Ensuring connection security between a vehicle and a remote management server for managing the vehicle
By employing a dual-SIM card system and a monitoring module to detect connectivity in vehicles, the security issues of vehicles in situations with no network coverage or unreliable communication are resolved. This enables low-cost secure communication and attack protection under user cellular subscriptions, thereby improving the user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 安培簡式股份有限公司
- Filing Date
- 2021-05-27
- Publication Date
- 2026-05-08
AI Technical Summary
In existing technologies, the security of telematics services cannot be guaranteed when there is no network coverage or communication is unreliable. Furthermore, there are security vulnerabilities when using a user's cellular phone subscription to connect to the Internet, resulting in costly dual-SIM dual-standby solutions.
A dual SIM card system is used, with one card associated with the vehicle manufacturer's subscription and the other with the user's subscription. The connection between the vehicle and the remote management server is monitored through a monitoring module. The system is tested regularly and switches to the manufacturer's card in case of anomalies to ensure security, combined with secure reboot and disabling of insecure communication.
Without significantly increasing costs, this method ensures reliable communication between vehicles and remote management servers, prevents cyberattacks, reduces anomaly detection due to lost radio coverage, and improves security and user experience.
Smart Images

Figure CN115769620B_ABST
Abstract
Description
[0001] This invention relates generally to telecommunications and motor vehicles, and more specifically to ensuring the provision of telematics services to vehicles and the software security of such vehicles.
[0002] Manufacturers provide detailed descriptions of telematics services in their vehicles, utilizing sensitive data and functions. These services are typically executed, on one hand, by embedded logic residing in the vehicle, and on the other hand, by external logic residing on at least one remote server hosted by the manufacturer or a third party. A fundamental issue in ensuring the security of telematics services and automotive software often revolves around the communication link between these two pieces of logic. In fact, to achieve a good level of security, manufacturers establish secure communication mechanisms between the embedded and external parts of the software for these telematics services. Manufacturers also establish management centers for their fleet of vehicles. These management tools, for example, allow manufacturers to detect anomalies and trigger blocking or corrective actions within the vehicle in response to malfunctions or potential cyberattacks, by updating the vehicle's software.
[0003] However, this security assurance strategy proves ineffective when the vehicle is not covered by the network and cannot communicate with the manufacturer's remote server, or when communication between the vehicle and the remote server is no longer considered reliable and trustworthy. One means of enhancing the connection security between the embedded part of the telematics service software in the vehicle and its external parts is to obtain additional protection and countermeasure capabilities subscribed to by the vehicle manufacturer and implemented by the telecommunications operator.
[0004] However, as these telematics services were established, the demand for bringing the internet to vehicle users was emerging and growing. Furthermore, car owners had a strong need to be able to access the internet using their own cellular phone subscriptions.
[0005] The internet connection now brings with it a host of threats and potential vulnerabilities that could allow hackers to control the electronic components using the connection. Furthermore, the fact that this internet connection utilizes user-specific subscriptions with different telecom operators than the vehicle manufacturer prevents users from benefiting from the safeguards and remedial measures that the manufacturer's telecom operator could provide to ensure the security of telematics services used by the vehicle.
[0006] Therefore, it is necessary to ensure secure communication between the vehicle and its remote management center, while allowing vehicle users to connect to the Internet via their cellular phone subscriptions.
[0007] One solution is to isolate the connection and system used for internet access on one side from those used for telematics services on the other. Since users use their own cellular phone subscriptions, this means the physical cellular communication system must be redundant: either utilizing two cellular modems instead of just one, or using one cellular modem that can operate with two simultaneously active SIM (Subscriber Identity Module) cards—a capability known as "active dual-SIM." In both cases, this redundancy represents a very significant cost overrun (tens of dollars per vehicle).
[0008] One object of the present invention is to overcome at least some of the disadvantages of the prior art by providing a vehicle, a system, and a method at a lower cost, which ensures trusted communication between the vehicle and a management center that manages the vehicle’s network security, while allowing the vehicle’s user to access the Internet via his or her own cellular phone subscription.
[0009] To this end, the present invention proposes a vehicle comprising a communication module capable of using two telecommunications identification cards, one of which relates to a subscription between the vehicle's manufacturer and a telecommunications operator, and the other of which relates to a subscription between the vehicle's user and a telecommunications operator. The vehicle includes a trusted execution environment hosting the vehicle's security functions and a multimedia system execution environment hosting at least a portion of the communication module. The vehicle is characterized in that the trusted execution environment includes a monitoring module that monitors the connection between the vehicle and a remote management server of the vehicle.
