is responsible for implementing an access mechanism secured according to the standard of the Unified Diagnostic Services (UDS). Summary of the Invention
[0005] An object of the present invention is to provide a method for securing diagnostic requests for a motor vehicle computer, which method can meet different required security levels and diagnostic tool usage scenarios.
[0006] To this end, a first aspect of the present invention relates to a system for securing diagnostic requests for a motor vehicle computer; the motor vehicle computer includes a diagnostic connection element and an on-vehicle storage memory, the diagnostic connection element being arranged to receive a connection with a diagnostic tool; the diagnostic tool includes a first storage memory on which a computer program is installed, the computer program being capable of accessing the computer to modify at least one operating parameter when the diagnostic tool is connected to the diagnostic connector; a communication device capable of connecting to a remote server; a second storage memory installed on the remote server; characterized in that the on-vehicle storage memory of the motor vehicle computer includes a first locking key and a second locking key, the first storage memory of the diagnostic tool includes a first storage key, the first storage key being arranged to unlock the first locking key, and the second storage memory of the remote server includes a second storage key, the second storage key being arranged to unlock the second locking key, so that the computer can control the access by the diagnostic tool during a diagnostic request.
[0007] According to an implementation variant, the first locking key is the same for all computers of a determined set of computers.
[0008] According to an implementation variant, the second locking key is unique for each computer.
[0009] A second aspect of the present invention relates to a method for securing diagnostic requests for the system according to the first aspect, characterized in that the method includes: a comparison step of comparing, by the motor vehicle computer, the first locking key stored in the storage memory of the computer with the first storage key stored in the storage memory of the diagnostic tool; if the first locking key and the first storage key are the same, a sending step of sending, by the diagnostic tool, a request for modifying or accessing at least one operating parameter of the computer.
[0010] According to an implementation variant, the method includes: a comparison step of comparing, by the motor vehicle computer, the second locking key stored in the storage memory of the computer with the second storage key stored in the storage memory of the remote server; if the second locking key and the second storage key are the same, a sending step of sending, by the diagnostic tool, a request for modifying or accessing at least one operating parameter of the computer.
[0011] According to an implementation variant, the method includes a prohibiting step for prohibiting a comparison step by the motor vehicle computer of the first locking key stored in the computer's storage memory with the first stored key stored in the storage memory of the diagnostic tool; the prohibiting step is triggered either during the transmission of a determined diagnostic request by the diagnostic tool or when the motor vehicle has traveled a determined distance.
[0012] A third aspect of the present invention relates to an information system for securing a diagnostic request for a motor vehicle computer, characterized in that the information system includes components for implementing the steps of the method according to the second aspect.
[0013] A fourth aspect of the present invention relates to a computer program, the computer program including instructions for implementing the method for securing a diagnostic request for a motor vehicle computer according to the second aspect when the computer program is executed on one or more processors. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Other features and advantages of the present invention will become clearer by reading the detailed description of the embodiments of the present invention given as non-limiting examples and the drawings, in which:
[0015] - Figure 1 A schematic diagram of a system for securing a diagnostic request for a motor vehicle computer according to the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] As is known, a motor vehicle includes a plurality of computers 1. These computers can control the operation of the vehicle, especially including engine control, control of cabin devices (such as air conditioning, lighting), vehicle driving (such as braking systems, active and passive safety systems), etc. All these computers are connected to a communication network or a data bus.
[0017] Each computer 1 includes an on-vehicle memory 10, which can especially store software that enables the computer 1 to operate, data received by the computer, and data related to the vehicle or the computer 1. For example, when installed on a vehicle, the on-vehicle memory 10 of the computer 1 may include the serial number 13 of the computer and / or the identification number 14 of the vehicle.
[0018] For verifying the proper operation of said computer or for determining parameters or updates for said computer, the communication network includes a diagnostic connector arranged to receive a connection with a diagnostic tool 2 so that the diagnostic tool 2 can transmit data to and receive data from the computer 1. The diagnostic tool is, for example, a computer including a storage memory 20 on which a computer program is stored, and this computer program can access the computer 1 via the diagnostic connector. The diagnostic tool 2 is known to include a human-machine interface (not shown).
[0019] The diagnostic tool 2 may also include a communication device capable of connecting to a remote server 3. The communication device is known. This communication device can be a WIFI or a wired connection module. The remote server also has a second storage memory 30. The remote server 3 is a subordinate server, or at least its access path is controlled by the vehicle manufacturer. This remote server particularly includes information related to the identification of such vehicles of the manufacturer identified (in particular via the vehicle identification number).
