Device having an interface and method for operating a device having an interface

By introducing state variables and volatile storage into the equipment, safety requirements can be dynamically adjusted, solving the safety issues of the equipment at different stages of use, enabling rapid testing in the production stage and safety assurance in the field stage, and reducing the risk of unauthorized manipulation.

CN114761893BActive Publication Date: 2025-10-28ROBERT BOSCH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080087762.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-16
Filing Date
2020-12-17
Publication Date
2025-10-28
Estimated Expiration
2040-12-17

AI Technical Summary

Technical Problem

In the existing technology, the security of equipment at different stages of use is difficult to be dynamically adjusted according to its usage scenario, which increases the possibility of manipulation, especially in the production and field stages, where the equipment is vulnerable to unauthorized access and manipulation.

Method used

By introducing state variables into the device, security requirements are dynamically adjusted according to different usage stages, restricting the execution and transmission permissions of computer programs, using volatile memory to temporarily store test software, and ensuring interface security through authentication and encryption measures at different stages.

Benefits of technology

It improves the safety of equipment at different stages of use, reduces the possibility of unauthorized operation, ensures that the test software can be executed quickly in the production stage, and provides interface security and overall protection for the equipment in the field stage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114761893B_ABST
    Figure CN114761893B_ABST
Patent Text Reader

Abstract

A method for operating a device (100), namely a control device for a motor vehicle, wherein the device (100) has at least one interface (120) for exchanging data with an external unit (200), and the device (100) includes at least one first storage device (130) for non-volatile storage of state variables (ZV), wherein the method (300) includes the following steps: evaluating (310) the state variables (ZV); and, based on the evaluation (310), enabling (320) or disabling (330) the execution of at least one computer program (PRG1) and / or at least one computer program (PRG1) from an external unit (200). The unit (200) transmits via interface (120) the at least one computer program (PRG1) for controlling the execution (360) of test software, particularly production line terminal (EoL) software, wherein the value of a state variable (ZV) is assigned to the usage phase of the device (100); and wherein the method (300) includes the additional step of changing (380) the value of the state variable (ZV) according to the usage phase of the device (100) and / or the transition from one usage phase of the device (100) to another usage phase of the device (100), wherein the value of the state variable (ZV) is changed incrementally and / or irreversibly.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method for operating a device having an interface for exchanging data with an external entity.

[0002] Furthermore, this disclosure relates to a device having an interface for exchanging data with an external unit. Background Technology

[0003] A method for online communication is known from DE 102010008816 A1. Access to a wireless data transmission network (Datenverkehrsnetz) is adjusted based on the determined security status. Summary of the Invention

[0004] In contrast, the method of the present invention has the following advantages: It allows for a graded security concept that can be accurately coordinated to different stages of use, based on the different applications of the device, thereby improving anti-manipulation security. When using state variables, the likelihood of interface activation and thus initiating the operation of the computer program, i.e., the test software, must be adapted to the specific circumstances. Furthermore, the possibility of manipulation is made even more difficult by allowing, in particular, incremental and / or irreversible changes to the values ​​of the state variables.

[0005] In a suitable extension scheme, the equipment has at least two or three, especially four or five, distinct usage phases, wherein the corresponding usage phases are characterized, in particular, by corresponding safety requirements, and in particular, at least one first value of a state variable is assigned to the first usage phase, especially the production phase, and at least one other, especially a second value, is assigned to another, especially the second usage phase, especially the field phase, wherein the other usage phase is characterized by high safety requirements. It is in these different usage phases that the equipment is subjected to different manipulation possibilities. In the production phase, these manipulation possibilities are more easily limited. To inspect the equipment, especially after production has commenced, at the bandende, it is necessary to be able to start running the test software particularly quickly. This is particularly preferably achieved by allowing the execution and / or transmission of computer programs in the first usage phase without authentication.

[0006] Particularly preferably, the execution and / or transmission of computer programs are prohibited during other phases of use. Devices, such as control devices, are now continuously operating within the vehicle and are therefore subject to numerous attempts at manipulation. To enhance safety, interfaces are disabled during critical phases of use. Particularly suitably, other diagnostic interfaces are activated, through which, in addition to common diagnostic functions, reactivation of the interfaces can be introduced in the workshop as needed under high safety requirements.

[0007] In a suitable extension scheme, between the first value and another value of the state variable, an optional second value of the state variable is assigned to an optional second use stage, particularly a storage stage, where execution and / or transmission of the computer program is only permitted after authentication. Thus, the possibility of increased manipulation relative to the production stage is considered.

[0008] In a suitable extension scheme, another value of the state variable is assigned to another usage phase of the device, particularly the back-off phase and / or analysis phase, where execution and / or transmission of the computer program are only permitted after authentication, especially via other means such as the backend or trust center. It is precisely through this hierarchical security concept, with different security requirements in each usage phase, that other attacks can be mitigated.

[0009] In other preferred embodiments, the computer program is advantageously configured to perform device operation, particularly system-related operation, particularly hardware testing, particularly final hardware testing, and / or device parameterization, particularly the transmission of at least one function and / or at least one configuration. For example, the computer program can also be configured to perform activation software, particularly function-on-demand activation software for enabling device functionality. According to other embodiments, the computer program may also include activation software or a portion thereof.

[0010] In other preferred embodiments, the device is a control device (electronic control unit, ECU), particularly for motor vehicles, such as control devices for internal combustion engines in motor vehicles. However, in other preferred embodiments, the application of the principles of the embodiments is not limited to the field of motor vehicles or the field of control devices.

[0011] In other preferred embodiments, the second storage device is a storage device for volatile storage of at least one, particularly device-executable, computer program. In other preferred embodiments, the second storage device is working memory (RAM, random access memory). By loading the computer program into RAM, the software does not reside permanently in the device because it is automatically deleted from RAM after a hardware / power-off reset due to the characteristic properties of volatile memory. Storage in permanent memory is unnecessary. Memory for the computer program is not retained and thus not wasted. During normal operation, the corresponding storage area can be used for other functions. Therefore, this method can be used not only for devices with large non-volatile memory, but also for devices with small non-volatile memory.