[0010] With this invention, a single modem either uses a connection based on the vehicle's subscription or a connection based on the user's subscription, but the connection between the vehicle and a remote server is monitored. Therefore, when a connection based on the user's subscription is no longer considered reliable or trustworthy, the modem can, for example, immediately switch to the vehicle manufacturer's SIM card to benefit from network attack prevention and remediation measures provided by the operator linked to the manufacturer, without requiring any expensive "dual SIM" modems.
[0011] Advantageously, the monitoring module can periodically test the connection by sending and receiving signed, unique, and predefined messages to and from the remote management server. This implementation, in particular, provides replay protection.
[0012] In a variant embodiment of the invention, the monitoring module is able to periodically test the connection by receiving a unique, predefined, signed message from the remote management server. Therefore, in this variant, the monitoring module does not send test messages but rather monitors the correct reception of test messages.
[0013] Again, advantageously, the monitoring module is able to detect connection anomalies in the following situations:
[0014] The communication module instructs the vehicle to perform cellular connection operations, while the communication module either confirms sending one of the messages to the remote management server or does not transmit one of the messages sent by the remote management server.
[0015] - Alternatively, the communication module may indicate that the vehicle's cellular connectivity is unavailable for a duration greater than a first predefined time interval.
[0016] This implementation makes it easy to detect suspicious anomalies in the communication module that are not caused by brief and limited loss of radio coverage. In this application, "cellular connectivity" of the vehicle is understood to mean the ability to receive or send messages via radio, particularly with adequate cellular telephone network coverage.
[0017] Advantageously again, the messages sent by the monitoring module include information indicating that an anomaly has been detected in the connection between the vehicle and the remote management server, or information indicating that this is not the case. This allows the remote management server to intervene, if possible, to rule out or confirm the anomaly, and to implement remedial actions such as remote vehicle software updates.
[0018] According to another advantageous feature, the vehicle according to the invention includes at least one transmitting device selected from a list comprising:
[0019] - A first device for sending instructions to the communication module to trigger the disabling of external communications of unsafe applications on the vehicle.
[0020] - A second device for sending instructions to the communication module to trigger the selection by the communication module of a telecommunications identifier card related to the vehicle manufacturer's subscription as the sole connection device, and for disabling any communication with any entity other than the remote management server by the communication module.
[0021] - A third device for sending instructions to the communication module to trigger a restart of the communication module, and for sending instructions to cause a restart of the multimedia system execution environment and simultaneously enforce a security configuration on the restart.
[0022] - and a fourth device for sending instructions to trigger a restart of at least a portion of the vehicle's other execution environment or other software and simultaneously enforcing a safety configuration on those portions.
[0023] The vehicle further includes an activation device configured to activate all or part of the selected sending devices when an abnormal connection is detected between the vehicle and the remote management server.
[0024] By incorporating one or more of these four transmitting devices, vehicles according to the invention benefit from a remedial solution independent of a remote management server.
[0025] Advantageously, the vehicle according to the invention includes at least the first transmitting device, and the activation device is configured to activate only the first transmitting device when the communication module indicates that the vehicle's cellular connection is unavailable for a duration greater than the first predefined time interval. Therefore, excessive degradation of the user experience is avoided in the event of erroneous anomaly detection due to loss of radio coverage.
[0026] Again, advantageously, the vehicle according to the invention includes at least the second transmitting device, the activation device being configured to activate the second transmitting device when the communication module indicates that the cellular connection is unavailable for a duration greater than a second predefined time interval, excluding a transmitting device selected from the third or fourth transmitting device, the second predefined time interval being greater than the first predefined time interval. Therefore, even if the vehicle according to the invention includes a third and / or fourth transmitting device, these devices are not initially implemented, especially as long as the vehicle is not stopped. Thus, the remote management server SG has time to intervene to avoid implementing the third and fourth transmitting devices in the event of a false detection. Therefore, when the possibility of a suspicious anomaly increases, the user experience is hardly degraded while ensuring vehicle safety.
[0027] Again, advantageously, the vehicle according to the invention includes at least the third or fourth transmitting device, and the activation device is configured to activate the third or fourth transmitting device only when the vehicle is stopped. This allows for ensuring vehicle safety by ensuring that the user experience is not compromised only at the most appropriate time, especially only outside of the vehicle's operating phase.
[0028] The present invention also relates to a system comprising a vehicle according to the invention and the remote management server, characterized in that the remote management server comprises:
[0029] - A means for receiving messages sent by the monitoring module and including information indicating that an anomaly has been detected in the connection between the vehicle and the remote management server.