[0020] As mentioned above, in terms of one or more computers 1 controlling a plurality of sensitive elements of the vehicle, the data exchange between the one or more computers 1 and the diagnostic tool 2 should be secured by using the standard of Unified Diagnostic Services (UDS in English). In fact, the access to the said computer can be implemented only via an authorized or verified diagnostic tool.
[0021] In addition, during the assembly of the vehicle, the parameters of the one or more computers should be determined, for example. The determination of the parameters is also performed by means of the diagnostic tool 2. For the same reason, during the manufacture of the vehicle, the access to the computer 1 can be implemented only via an authorized or verified diagnostic tool. However, the access to the said computer during manufacture is less disclosed because the vehicle is at the manufacturer's manufacturing site.
[0022] According to the present invention and taking into account the different life cycles of the vehicle, the system for securing diagnostic requests for a motor vehicle computer according to the present invention includes a first locking key 11 and a second locking key 12 stored in the in-vehicle memory 10 of the computer 1. The corresponding first storage key 21 is stored in the first storage memory 20 of the diagnostic tool 2. The corresponding second storage key 32 is stored in the second storage memory 30 of the remote server 3.
[0023] The first locking key 11 and the first storage key 21 are so-called public and are identical for a determined set of computers. For example, the public key 11 is identical for all computers of the same type (e.g., engine control) and the same version (e.g., for a range of vehicles belonging to a given manufacturing year). It is understood that the first storage memory 20 of the diagnostic tool 2 may include a plurality of different public keys 21, while the computer 1 includes only a single public key 11.
[0024] It is also understood that during the manufacturing phase, after a diagnostic request of the diagnostic tool 2 is sent, the public key 11 present on the computer 1 on the one hand is compared with the public key 21 present on the diagnostic tool on the other hand by the computer 1. If the public key 11 present on the computer 1 corresponds to one of the public keys 21 present on the diagnostic tool, the diagnostic request is allowed.
[0025] It is understood that access to the computer 1 can be implemented via the diagnostic tool 2 without accessing the remote server 3. However, in the context of vehicle assembly operations, the security of the computer 1 is less disclosed because the computer is located inside the automobile manufacturer's factory. At the end of the manufacturing process, the identification number 14 of the vehicle is known. This identification number is stored in the computer 1 via a diagnostic request of the diagnostic tool 2. Similarly, the identification number of the vehicle is related on the one hand to the computer serial number 13 and on the other hand to a so-called unique second locking key 12. Information regarding the correlation between the unique key 12, the vehicle identification number 14, and the computer serial number 13 is stored on the second storage memory of the remote server 3.
[0026] After the manufacturing of the vehicle is completed, the vehicle enters the distribution phase. During this phase, the vehicle has not yet been assigned to the end user. The vehicle may be waiting for delivery or in the process of being delivered. Still, the environment of the vehicle is controlled by the manufacturer, and thus, the security disclosure level of the computer is relatively low. During this distribution phase, if a diagnostic request needs to be sent by the diagnostic tool 2, verification of the consistency of the public key 11 or the unique key 12 will be implemented.
[0027] Verification of the unique key 12 requires the diagnostic tool 2 to access the remote server 3. This verification is performed as follows. The diagnostic tool 2 reads the computer serial number 13 and the vehicle identification number 14 stored on the on-vehicle memory of the computer 1 of the vehicle at a first time. The computer serial number 13 and the identification number 14 of the vehicle are then transmitted by the diagnostic tool 2 to the remote server to obtain the value of the corresponding unique key 32 stored on the second storage memory of the remote server.
[0028] The value of the unique key 32 sent by the remote server 3 to the diagnostic tool is thus compared by the computer 1 with the value of the unique key 12 stored on the on-board memory 10 of the computer 1. If the two values are identical, the diagnostic tool is allowed to send a diagnostic request to the computer 1.
[0029] Once the vehicle has been allocated and delivered to the end user, the environment of the vehicle is no longer under the control of the manufacturer. Thus, it is necessary to increase the security of the connection to the computer 1 of the vehicle. Thus, after the end of manufacturing and before delivery to the end user, the use of the public key 11 stored on the computer is irreversibly invalidated, such that for each diagnostic request transmitted by the diagnostic tool 2 only after verification of the correspondence of the unique key, and thus access to the remote server 3 is required.