[0012] In other preferred embodiments, the first storage device is, for example, a flash memory, such as a flash EEPROM or NOR flash or NAND flash, or a non-volatile working memory NVRAM (non-volatile random access memory), such as FeRAM, MRAM, PCRAM, or NRAM.

[0013] In other preferred embodiments, the first storage device is configured to include a one-time programmable (OTP) memory, or a portion thereof.

[0014] In other preferred embodiments, the first storage device includes a hardware security module (HSM), particularly a cryptographic module, or a portion thereof. For example, the hardware security module is configured to perform an encryption method or algorithm, or at least a portion thereof.

[0015] In other preferred embodiments, the hardware security module (HSM) is configured to have a protected, in particular a separate memory, for storing state variables. Attached Figure Description

[0016] Other features, applications, and advantages of the invention will become apparent from the following description of embodiments of the invention, illustrated in the accompanying drawings. All described or illustrated features, either alone or in any combination, form the subject matter of the invention, and are independent of their representation in the specification or their illustration in the drawings.

[0017] In the attached diagram:

[0018] Figure 1 A simplified block diagram and external units of the device according to a preferred embodiment are shown;

[0019] Figure 2 A simplified flowchart illustrating the method according to other preferred embodiments is shown schematically;

[0020] Figure 3 A simplified flowchart illustrating a portion of the method according to other preferred embodiments is shown schematically;

[0021] Figure 4 A simplified flowchart illustrating the method according to other preferred embodiments is shown schematically;

[0022] Figure 5 A simplified flowchart illustrating a portion of the method according to other preferred embodiments is shown schematically.

[0023] Figure 6 A simplified flowchart illustrating a portion of the method according to other preferred embodiments is shown schematically. Detailed Implementation

[0024] Figure 1 A simplified block diagram of device 100 according to a preferred embodiment is shown schematically. Device 100 is preferably a control device (electronic control unit, ECU).

[0025] In other preferred embodiments, device 100 can be configured as a control device, particularly for motor vehicles, such as a control device for an internal combustion engine of a motor vehicle. However, in other preferred embodiments, the application of the principles of the embodiments is not limited to the field of motor vehicles or the field of control devices.

[0026] Device 100 preferably has at least one computing device 110, which may be allocated, for example, storage devices 130 and 140, particularly for at least temporarily storing at least one computer program PRG1 and PRG2, which is particularly used to control the operation of device 100. In other preferred embodiments, multiple computer programs, such as bootloaders, may be stored in storage devices 130 and 140; that is, computer programs that can control the startup process of the device or the startup process of the computing device 110 of device 100, or particularly after the startup process, can control the calling of other computer programs PRG1 and PRG2; and other computer programs PRG1 and PRG2 may be stored, such as the operating system and / or application programs of device 100.

[0027] In other preferred embodiments, the computing device 110 includes at least one of the following elements: a microprocessor, a microcontroller, a digital signal processor (DSP), a programmable logic module (e.g., an FPGA, field-programmable gate array), an ASIC (application-specific integrated circuit), or hardware circuitry. In other preferred embodiments, combinations thereof are also conceivable.

[0028] Device 100 has an interface 120. For example, interface 120 may be a preferably bidirectional communication interface (address bus and / or data bus and / or serial communication bus or the like), through which device 100 can be connected to an external unit 200 (especially for testing device 100) for data exchange. The external unit is, for example, a computer, especially a test computer, having a computing unit and at least one storage unit connected to the computing unit, and software, especially test software, is stored in an executable manner on said storage unit. For example, in the context of end-of-line (EoL) testing, especially at the end of the production process of device 100, a computer program PRG1 is transferred from the external unit 200 to device 100 via interface 120, especially to the storage device 140 of device 100. This computer program PRG1 is particularly used to control the execution of the test software, especially the EoL software. The test software is preferably used for hardware testing during production or at the terminal, which can also be used for backtesting.

[0029] In other preferred embodiments, interface 120 is configured to be a particularly general test and / or diagnostic interface, particularly an Ethernet or CAN interface.

[0030] Advantageously, testing of device 100, particularly hardware and / or software testing, is possible via interface 120. Here, access to the hardware of device 100 is possible via interface 120, especially when executing test software, particularly end-of-line (EoL) software. To prevent potential abuse of access via interface 120, appropriate measures must be taken to secure interface 120. See below for reference. Figures 1 to 6 This describes an advantageous implementation of the measures used to secure interface 120.

[0031] In addition, device 100 (besides interface 120) also includes a diagnostic interface 150. If the vehicle is, for example, in a workshop during normal operation, common diagnostic procedures can be performed via the diagnostic interface 150 during another usage phase (field phase). The corresponding diagnostic software that works in conjunction with the diagnostic interface 150 is significantly different from the computer program PRG1 described above, especially the computer program used to control the execution of test software, particularly end-of-line (EoL) software. In this context, the corresponding diagnostic software executed using the diagnostic interface 150 may, for example, be permanently stored in non-volatile memory 130.

[0032] The reactivation of interface 120, which was shut down during the field phase, can be introduced via diagnostic interface 150, as described later. Interface 150 can be a logical interface, meaning that interfaces 120 and 150, while physically using the same interface, use different protocols. Alternatively, they can also be physically different interfaces with different ports.

[0033] According to a preferred embodiment, the device 100 includes at least one first storage device 130 and at least one second storage device 140, the at least one first storage device 130 being used for non-volatile storage of state variable ZV, and the at least one second storage device 140 being used to store at least one, in particular, device-executable computer program PRG1, the computer program PRG1 being used in particular for controlling the execution of test software, in particular production line end (EoL) software.