[0030] - A means for detecting whether the abnormal detection result is due to a cyberattack by correlating the location of the vehicle (V) with radio coverage data.
[0031] - A means for sending a message indicating that the anomaly is not caused by a cyberattack on the vehicle (V) in response to a message from the monitoring module (MS) that reports the anomaly detection result.
[0032] Therefore, the remote management server prevents the vehicle from performing remedial actions that would harm the user experience when false detections occur due to momentary or prolonged loss of radio coverage.
[0033] Advantageously, the remote management server further includes:
[0034] - A device for immediately detecting a cyberattack when multiple vehicles report more anomalies than a predefined threshold.
[0035] - A means for sending a message to the vehicle to activate a program for securely restarting the communication module and the multimedia execution environment, and / or for immediately updating a program in the multimedia execution environment when the detection device detects a cyberattack. This additional feature enables protection of the vehicle from predefined future cyberattacks.
[0036] Finally, the present invention relates to a method for ensuring a secure connection between a vehicle according to the invention and the remote management server of the vehicle, the method comprising the following steps:
[0037] - Send and / or receive signed, unique, and predefined messages from the remote management server, respectively.
[0038] - Detect anomalies in the connection.
[0039] - Send instructions to the communication module to switch the communication between the vehicle and the remote management server to a connection using a telecommunications identifier card associated with the vehicle's manufacturer's subscription.
[0040] The system and method according to the invention provide advantages similar to those of the vehicle according to the invention.
[0041] Other features and advantages will become clear from the preferred embodiments described with reference to the accompanying drawings, in which:
[0042] - Figure 1 This illustrates the vehicle and system according to the invention in this preferred embodiment.
[0043] - Figure 2This illustrates a remedial device for a vehicle according to the invention in this preferred embodiment.
[0044] - Figure 3 This illustrates the steps of the method according to the invention in this preferred embodiment.
[0045] - Figure 4 This illustrates a state diagram of the remedial logic implemented in a vehicle according to the invention in this preferred embodiment.
[0046] according to Figure 1 The preferred embodiment of the invention shown herein includes a vehicle V comprising various execution environments hosting various software. Specifically, the vehicle V's safety software (such as engine control software or driver assistance software) is hosted on a secure computer, accessible, for example, only via a secure gateway containing a Trusted Execution Environment (TEE). In this exemplary embodiment of the invention, the TEE hosts the following: the vehicle V's safety functions (SF), a module (MR) hosting remedial functions triggered in the event of a network attack, and a module (MS) for monitoring the connection between the vehicle V and a remote management server (SG) of the vehicle V. The TEE is hosted, for example, in a secure gateway that establishes a link between the vehicle's safety software area and a software area including multimedia communication functions for communicating with the outside of the vehicle, which can access the vehicle's secure computer.
[0047] Vehicle V also includes at least one unsafe execution environment, where the multimedia system execution environment EESM hosts the so-called "infotainment" information and leisure portion of Vehicle V. Therefore, the execution environment EESM hosts applications AC intended for use by the vehicle's users (and these applications are exposed to data streams from or to the Internet), such as geolocation services, embedded browsers, etc. The execution environment EESM also hosts non-safety functions BF of the vehicle, such as the vehicle V's audio output settings or graphical interface.
[0048] Finally, the execution environment EESM hosts the communication module MC. The communication module MC contains a cellular radio modem capable of converting Ethernet network signals to GSM (“Global System for Mobile Communications”), 3G, 4G, 5G (G stands for mobile phone technology generation), or Wi-Fi (according to the IEEE 802.11 standard) radio signals, and vice versa. In variant embodiments, the communication module MC converts other types of wired protocols to other types of radio protocols, particularly depending on the country of use of the vehicle and its electrical / electronic architecture. For example, in a variant, the modem is used to convert CAN (Controller Area Network) signals to CDMA2000 signals.
[0049] While the communication module MC is included in the execution environment EESM, primarily to allow insecure applications to communicate externally, some functions of these insecure applications are secure. These secure functions are implemented by secure electronic circuitry or in a secure computer, such as a microcontroller. Therefore, the execution environment EESM contains not only insecure software but also secure software and / or hardware circuitry. These functions, in particular, allow the Trusted Execution Environment (TEE) to force the communication module MC to switch to a vehicle V-specific manufacturer's telecommunications identifier card, as described later. It is certainly possible, in variants, that the secure portion of the communication module MC forms part of the Trusted Execution Environment (TEE).