[0030] To this end, the computer 1 includes a once-modifiable area 15 of the on-board memory 10. This area 15 of the memory is read by the computer 1. Depending on the value recorded in this area 15, the computer 1 either performs a comparison of one or the other of the public key or the unique key, or only performs a comparison of the unique key. In the initial state, i.e., during the manufacture of the computer 1, the value recorded in area 15 corresponds to the verification of the public key or the unique key.
[0031] At the end of the manufacturing process and before delivering the vehicle to the end user, the value of area 15 is irreversibly modified in the on-board memory 10 of the computer 1. The new value recorded in area 15 thus corresponds to the verification of only the unique key before executing the diagnostic request sent by the diagnostic tool.
[0032] It is understood that the modification of a specific area 15 of the on-board memory 10 of the computer 1 permanently prohibits the use of the public key to allow the execution of diagnostic requests transmitted by the diagnostic tool 2.
[0033] The modification of the specific area 15 of the on-board memory can be implemented in two ways:
[0034] either via a specific diagnostic request, which is sent after the diagnostic tool authenticates, for example, the public key,
[0035] or by a computer program of the computer itself after the computer detects that the vehicle has traveled a determined distance (for example, from about a few kilometers to one thousand kilometers).
Claims
1. A system for securing diagnostic requests for a motor vehicle computer (1), · The motor vehicle computer (1) includes: - A diagnostic connection element arranged to receive a connection with a diagnostic tool (2), - An on-vehicle storage memory (10), · The diagnostic tool (2) includes: - A first storage memory (20) on which a computer program is installed, the computer program being capable of accessing the computer (1) to modify at least one operating parameter when the diagnostic tool (2) is connected to the diagnostic connector, · A communication device capable of connecting to a remote server (3), · A second storage memory (30) installed on the remote server (3), Characterized in that, The on-vehicle storage memory (10) of the motor vehicle computer includes a first locking key (11) and a second locking key (12), the first locking key (11) being the same for all computers of a determined set of computers, and the second locking key (12) being unique for each computer, The first storage memory (20) of the diagnostic tool includes a first storage key (21) arranged to unlock the first locking key (11) during the vehicle manufacturing phase, and the second storage memory (30) of the remote server (3) includes a second storage key (32) arranged to unlock the second locking key (12) after the vehicle manufacturing is completed, So that the computer can control access by the diagnostic tool during a diagnostic request, The system is configured to prohibit, after the vehicle manufacturing is completed and before delivery to the user, a comparison step in which the motor vehicle computer (1) compares the first locking key (11) stored in the storage memory (10) of the computer (1) with the first storage key (21) stored in the storage memory (20) of the diagnostic tool (2), - The prohibition is triggered either during a determined diagnostic request sent by the diagnostic tool or when the motor vehicle has traveled a determined distance.
2. A method for securing a diagnostic request for the system according to claim 1, characterized in that, The method includes: During the vehicle manufacturing phase, - A comparison step in which the motor vehicle computer (1) compares the first locking key (11) stored in the storage memory (10) of the computer (1) with the first storage key (21) stored in the storage memory (20) of the diagnostic tool, - If the first locking key is the same as the first storage key, a sending step in which the diagnostic tool sends a request to modify or access at least one operating parameter of the computer, After the vehicle manufacturing is completed, - A comparison step in which the motor vehicle computer (1) compares the second locking key (12) stored in the storage memory of the computer with the second storage key (32) stored in the storage memory (30) of the remote server (3), - If the second locking key is the same as the second storage key, the step of sending a request for modifying at least one operating parameter of the computer by the diagnostic tool, after the end of the manufacture of the vehicle and before delivery to the user, - A step of prohibiting a comparison step for prohibiting the motor vehicle computer (1) from comparing the first locking key (11) stored in the storage memory (10) of the computer (1) with the first storage key (21) stored in the storage memory (20) of the diagnostic tool (2), - The prohibiting step is triggered either during the sending of a determined diagnostic request by the diagnostic tool or when the motor vehicle has traveled a determined distance.
3. An information system for securing diagnostic requests for a motor vehicle computer, characterized in that, The information system includes components for implementing the steps of the method according to claim 2.
4. A computer program product, the computer program product including instructions for implementing the method according to claim 2 for securing diagnostic requests for a motor vehicle computer when the computer program is executed on one or more processors.
Citation Information
Patent Citations
Establishing secure communication for vehicle diagnostic data
CN105323302A