[0034] The second storage device 140 for storing the computer program PRG1 is, for example, a storage device for volatile storage of the computer program PRG1, such as working memory (RAM, random access memory). Within the scope of the test equipment 100, such as in the scope of end-of-line (EoL) testing (with-end testing, testing after production), especially at the end of the production process of equipment 100, the computer program PRG1 is transferred to the storage device 140 of equipment 100 via interface 120.

[0035] In other preferred embodiments, the computer program PRG1 includes privileges that, when executing the computer program PRG1, particularly when executing test software, especially production line terminal (EoL) software, may allow access to the hardware of device 100 and / or reading and / or writing to the storage device of device 100. To prevent potential abuse of these privileges, it may be advantageous to remove the computer program PRG1 from the second storage device 140 of device 100 after execution.

[0036] Due to the volatile nature of the memory, especially during a hardware power-down reset (HW / power-down reset), particularly when the power supply to device 100 is cut off, the computer program PRG1 is deleted from the second storage device 140. Therefore, the deletion of the computer program PRG1 occurs with the execution of the HW / power-down reset, making explicit deletion unnecessary. Furthermore, by residing in volatile memory, the computer program PRG1 does not require the memory of the first storage device 130, especially permanent memory.

[0037] In particular, the computer program PRG1 is a computer program used to control the execution of test software, especially production line terminal (EoL) software, i.e., to control the inspection of equipment 100 (e.g., control equipment for a motor vehicle) at the terminal, i.e., after production of equipment 100. According to other preferred embodiments, the computer program PRG1 may also include test software, especially production line terminal (EoL) software, or a portion thereof. The computer program PRG1 is advantageously configured to perform operations on equipment 100, especially system-related operations, especially hardware testing, especially final hardware testing, and / or perform parameterization of equipment 100, especially transmission and / or activation of at least one function and / or at least one configuration. Thus, especially in the production context, the computer program PRG1 enables in-depth final hardware testing and the writing of production-related data into equipment 100. Following the production phase, the final, fully programmed device 100, tested by the computer program PRG1, is either directly supplied to the customer (e.g., a vehicle manufacturer) (and subsequently reaches the field phase), or it reaches the warehouse (storage phase) and subsequently reaches the customer. Further, during the return analysis phase, after certification within the return phase, or at the set first analysis flag FA1, detailed hardware tests provided by the computer program PRG1 can be performed. To enhance security against abuse, interface 120 is permanently disabled during the field phase, making it impossible to access device 100 independently during the field phase via interface 120.

[0038] In other preferred embodiments, the computer program PRG1 is advantageously configured to change the state variable ZV. Advantageously, the computer program PRG1 includes computer-readable instructions that, when executed by the device 100, and in particular by the computing device 110 of the device 100, perform the change of the state variable ZV, as referenced below. Figure 6 The description.

[0039] The computer program PRG1 may also include program parts for performing reprogramming and / or for disabling interface 120, for example by removing the path used to reach or address interface 120 in the bootloader.

[0040] In particular, the computer program PRG1 can be transferred to the second storage device 140 as a file, especially a hexadecimal file, or it can be transferred to the second storage device 140 gradually as multiple files, especially executable files, especially hexadecimal files, wherein the term "hexadecimal file" can include any machine-readable code form. In particular, the transfer of the computer program PRG1 as a total hexadecimal file or as multiple individual hexadecimal files can advantageously adapt to the available storage space of the second storage device 140.

[0041] For example, the first storage device 130 is a flash memory, such as flash EEPROM, NOR flash, or NAND flash, or non-volatile working memory (NVRAM), such as FeRAM, MRAM, PCRAM, or NRAM. Advantageously, when needed, especially for evaluating the state variable ZV, the device 100 can read the state variable ZV from the first storage device 130.

[0042] The device 100, and in particular the computing device 110 of the device 100, is configured to perform the method 300, which is described below with reference to the figures.

[0043] Other preferred embodiments relate to a method 300 for operating device 100, wherein method 300 is advantageously performed within, and / or immediately following, the startup or boot process of device 100. Method 300 according to these embodiments includes the following steps (see also...) Figure 2 (Simplified flowchart in the text):

[0044] Evaluate state variable ZV 310; and based on evaluation 310, allow 320 or prohibit 330 the transfer of computer program PRG1 from external unit 200 to second storage device 140 via interface 120, said computer program PRG1 being particularly used to control the execution of test software, particularly production line terminal (EoL) software. Immediately after allowing 320, the computer program PRG1 is advantageously transferred to the second storage device 140 of device 100, and then executed. Figure 2 (Not shown in the image).

[0045] After the computer program PRG1 is executed, especially when performing a power-off reset, particularly when the power supply voltage to device 100 is cut off, the computer program PRG1 is deleted from the second storage device 140. Therefore, the storage space reserved by the computer program PRG1 is only temporarily maintained, particularly within the scope of testing device 100, and especially within the scope of end-of-line (EoL) testing. Subsequently, for example, when device 100 is used in normal operation, such as when device 100 is used as a control device in a motor vehicle during normal operation, the corresponding storage space in the second storage device 140 can be used to perform other functions and applications of device 100.

[0046] In other preferred embodiments, depending on the state variable ZV, 320 or 330 may allow or prohibit the transfer of computer program PRG1 from external unit 200 to second storage device 140 via interface 120.

[0047] The state variable ZV, and especially the value of the state variable ZV, advantageously characterizes the state of the device 100, and in particular the corresponding stage of the life cycle of the device 100.

[0048] In other preferred embodiments, the value of the state variable ZV is assigned to the usage phase of the device 100. Therefore, depending on the usage phase of the device 100, the transmission of the computer program PRG1 from the external unit 200 to the second storage device 140 is permitted 320 or prohibited 330.