[0050] The modem of the communication module MC has a "dual SIM" capability, which allows it to use two SIM cards. In this embodiment, these two cards are:
[0051] - A SIM card marked with the telecommunications identifier UCA, related to a subscription between the vehicle's user and the telecommunications operator.
[0052] - A SIM card marked with the telecommunications identifier VCA is associated with a subscription between the vehicle manufacturer and a telecommunications operator, which may be different from the telecommunications operator supplying the UCA card.
[0053] The UCA card used by the communication module MC is, for example, a virtual SIM. This means that the user does not need to place their SIM card in a specific slot in the vehicle's modem; they simply enter the data to authenticate their personal SIM card in the vehicle so that the vehicle can generate the virtual SIM card. In variants, the communication module MC has a physical slot that allows the user to insert their personal SIM card.
[0054] In this embodiment of the invention, the modem of the communication module MC does not have the ability to use both UCA and VCA cards simultaneously, but only one of these cards at a time, establishing communication with the outside world by switching from one card to the other, depending on the context. Therefore, it does not have so-called "dual SIM dual standby" capability. For example, when a user of vehicle V uses the execution environment EESM to access the Internet, the communication module uses the UCA card to establish a communication session LSU with the Internet network INT. This communication session is established at a standard security level specific to a personal cellular phone subscription and can also be used to communicate with the remote management server SG. When vehicle V is stopped, the engine is off, the doors are closed, and there are no users inside, and the vehicle is communicating with the remote management server SG for maintenance reasons, the communication module MC, on the other hand, uses the VCA card to establish a communication session LSV with the remote management server SG. This communication session LSV benefits from a security level that may be higher than the security level of the communication session LSU, such as using a secure APN ("Access Point Name").
[0055] The communication module (MC) also has the ability to report the status of cellular connections to the execution environment (TEE). In particular, it indicates whether radio network coverage is too weak or nonexistent to establish an external communication session.
[0056] The remote management server SG includes a logical VAL for general management of the manufacturer's vehicles and a regulatory module SMM for monitoring the communication link between the vehicle V and the remote management server SG.
[0057] The primary risk associated with using a UCA card is attacks from the internet, which could allow hackers to control the vehicle's computer and insecure execution environment (TEE). This could potentially allow a hacker to sever communication between the remote management server (SG) and the TEE, thereby preventing the TEE from receiving commands to trigger corrective actions and restore normal operation. To mitigate this issue, the supervisory module (MS) monitors the connection between the vehicle (V) and the remote management server (SG) while the vehicle (V) is in use. This monitoring is specifically performed by periodically testing the connection. Therefore, the supervisory module can detect abnormal interruptions in communication between the vehicle (V) and the remote management server (SG). When such a connection anomaly is detected, the supervisory module (MS) activates security functions (SF), which include... Figure 2 This is implemented in modules M1 through M4. Therefore, it should be understood in this application that the supervisory module MS implements supervision of the connection between the vehicle and the remote management server SG, which differs from the standardized supervisory mechanism implemented by the communication module MC, and in particular from the message encryption mechanisms mandated by GSM, 3G, 4G, 5G, or Wi-Fi communication standards used by the communication module MC. In fact, this supervisory module can detect abnormal interruptions in communication between the vehicle V and the remote management server SG, that is, abnormal interruptions caused by a breach of the software integrity of the communication module MC.
[0058] More specifically, the monitoring module MS includes an activation module MA, which receives an exception code, the status of the cellular connection, and the status of the vehicle V as input. Based on these input parameters, the activation module MA activates one or more of modules M1 to M4.
[0059] Module M1 is a software device for sending instructions to the safety microcontroller of the communication module MC to trigger the disabling of external communications of unsafe applications on the vehicle (that is, cutting off any communication originating from the execution environment EESM and destined for the Internet).
[0060] Module M2 is a software device used to send instructions to the security microcontroller of the communication module MC to trigger the communication module MC to select external communication of the VCA card and to disable any communication with the remote management server SG.
[0061] Module M3 is a software device for sending instructions to the secure microcontroller of the communication module MC to trigger a restart of the communication module MC, and for sending instructions to the secure section MB1 of the execution environment EESM to restart that secure section. In variants, only one instruction is required, especially when the microcontroller is linked to the secure section MB1. These secure restarts trigger the erasure of the system's random access memory and force the VCA card to communicate with the remote management server SG without requiring an internet connection.
[0062] Module M4 is a software device for sending instructions to trigger a secure reboot of vehicle V, including all or part of the other execution environment or other software MB2 to MBn. This secure reboot triggers the erasure of the random access memory of these other environments and the software, and, if necessary, prevents the use of certain software parts that are more sensitive to attacks than other software parts.