[0049] The usage stages of the equipment 100 according to the preferred embodiment are, for example: a first usage stage, also known as the production stage (Tier 1 Production); a second usage stage, also known as the storage stage (storage); a third usage stage, also known as the field stage (OEM production / field); and a fourth usage stage, also known as the return stage (return analysis). In the first usage stage, the equipment 100 is produced, and the equipment 100 is at the manufacturer's (Tier 1) location. In this stage, particularly immediately following the manufacturing process of the equipment 100, it is advantageous to perform testing on the equipment 100, such as performing end-of-line (EoL) or end-of-line testing. In the second usage stage, the equipment 100 is stored, at least temporarily, particularly in the manufacturer's storage facility or in an external storage facility. In this stage, particularly before delivery to the customer, especially the OEM, it is advantageous to perform retesting on the equipment 100, such as performing end-of-line (EoL) testing. In the third usage stage, the equipment 100 is used at the customer's location, particularly at the OEM's location, or on-site. During this usage phase, testing of device 100, especially EoL testing, should be impossible. In the fourth usage phase, device 100 is back at the manufacturer's premises, and there it is (re)inspected, for example, within the scope of a return analysis.

[0050] The above list of usage phases relates to preferred embodiments and is merely exemplary. Within the scope of the invention, device 100 may advantageously include portions of the mentioned usage phases and / or other usage phases.

[0051] In other preferred embodiments, if the state variable ZV has a value assigned to the third usage stage (field stage), that is, if the evaluation 310 of the state variable ZV determines that the state variable ZV has a value assigned to the third usage stage (field stage), then the transmission of the computer program PRG1 from the external unit 200 to the second storage device 140 via the interface 120 is prohibited. Therefore, in the third usage stage, especially the field stage, the transmission of the computer program PRG1 via the interface (hereinafter also referred to as EoL access) is unavailable.

[0052] In other preferred embodiments, if the state variable ZV has a value assigned to the first use stage, especially the production stage, i.e., the evaluation 310 of the state variable ZV concludes that the state variable ZV has a value assigned to the first use stage, especially the production stage, then the computer program PRG1 is allowed to transfer from the external unit 200 to the second storage device 140 via the interface 120.

[0053] The evaluation of the state variable ZV 310 may include, in particular (see...) Figure 3 ): Query 310a to check if the state variable ZV has a value assigned to the third usage stage, i.e., the field stage. If so, then prohibit the transfer of computer program PRG1 from external unit 200 to the second storage device 140 via interface 120.

[0054] Advantageously, during and / or immediately following the startup or boot process of device 100, following a prohibition 330, a query is made in other, particularly optional, steps 330a, to check for the existence of a programming request, particularly a reprogramming request, especially for programming device 100 using an application. Based on the result of query 330a, then advantageously, another, particularly optional, step 330b is performed, i.e., programming, particularly reprogramming, or step 330c is performed, i.e., application execution.

[0055] The evaluation of state variable ZV 310 may further include: querying 310c whether state variable ZV has a value assigned to the first usage stage (production stage). If so, the transfer of computer program PRG1 from external unit 200 to the second storage device 140 is permitted 320. Immediately following the permission of 320, computer program PRG1 is advantageously transferred to the second storage device 140 of the device, and computer program PRG1 is executed 360.

[0056] Advantageously, before allowing the transfer of computer program PRG1 (320), a further query is made in step 320a to check whether there is a request for performing tests on device 100, particularly end-of-line (EoL) tests, and only if so, is the transfer of computer program PRG1 (320) from external unit 200 to the second storage device 140 via interface 120 permitted. It can be further advantageously configured that, if not, a query is made in another, particularly optional, step 330a, to check whether there is a programming request, particularly a reprogramming request, specifically for programming device 100 using an application. Based on the result of query 330a, then another, particularly optional, step 330b, i.e., performing programming, particularly reprogramming, or step 330c, i.e., performing the application, is advantageously performed.

[0057] In other preferred embodiments, the device 100 is configured to have at least two, three, particularly four, or five distinct usage phases, wherein each usage phase is characterized, in particular, by corresponding safety requirements, and in particular, at least one first value of the state variable ZV is assigned to the first usage phase, wherein the first usage phase of the device 100 is characterized by low safety requirements, and at least one other, particularly a second value, is assigned to another, particularly a second usage phase of the device 100, wherein the other, particularly a second usage phase of the device 100 is characterized by high safety requirements. The usage phases are advantageously those mentioned above, namely: the first usage phase, also known as the production phase (first-level production); the second usage phase, also known as the storage phase (storage); the third usage phase, also known as the field phase (OEM production / field); and the fourth usage phase, also known as the return phase (return analysis).

[0058] For example, the first use phase is the production phase. In this phase, the equipment is in the manufacturer's (first level) "safe" environment. Thus, the first use phase is advantageously characterized by low safety requirements. In the first use phase of equipment 100 (where the state variable ZV corresponds to the first value), the execution and / or transmission of the computer program PRG1 is permitted without authentication (see step 340). The computer program PRG1 is loaded into the second storage device 140 by the bootloader (FBL, a software module used to load / write software into volatile storage device 140 or non-volatile storage device 130) and executed from there. After a hardware / power-down reset, due to the characteristic features of the volatile second storage device 140, the computer program PRG1 is automatically deleted from RAM. It is not necessary to maintain an additional permanent storage area for the computer program PRG1. Furthermore, this improves security because the computer program PRG1 does not permanently reside on device 100. Therefore, especially during the initial production run, interface 120 is available and unsecured.

[0059] An optional second use phase is, for example, a storage phase. Specifically, it is configured that device 100 has left or will leave the manufacturer's secure environment during the second use phase. To prevent abuse of access via interface 120, enhanced security requirements for securing interface 120 advantageously apply at least to the second use phase. Thus, the optional second use phase is advantageously characterized by high security requirements, particularly enhanced compared to the first use phase. In the optional second use phase of device 100 (where the state variable ZV takes an optional second value), execution and / or transmission of the computer program PRG1 is permitted only after authentication (e.g., step 340 described later). Therefore, interface 120 is theoretically available during the optional second use phase, but only after authentication (secured in an encrypted manner).