[0063] exist Figure 3 The present invention illustrates an example of a method for ensuring a secure connection between a vehicle V and a remote management server SG, as described in the present invention, whereby a supervisory module MS uses one of these devices. In this example, the communication module MC initially uses a UCA card for external communication.
[0064] Step E1 involves the supervisory module MS sending and receiving signed, unique, and predefined messages to the remote management server SG and from the vehicle V, respectively. To this end, the supervisory module MS periodically sends messages to the remote management server SG, allowing the SG to authenticate them. For example, the message is signed using an asymmetric encryption algorithm such as RSA (Rivest, Shamir, and Adleman) encryption. In a variant, the supervisory module MS uses a signature obtained through a hash algorithm of type HMAC (“Key Hash Message Authentication Code”), which uses an encryption key known only to the manufacturer (and securely contained in both the vehicle V and the remote management server SG). Of course, other symmetric or asymmetric encryption algorithms can also be used to sign the messages sent by the supervisory module MS. These messages also include replay prevention data, such as timestamps, counts, or predefined numbers generated by algorithms known only to the vehicle V and the remote management server SG. The messages sent by the supervisory module MS also include an exception code, the value of which and its meaning are, for example:
[0065] -0: The monitoring module MS did not detect any anomalies.
[0066] -1: Connection disconnection caused by the communication module MC indicating that the time of lack of network coverage continues to exceed the first predetermined time threshold T1.
[0067] -2: Connection disconnection caused by the communication module MC indicating a lack of network coverage for a period exceeding a second predetermined time threshold T2, where the second predetermined time threshold is greater than a first predetermined time threshold T1.
[0068] -3: The connection was lost for unknown reasons.
[0069] The first predetermined time threshold T1 is set to, for example, 30 minutes, and the second predetermined time threshold T2 is set to, for example, 60 minutes.
[0070] It should be noted that, in this embodiment of the invention, for simplicity, the exception codes specifically focus on connection drops caused by real or spurious network coverage interruptions. In reality, exception codes may have more subtle differences. For example, in variations, different codes are applied to the following situations:
[0071] The monitoring module MS has sent a test message and received an immediate protocol reply, but has not received a response from the remote management server SG.
[0072] The monitoring module MS has sent a test message but has not received any immediate protocol response, while the communication module MC has indicated that a connection has been established with the remote management server SG.
[0073] The monitoring module MS failed to transmit test messages, and the communication module MC indicated that no further connection could be established with the remote management server SG, while the cellular connection was operating in data transmission mode.
[0074] - The communication module MC indicates that there is no longer a usable cellular connection in data transmission mode, but network coverage is available.
[0075] - The communication module MC indicates that there is no longer network coverage.
[0076] In this variant, the time counters corresponding to times T1 and T2 are, for example, more broadly applied to the communication module MC to indicate that there is no longer a connection established with the remote server SG, so as to activate modules M1 and M2 respectively.
[0077] The messages sent by the remote management server SG in response to messages received from the supervisory module MS are signed and include replay blocking data, similar to the messages sent by the supervisory module MS. Additionally, response messages from the remote management server SG may include confirmation or exclusion of a previously reported lack of network coverage by the supervisory module MS, or instructions to trigger remedial actions on vehicle V (such as a software update or safe reboot instruction performed immediately when vehicle V stops).
[0078] Step E2 of this method involves the supervisory module MS detecting a connection anomaly. The supervisory module MS detects this anomaly under the following conditions:
[0079] - The supervisory module does not receive a response to one of the messages it sent, or the communication module MC indicates that it cannot transmit one of the messages from the supervisory module MS to the remote management server SG, but the communication module MC indicates that network coverage is available. This detection result may be achieved after several retransmission tests or when a time counter set to a predefined response time (e.g., set to 15 minutes) expires; this detection result corresponds to exception code 3 defined above.
[0080] - The communication module MC indicates that the network coverage is unavailable for a duration greater than a predefined time threshold T1 or T2; this detection result corresponds to the above-defined exception code 1 or 2 based on the corresponding threshold.