[0060] Specifically, it can be configured such that, in an optional second usage phase of device 100, the transmission of computer program PRG1 from external unit 200 via interface 120 to the second storage device 140 of device 100 is coupled to successful authentication of external unit 200 and / or user of external unit 200, and thereby, in particular, access to the hardware of device 100 is coupled to successful authentication of external unit 200 and / or user of external unit 200, said computer program PRG1 being used, in particular, to control the execution of test software, particularly production line terminal (EoL) software. As another security measure, allowing the execution of computer program PRG1 can be coupled to successful authentication of computer program PRG1. This will be discussed later. Figure 5 Describe it.

[0061] Furthermore, another, especially a third, value for the state variable ZV can be assigned to another, especially a third, usage phase of the device 100, wherein at least this other, especially third, usage phase is characterized by higher security requirements, especially relative to the first usage phase and / or higher security requirements, especially relative to the second usage phase. This other or third usage phase is, for example, a field phase. In this phase, the device 100 has left the manufacturer's "safe" environment and is either at the OEM or in the field. Specifically, in this other or third usage phase of the device 100, the transfer of the computer program PRG1 from the external unit 200 to the second storage device 140 of the device 100 via interface 120 is prohibited, and thereby, in particular, access to the hardware of the device 100, said computer program PRG1, is used to control the execution of test software, especially production line terminal (EoL) software. In other usage phases, especially the field phase, the diagnostic interface 150 remains available. Interface 120 can be reactivated in conjunction with successful authentication introduced via the diagnostic interface 150.

[0062] Furthermore, another, especially a fourth, value of the state variable ZV can be assigned to another, especially a fourth, usage phase of the device 100, wherein at least this fourth, especially the fourth, usage phase is characterized by higher, especially at least relative to, the security requirements of the first usage phase. This fourth or second usage phase is, for example, a rollback phase. In this usage phase, the device 100 is back at the manufacturer's premises, and there, for example, it is (re)examined within the scope of the rollback analysis. In particular, it can be advantageously configured that, in this fourth or second usage phase of the device 100, the computer program PRG1 is coupled to the successful authentication of the external unit 200 and / or the user of the external unit 200 via the interface 120 to the second storage device 140 of the device 100, and thereby, in particular, access to the hardware of the device 100 is coupled to the successful authentication of the external unit 200 and / or the user of the external unit 200, as this has already been mentioned above in connection with the optional second usage phase. The computer program PRG1 is particularly used to control the execution of test software, particularly the production line terminal (EoL) software. Furthermore, allowing the execution of computer program PRG1 can be coupled to the successful authentication of computer program PRG1. This will be discussed later as well. Figure 5 This is described. As described, the reactivation of interface 120 (which is closed during the field phase) can therefore be performed in the next or fourth use phase, especially the analysis phase. The corresponding value of the state variable ZV is irreversibly incremented, meaning that transitioning to the previous phase (field phase) is not possible in this variant.

[0063] In an alternative embodiment, the reactivation of interface 120 (after authentication) may be accompanied by setting the first analysis flag FA without first leaving the field phase.

[0064] According to the described implementation, another or third use phase is advantageously characterized by the highest security requirements. The first use phase is advantageously characterized by the lowest security requirements. The security requirements of optional second and yet another or fourth use phases lie between the security requirements of the first use phase and the security requirements of another or third use phase. In particular, the device 100 is no longer in the manufacturer's security environment in the second, third, and fourth use phases, or at least temporarily outside the manufacturer's security environment, making it impossible to rule out unauthorized access.

[0065] Advantageously, in the third usage phase (field phase), device 100 has the highest level of assurance for interface 120, meaning that EoL access is neither available nor reactivated in the field phase. In the first usage phase, device 100 has a comparatively lowest level of assurance for interface 120, meaning that EoL access is available in the first usage phase (also known as the production phase (first-level production)) without further authentication.

[0066] Advantageously, within the scope of the startup or boot process of device 100, when evaluating the state variable 310, a query is first made in step 310a to determine whether the state variable ZV has a value assigned to another or third usage phase, i.e., the field phase, see [reference]. Figure 3 If this is not the case, then in step 310b, it is queried whether the state variable ZV has a value assigned to an optional second or fourth use phase. If this is not the case, then in step 310c, it is queried whether the state variable ZV has a value assigned to the first use phase. Advantageously, the steps for querying 310a, 310b, and 310c are performed in the following order within the range of evaluating the state variable ZV: first querying the value assigned to the use phase with the highest level of security for interface 120, and finally querying the value assigned to the use phase with the lowest level of security for interface 120. Advantageously, this way, in the event of abuse, especially in the case of a glitch attack, several obstacles may have to be overcome.

[0067] Advantageously, it can be further configured that if the evaluations 310, 310a, 310b, 310c of the state variable ZV do not yield a valid value, especially if the state variable ZV does not have a value assigned to the usage phase of the device 100, then another optional step 310d is performed, wherein step 310d includes, in particular, detecting a fault and / or transposing the device 100 to a fault mode.

[0068] In other preferred embodiments, the method includes an additional step 380: changing the value of the state variable ZV according to the usage phase of the device 100 and / or the transition from one usage phase of the device 100 to another usage phase of the device 100, wherein the value of the state variable ZV is changed incrementally, and in particular irreversibly. This means that after transitioning to the next usage phase, the previously experienced usage phase cannot be retold. Advantageously, the change 380 of the state variable ZV is immediately followed by allowing the transmission of the computer program PRG1 320 and the transmission and execution of at least a portion of the computer program PRG1 360.

[0069] In other preferred embodiments, the computer program PRG1 is advantageously constructed to change the 380 state variable ZV.

[0070] The value of the 380 state variable ZV is changed as follows (see below). Figure 6 The following is a description. According to the illustrated implementation, the state variable ZV initially has a value assigned to the first usage phase. After evaluating the state variable ZV 310, the transfer of the computer program PRG1 320 is permitted, and the computer program PRG1 has been transferred to the second storage device 140 (in...). Figure 6 (Not shown in the diagram). In step 360, computer program PRG1 is executed, particularly at least a portion of computer program PRG1, which is specifically used to control the execution of test software, particularly production line terminal (EoL) software. Advantageously, executing computer program PRG1 includes performing hardware testing 360a. According to the illustrated embodiment, executing computer program PRG1 further includes optional step 370, ensuring that the interface 120 of device 100 is secured, particularly by means of encryption, particularly by means of a signature-based or key-related checksum-based (also known as Message Authentication Code, MAC) scheme. In particular, this is done in conjunction with other authentication and / or verification measures (see [link to documentation]). Figure 4 and Figure 5 Relatedly, this step can prove to be advantageous.

[0071] According to the illustrated embodiment, executing the 360 ​​computer program PRG1 further includes an optional step 380: changing the state variable ZV. Advantageously, the change 380 may include: changing the value of the state variable to a value assigned to a subsequent use phase. Advantageously, the value of the state variable ZV may only be changed to a value assigned to a subsequent use phase, and may not be changed to a value assigned to a previous use phase. According to the described embodiment, the value of the state variable ZV may, for example, be changed from a value in a first use phase to a value in a second use phase, from a value in a second use phase to a value in a third use phase, and from a value in a third use phase to a value in a fourth use phase.

[0072] Advantageously, the change in the value of the state variable ZV cannot be reversed.

[0073] According to Figure 6 In the embodiment shown, the value of the state variable ZV is first changed from its value in the first use phase to its value in the second use phase (storage phase), 380a. Then, if the equipment 100 is delivered to the customer, i.e., the upcoming subsequent use phase is the third use phase (field phase), the value of the state variable is changed from its value in the second use phase to its value in the third use phase, 380b. In other preferred embodiments, if, for example, the equipment 100 is delivered directly to the customer after production without intermediate storage, the value of the state variable ZV can be changed from its value in the first use phase to its value in the third use phase (field phase).

[0074] In other preferred embodiments, a first storage device 130 is provided (see Figure 1 This includes an One-Time Programmable (OTP) memory, or a portion thereof. Advantageously, the OTP memory is implemented as a so-called "OTP Area" in the first storage device 130 (especially in flash memory). This OTP Area is protected from alteration, particularly by additional logic means. Advantageously, additional variables ZV and / or the first analysis flag FA1 are stored in the OTP memory.

[0075] In other preferred embodiments, the first storage device 130 includes a hardware security module (HSM), particularly a cryptographic module, or a portion thereof. For example, the hardware security module is configured to execute an encryption method or algorithm, or at least a portion thereof. In other preferred embodiments, the hardware security module (HSM) has a protected, particularly separate, memory for storing the state variable ZV and / or the first analysis flag FA1. Particularly preferably, only the device 100, particularly the computing device 110 of the device 100, configured to execute the methods according to these embodiments, has access to the state variable ZV stored in the hardware security module. In other preferred embodiments, the hardware security module or cryptographic module executes the methods according to these embodiments, at least partially or completely, particularly performing step 380, i.e., changing the state variable ZV. In other preferred embodiments, the hardware security module or cryptographic module manages (particularly stores and / or changes) and / or evaluates the state variable ZV. In other preferred embodiments, a hardware security module or cryptographic module is configured to output the evaluation results of the state variables to other units, such as computing device 110.

[0076] In other implementations, EoL access can be completely eliminated, i.e., the EoL software can be transmitted via the interface. This is exemplarily achieved through optional step 390 (see...). Figure 6 As shown in the diagram. In this case, the 390EoL access is eliminated before delivery to the customer, i.e., before transitioning to the third usage phase (field phase). In this case, the method 300 according to the invention is executed for either the first usage phase or for both the first and second usage phases, and the corresponding EoL access path is deleted at the end of the execution of the computer program PRG1, in particular from the bootloader. In this case, method 300 is no longer executed during the startup or boot process of the computing device 110 or the device 100. Therefore, reactivation of the EoL access is excluded from the scope of re-EoL testing, and thus, regression analysis is excluded.

[0077] In other preferred embodiments, it is advantageously provided that the interface 120 of device 100 is secured in optional step 370, particularly by means of encryption, especially by means of a signature-based or key-related checksum-based (also known as a message authentication code MAC) scheme, see [link to relevant documentation]. Figure 6 For subsequent access via interface 120, especially for the transmission of computer programs, this makes additional authentication and / or verification measures necessary. (Refer to method 300) Figure 4 and Figure 5In connection with the implementation described below, this protection 370 can be proven to be advantageous.

[0078] In other preferred embodiments, the method 300 is further provided with (see...) Figure 4 ): Authenticate external unit 200 and / or the user of external unit 200, wherein after successful authentication of 340, at least one computer program PRG1 is allowed to transfer from external unit 200 to the second storage device 140 via interface 120, and after unsuccessful authentication of 340, at least one computer program PRG1 is prohibited from transferring from external unit 200 to the second storage device 140 via interface 120.

[0079] In other preferred embodiments, authentication of external unit 200 and / or user of external unit 200 is provided using a signature-based or key-related checksum-based scheme.

[0080] It can be configured to perform authentication 340 regardless of the value of the state variable ZV.

[0081] In other preferred embodiments, authentication 340 is advantageously configured to be performed based on the value of the state variable ZV.

[0082] In other preferred embodiments, authentication 340 is performed if the state variable ZV has other, especially second or fourth, values, and authentication 340 is not performed if the state variable ZV has a first value.