[0081] Step E3 involves the supervisory module MS activating remedial measures to re-establish trusted communication between vehicle V and remote management server SG, even if the execution environment EESM is compromised due to an attack. These measures are chosen to best protect the user experience, especially when the detected anomaly corresponds to a genuine loss of network coverage rather than a network attack. Therefore, the impact on the likelihood of connection between the user and vehicle V gradually increases based on the state of vehicle V and the actual risk of a network attack. For example, the supervisory module MS makes more attempts to resend messages when the communication module MC indicates a lack of network coverage compared to when the communication module MC indicates network coverage is available. Similarly, predefined time thresholds T1 or T2 are set, for example, based on geolocation data. Thus, if the vehicle detects entering a blank area, these thresholds are adapted, for example, to the estimated time spent traveling in that area. The impact of the remedial action also varies depending on the detected anomaly code. In this example using the invention, it is assumed that vehicle V is in use and the reported anomaly code is 3. In this case, step E3 includes activating module M2 to trigger a switch of communication between vehicle V and remote management server SG to a connection using a VCA card. In other words, module M2 sends a command to communication module MC to temporarily sever communication between vehicle V and remote management server SG, and to re-establish the connection between the two entities by using a subscription from vehicle V's manufacturer.
[0082] Once communication is re-established between vehicle V and remote management server SG, the supervisory module MS sends exception code 3 to remote management server SG in a message. Then, the supervisory module SMM of remote management server SG sends, either in a corresponding response message or separately, an instruction to perform remedial action via vehicle safety function SF. This remedial action, such as a software update or a safe restart of the environmental EESM, will be implemented immediately when the vehicle stops, preferably with the engine off simultaneously. If remote management server SG does not respond, vehicle V performs the remedial action itself.
[0083] It should be noted that after communication is re-established between vehicle V and remote management server SG, when the exception code reported by the monitoring module is 1 or 2, the remote management server SG can check whether vehicle V is in an area with poor or non-existent network coverage. If this is the case, the monitoring module SMM of the remote management server SG immediately notifies vehicle V of its presence in such an area upon re-establishment of communication with vehicle V, thereby avoiding a pointless safety reboot of the environment EESM the next time vehicle V stops. On the other hand, when this is not the case, the monitoring module SMM of the remote management server SG immediately notifies vehicle V of this upon re-establishment of communication with vehicle V, and immediately sends a safety reboot command or updates the execution command of the environment EESM when the vehicle stops, preferably simultaneously with the engine off. It should be noted that, preferably, the safety reboot of the communication module MC and the environment EESM is delayed for several tens of seconds after the vehicle stops, so that the completion of task processing operations is not interrupted. In addition, when the vehicle stops, sending and receiving test messages is stopped to protect the vehicle's battery.
[0084] Furthermore, since the remote management server SG manages all the vehicles in operation, it can detect cyberattacks by correlating anomalies reported by these vehicles. Specifically, if the number of anomalies reported by these vehicles within a geographic area including acceptable network coverage exceeds a predefined threshold, such as exceeding 1000 within a short period, the supervisory module SMM detects the cyberattack and uses a secure reboot to program software updates on its vehicles.
[0085] refer to Figure 4 Examples of logic implemented in the supervisory module MS that can minimize the impact of the security assurance method according to the invention on the user experience include states S0 to S5.
[0086] In state S0, vehicle V is stopped, and the engine is off and not ignited; that is, no ignition switch is set. In this state, vehicle V only communicates with the remote management server SG using the VCA card, and no internet communication is established. When the user starts vehicle V using the ignition switch, the logic switches to state S1.
[0087] In state S1, the user can input their personal SIM card data into the vehicle and access the internet via the execution environment EESM through the UCA card. If this data has already been input into vehicle V during previous use, the communication module MC immediately switches to the UCA card upon vehicle startup. The monitoring module MS then monitors the connection between vehicle V and the remote management server SG. In this state S1, when the user turns off the vehicle, the logic returns to state S0.
[0088] If, in state S1, the supervisory module MS receives an instruction from the remote management server SG to securely restart the communication module MC and the environment EESM, and possibly update these entities, then the logic switches to state S2, which securely restarts (and possibly updates) these entities. After a secure restart in state S2, the logic switches to secure communication state S4, which will be described later.
[0089] If the supervisory module MS detects anomaly code 1 or 3 in state S1, the supervisory module MS activates module M1 and logically switches to state S3. In this state, the communication module MC continues to use the UCA card, but communication with any Internet other than the remote management server SG is prohibited.
[0090] If, in state S3, the monitoring module MS detects anomaly code 2 or 3, that is, the communication module MC indicates that there has been no network coverage for one hour, or the communication module MC has not sent or received messages for fifteen minutes without indicating a loss of network coverage, then the logic switches to secure communication state S4.