[0083] In particular, if the state variable ZV has a value assigned to device 100 for a usage phase with low security requirements (especially the first usage phase), authentication 340 is not performed. If device 100 is in the first usage phase, especially at the manufacturer's location, interface 120 is not encrypted for performance or cycle time reasons, meaning that the transfer of computer program PRG1 from external unit 200 to the second storage device 140 of device 100 is permitted without additional authentication process 340 (see [link to relevant documentation]). Figure 4 Advantageously, within the scope of executing the 360 ​​computer program PRG1, especially immediately following the execution of the 360a hardware test, in step 370, interface 120 is secured, in particular, by encryption. (See also...) Figure 6 .

[0084] Advantageously, authentication 340 is performed if the state variable ZV has a value assigned to the second or fourth use phase of device 100. In particular, authentication 340 is performed for use phases in which device 100 is at least temporarily outside the manufacturer's secure environment, or was previously outside the manufacturer's secure environment, during and / or before the use phase.

[0085] For example, in the second phase of use, after the device 100, especially the final manufactured and fully programmed device, is stored in a warehouse that is especially "freely accessible" and located outside the manufacturer, retesting of the device 100 is performed before delivery to the customer. This includes, in particular, end-of-line (EoL) testing, hardware testing, and final hardware testing, and / or parameterization of the device 100. Interface 120 is now secured in an encrypted manner, making the authentication process 340 necessary.

[0086] In other preferred embodiments, the method further includes: authenticating the computer program PRG1 transmitted by 350, wherein after successful authentication of the computer program PRG1 transmitted by 350, at least a portion of the transmitted computer program PRG1 is executed by device 100, and after unsuccessful authentication of the computer program PRG1 transmitted by 350, the computer program transmitted by 360b is not executed.

[0087] In other preferred embodiments, the computer program PRG1 transmitted by 350 is configured to be authenticated using a signature-based or key-related checksum-based scheme.

[0088] In other preferred embodiments, authentication of external unit 200 and / or user of external unit 200, and / or authentication of computer program PRG1 transmitted by external unit 200 are provided using at least one encryption key, especially a private key.

[0089] In other preferred embodiments, the computer program PRG1 transmitted by the authentication 340 external unit 200 and / or the user and / or authentication 350 of the external unit 200 further includes: generating a challenge, particularly a challenge including a random number and / or a pseudo-random number, transmitting the challenge to the external unit, and receiving the signed challenge from the external unit.

[0090] Now refer to Figure 4 and Figure 5 The computer program PRG1 transmitted by the user and / or the authentication 350 of the external unit 200 and / or the external unit 200 for the signature-based scheme is described.

[0091] Authentication of external unit 200 and / or users of external unit 200 by device 100 specifically includes: submitting a security request by external unit 200 and / or users of external unit 200. For example, submitting a security request might be done via diagnostic interface 150 (especially in another usage phase (field phase), in which interface 120 is disabled while diagnostic interface 150 remains active). In step 400, a challenge is then generated, especially a challenge including random numbers and / or pseudo-random numbers, and especially as a response to the submitted security request, the challenge is transmitted to external unit 200 410.

[0092] In other implementations, a 400 challenge is generated via an HSM or by means of suitable software. External unit 200 and / or its user signs the challenge using a private key, particularly a project-specific one, and transmits the signed challenge to device 100.

[0093] In step 420, device 100 receives a signed challenge. In step 430, device 100 verifies the received signed challenge using other keys, especially public keys, that match the private keys of external unit 200 and / or the user of external unit 200.

[0094] If verification 420 is successful, that is, if the other keys of device 100 match the private keys of external unit 200 and / or the user of external unit 200, then the transmission of computer program PRG1 is permitted. If verification 420 fails, the transmission is prohibited.

[0095] The method is further configured according to the embodiment shown, and further includes: authenticating the computer program PRG1 transmitted by 350, wherein the computer program PRG1 is executed only after successful authentication of 350.

[0096] In other preferred embodiments, the authentication of the computer program PRG1 transmitted by 350 further includes: receiving the signed computer program PRG1 by 350a.

[0097] For this purpose, external unit 200 and / or the user of the external unit also sign the computer program PRG1 using a private key, especially a project-specific one, and transmit the signed computer program PRG1 to device 100. Device 100 receives the signed computer program PRG1.

[0098] In step 440, the device 100 verifies the received signed computer program PRG1 by using other keys, especially public keys, that match the private key of the external unit 200 and / or the user of the external unit 200.

[0099] If verification 440 is successful, that is, if the other keys of device 100 match the private keys of external unit 200 and / or the user of external unit 200, then computer program 360a PRG1 is executed. If verification 440 fails, computer program 360b is not executed.

[0100] Within the scope of executing the 360a computer program PRG1, especially after successfully executing the hardware test, the value of the status variable is changed from the value of the second usage phase to the value of the 380 third usage phase. See [link / description]. Figure 6 .

[0101] In other preferred embodiments, if the state variable ZV has another or a fourth value, the authentication 340 external unit and the authentication 350 computer program are executed, while if the state variable ZV has another or a third value, the authentication 340 external unit and the authentication 350 computer program are not executed.

[0102] According to the implementation shown, in another or third phase of use, EoL access via interface 120 is neither available nor reactivated. Therefore, if the state variable ZV has another or third value, authentication 340 is not performed.

[0103] Furthermore, similarly for another or fourth use phase, the method can be performed with respect to an optional second use phase. Figure 5 The steps shown are as follows.

[0104] Other preferred embodiments involve a computer-readable storage medium SM that includes commands, particularly commands in the form of a computer program PRG2, which, when executed by a computer, cause the computer to perform the method 300 according to these embodiments.

[0105] In other preferred embodiments, the storage medium includes the first storage device 130 of device 100, or a portion thereof, see [reference needed]. Figure 1 .

[0106] Other preferred embodiments involve a computer program PRG2 comprising computer-readable instructions that, when executed by a computer, particularly by a computing device 110 of device 100, perform the steps of method 300 according to the embodiment.