[0091] If, in state S3, the user turns off vehicle V, and the remote management server SG cannot rule out triggering exception code 1 or 3 to switch to state S3 and notify vehicle V, then the logic switches to state S5 for a safe restart of the communication module MC, thereby forcing the communication module to use only the VCA card; after this restart, the logic switches to safe communication state S4.
[0092] If, in state S3, the remote management server SG excludes exception codes 1 or 3 that would trigger a switch to state S3, then the logic switches to state S1.
[0093] In secure communication state S4, the communication module MC is authorized to communicate with the remote management server SG using only the VCA card, regardless of whether vehicle V is started or stopped. If vehicle V is started in state S4, and the user stops the vehicle, but the remote management server SG cannot rule out exception codes 1, 2, or 3 that would cause a transition to state S4 and notifies vehicle V, the logic loop returns to state S4. Conversely, if in state S4 the remote management server SG rules out exception codes 1, 2, or 3 that would cause a transition to state S4 and notifies vehicle V, the logic loop returns to state S0 if the vehicle is stopped, and returns to state S1 if the vehicle is started.
[0094] Clearly, this logic is merely an exemplary embodiment of the invention. Other logic may be implemented in other variant embodiments of the vehicle, system, or method according to the invention. For example, in a variant where only modules M2 and M3 are implemented in the vehicle, states S3 and S4 are merged. Additionally, in another variant embodiment of the invention, the remote management server SG is owned by a third party. In this variant, the exchange of private keys used to sign messages exchanged between the monitoring module MS and the remote management server SG is performed via a first encrypted exchange, which, for example, uses an RSA asymmetric encryption algorithm. Many other variant embodiments are, of course, possible. In particular, in another variant embodiment of the invention, the monitoring module MS monitors the correct operation of the connection between the communication module MC and the remote management server SG by monitoring the correct reception of signed, unique, and predefined messages sent by the remote management server SG, but the monitoring module itself does not send test messages to the remote management server SG. However, this variant only covers the monitoring of the connection in one direction. In another variant, the monitoring module sends test messages to the remote monitoring server SG, which do not contain exception codes, or only contain exception codes when an exception is detected. Finally, in another variant, the management server SG sends a warning message to vehicle V before it enters the blank area, in order to deactivate the time counters associated with thresholds T1 and T2 until the vehicle has left the blank area.
Claims
1. A vehicle (V) including a communication module (MC) capable of using two telecommunications identification cards, one telecommunications identification card (VCA) associated with a subscription between the manufacturer of the vehicle (V) and a telecommunications operator, and the other telecommunications identification card (UCA) associated with a subscription between a user of the vehicle (V) and a telecommunications operator, the vehicle (V) including a trusted execution environment (TEE) hosting security functions of the vehicle (V), and a multimedia system execution environment (EESM) hosting at least a portion of the communication module (MC). The vehicle (V) is characterized in that the Trusted Execution Environment (TEE) includes a supervisory module (MS) that monitors the connection between the vehicle (V) and the vehicle (V)'s remote management server (SG), and the supervisory module is configured to: When the communication module indicates that the vehicle's cellular connection is unavailable for a duration exceeding a first predefined time interval, a first instruction is sent to the communication module to trigger the disabling of external communication from insecure applications on the vehicle. When the communication module indicates that the vehicle's cellular connectivity is unavailable for a duration greater than a second predefined time interval, a second instruction is sent to the communication module to trigger the communication module to select a telecommunications identifier card associated with the vehicle's manufacturer's subscription as the sole connection device, and to disable any communication with the remote management server, wherein the second predefined time interval is greater than the first predefined time interval.
2. The vehicle (V) as claimed in claim 1, characterized in that, The monitoring module (MS) can periodically test the connection by sending and receiving signed, unique, and predefined messages to and from the remote management server (SG).
3. The vehicle (V) as claimed in claim 1, characterized in that, The monitoring module (MS) can periodically test the connection by receiving a unique, predefined, signed message from the remote management server (SG).
4. The vehicle (V) as described in claim 2 or 3, characterized in that, The monitoring module (MS) is able to detect connection anomalies under the following conditions: The communication module (MC) instructs the vehicle to perform cellular connection operations, while the communication module (MC) either confirms sending one of the messages to the remote management server (SG) or the communication module does not transmit one of the messages sent by the remote management server (SG). - Alternatively, the communication module (MC) may indicate that the vehicle's cellular connectivity is unavailable for a duration greater than a first predefined time interval.
5. The vehicle (V) as claimed in claim 2, characterized in that, The messages sent by the monitoring module (MS) include information indicating that an abnormal connection was detected between the vehicle (V) and the remote management server (SG), or information indicating that no abnormal connection was detected between the vehicle and the remote management server.
6. The vehicle (V) as claimed in claim 4, characterized in that, The messages sent by the monitoring module (MS) include information indicating that an abnormal connection was detected between the vehicle (V) and the remote management server (SG), or information indicating that no abnormal connection was detected between the vehicle and the remote management server.
7. The vehicle (V) as claimed in any one of claims 1-3, characterized in that, The vehicle includes at least one of a list of transmitting devices including the following: - A first transmitting device (M1) for sending instructions to the communication module (MC) to trigger the disabling of unsafe applications of the vehicle (V) for external communication. - A second transmitting device (M2) for sending instructions to the communication module (MC) to trigger the selection by the communication module (MC) of a telecommunications identifier card (VCA) related to the subscription of the vehicle (V) manufacturer as the sole connection device, and for disabling by the communication module (MC) any communication with any entity other than the remote management server (SG). - A third transmitting device (M3) for sending instructions to the communication module (MC) to trigger a restart of the communication module (MC), and for sending instructions to cause a restart of the multimedia system execution environment (EESM) and simultaneously enforce a security configuration on the restart. - and a fourth transmitting device (M4) for sending instructions to trigger a restart of at least a portion of the other execution environment or other software of the vehicle (V) and simultaneously enforcing a safety configuration on those portions, Furthermore, the vehicle includes an activation device (MA) configured to activate all or some of the selected transmitting devices (M1, M2, M3, M4) when an abnormal connection is detected between the vehicle (V) and the remote management server (SG).
8. The vehicle (V) as claimed in claim 7, wherein, The vehicle (V) includes at least the first transmitting device (M1), characterized in that the activation device (MA) is configured to activate only the first transmitting device (M1) when the communication module (MC) indicates that the cellular connection of the vehicle (V) is unavailable for a duration greater than the first predefined time interval.
9. The vehicle (V) as claimed in claim 7, wherein, The vehicle (V) includes at least the second transmitting device (M2), characterized in that the activation device (MA) is configured to activate the second transmitting device (M2) when the communication module (MC) indicates that the cellular connection of the vehicle (V) is unavailable for a duration greater than a second predefined time interval, excluding a transmitting device selected from the third transmitting device (M3) or the fourth transmitting device (M4).
10. The vehicle (V) as claimed in claim 7, wherein, The vehicle (V) includes at least the third transmitting device (M3) or the fourth transmitting device (M4), characterized in that the activation device (MA) is configured to activate the third transmitting device (M3) or the fourth transmitting device (M4) only when the vehicle (V) is stopped.
11. A system for ensuring a secure connection between a vehicle and a remote management server for managing the vehicle, the system comprising a vehicle (V) as claimed in any one of claims 1 to 10, and the remote management server (SG), characterized in that, The remote management server (SG) includes: - A receiving device (SMM) for receiving a message sent by the monitoring module (MS) and including information indicating that an anomaly has been detected in the connection between the vehicle (V) and the remote management server (SG). - A detection device (SMM) for detecting whether anomaly detection results are due to a cyberattack by correlating the location of the vehicle (V) with radio coverage data. - A sending device (SMM) for sending a message indicating that the anomaly is not caused by a cyberattack on the vehicle (V) in response to a message from the monitoring module (MS) that reports the anomaly detection result.
12. The system as claimed in claim 11, characterized in that, The remote management server (SG) further includes: - A detection device (SMM) for immediately detecting cyberattacks when multiple vehicles report more anomalies than a predefined threshold. - A means for sending a message to the vehicle to activate the program for securely restarting the communication module (MC) and the multimedia system execution environment (EESM) and / or for immediately updating the program of the multimedia system execution environment (EESM) when the detection device (SMM) detects a cyberattack.
13. A method for ensuring secure connection between a vehicle (V) as claimed in any one of claims 1 to 7 and the remote management server (SG) of the vehicle, the method comprising the steps of: - Send and / or receive (E1) signed, unique, and predefined messages to and / or from the remote management server (SG). - Detect an anomaly in the connection described in (E2), - Send an (E3) instruction to the communication module (MC) to switch the communication between the vehicle (V) and the remote management server (SG) to a connection using a telecommunications identification card (VCA) associated with the vehicle (V) manufacturer's subscription.
Citation Information
Patent Citations
Server, communication method, vehicle terminal, attack preventing method and system
CN105871816A
Access control system and method of trusted execution environment
CN107426174A
Methods for recording performance indicators of communication networks and telematics units
DE102017128063A1