[0107] Other preferred embodiments involve the use of method 300 according to the embodiment and / or device 100 according to the embodiment and / or computer program PRG2 according to the embodiment for the following: enabling or disabling interface 120 of device 100 to transmit a computer program PRG1 executable by device 100, based on a state variable ZV of device 100, wherein the computer program PRG1 is particularly used to control the execution of test software, particularly production line end (EoL) software, wherein the value of state variable ZV is assigned to the usage phase of device 100.

[0108] Other preferred embodiments involve the use of the method 300 according to the embodiment and / or the device 100 according to the embodiment and / or the computer program PRG2 according to the embodiment for the following: allowing or disabling the execution of the computer program PRG1, which can be executed by the device 100 and transmitted via the interface 120 of the device 100.

[0109] In other alternative configurations, particularly for reactivating interface 120 which has been deactivated during other usage or field phases, authentication of the identified user may be necessary. For example, the user may authenticate with a key management system (KMS) or public key infrastructure (PKI) via appropriate authentication methods, such as smart cards. This is preferably performed via an external device. After successful authentication, a corresponding request to reactivate interface 120 may be made, for example, via diagnostic interface 150. However, if the user has not previously been verified as authorized, such a request to reactivate interface 120 is not permitted via diagnostic interface 150. Other authentication methods for reactivating interface 120 are performed as described above.

[0110] The described method is used in particular for the safe and flexible management of control devices (as device 100) for motor vehicles at different stages of use. However, its use is not limited to this.

Claims

1. A method for operating a control device (100) of a motor vehicle, wherein the control device (100) has at least one interface (120) for exchanging data with an external unit (200), and the control device (100) includes at least one first storage device (130) for non-volatile storage of state variables (ZV), wherein the method (300) includes the following steps: The state variable (ZV) is evaluated (310), and based on the evaluation (310), the execution of at least one computer program (PRG1) and / or the transmission of at least one computer program (PRG1) from the external unit (200) via the interface (120) are permitted (320) or prohibited (330) based on the evaluation (310). The computer program (PRG1) is used to control the execution (360) of test software, including production line terminal (EoL) software, wherein the value of the state variable (ZV) is assigned to the usage phase of the control device (100), and wherein the method (300) includes the additional step of changing (380) the value of the state variable (ZV) based on the usage phase of the control device (100) and / or the transition from one usage phase of the control device (100) to another usage phase of the control device (100). The transmission and execution of the test software mentioned above - Permitted during the production phase as the first stage of use without certification. - Storage and / or return and / or analysis phases, which are used as other use phases, are only permitted after certification (340). - It is simply not possible in the field stage as the third stage of use. The corresponding usage phase is characterized by corresponding safety requirements, and at least one first value of the state variable (ZV) is assigned to the production phase, wherein the production phase of the control device (100) is characterized by low safety requirements or no safety requirements, and at least one third value of the state variable (ZV) is assigned to the field phase of the control device (100), wherein the field phase of the control device (100) is characterized by high safety requirements.

2. The method according to claim 1, wherein, The value of the state variable (ZV) is changed incrementally and / or irreversibly.

3. The method according to claim 1, wherein, The interface (120) is unavailable and / or cannot be reactivated, and / or the corresponding access path to the interface (120) is removed from the bootloader.

4. The method according to any one of claims 1-3, wherein, The control device (100) has at least one diagnostic interface (150) different from the interface (120), through which the reactivation of the interface (120) can be introduced.

5. The method according to any one of claims 1-3, wherein, The transition from the first value of the state variable (ZV) directly to the third value of the state variable (ZV), without transitioning to the optional second value of the state variable (ZV), makes it no longer possible to change the state variable (ZV) to the optional second value.

6. The method according to any one of claims 1-3, wherein, The method further includes: securing (370) the interface (120) of the control device (100) in an encrypted manner.

7. The method (300) according to any one of claims 1-3, wherein, The method (300) further comprises: authenticating (340) the external unit (200) and / or the user of the external unit (200), wherein, upon successful authentication (340), the transmission of the at least one computer program (PRG1) from the external unit (200) to the second storage device (140) via the interface (120) is permitted (320), and upon unsuccessful authentication (340), the transmission of the at least one computer program (PRG1) from the external unit (200) to the second storage device (140) via the interface (120) is prohibited (330).

8. The method (300) according to any one of claims 1-3, wherein, The authentication (340) is performed based on the value of the state variable (ZV), and if the state variable (ZV) has the first value, the authentication (340) is not performed.

9. The method (300) according to any one of claims 1-3, wherein, The method further includes: authenticating (350) the transmitted computer program (PRG1), wherein after successful authentication (350) of the transmitted computer program (PRG1), the transmitted computer program (PRG1) is executed (360a) by the control device (100), and after unsuccessful authentication (350) of the computer program (PRG1), the transmitted computer program (PRG1) is not executed (360b).

10. A motor vehicle control device (100) comprising: an interface (120) for exchanging data with an external unit (200), and at least one first storage device (130) for non-volatile storage of state variables (ZV), and at least one second storage device (140) for storing at least one computer program (PRG1) executable by the control device (100), the computer program (PRG1) being used to control the execution (360) of test software, including production line terminal (EoL) software, wherein the control device (100) is configured to perform the method (300) according to any one of claims 1-9.

11. The control device (100) according to claim 10, wherein, The first storage device (130) includes an one-time programmable (OTP) memory, or a portion thereof; and / or the first storage device (130) includes a hardware security module (HSM), or a portion thereof.

12. A computer-readable storage medium (SM) comprising a computer program (PRG2) having instructions that, when executed by a computer, cause the computer to perform the method (300) according to any one of claims 1-9.

13. A computer program product comprising a computer program (PRG2) including computer-readable instructions that, when executed by a computer, perform the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Methods for online communication

    DE102010008816A1

  • Method for protecting microcomputer from manipulation, involves determining multiple access levels for test software and test software is only executed on microcomputer at determined access level

    DE102006061935A1