Vehicle control system and vehicle control method

By using a secure seed and key verification mechanism in a centralized domain controller architecture, the hardware and software of the electronic control unit are matched, which solves the problem of incompatibility of the electronic control unit in a centralized domain controller architecture and improves the reliability and safety of the vehicle.

CN117087602BActive Publication Date: 2026-07-21BOSCH AUTOMOTIVE PRODUCTS (SUZHOU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BOSCH AUTOMOTIVE PRODUCTS (SUZHOU) CO LTD
Filing Date
2023-10-08
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In a centralized domain controller architecture, the hardware and software of the electronic control unit cannot be effectively matched, which affects the reliability and safety of the vehicle.

Method used

The domain controller sends a security seed to the electronic control unit, calculates a security key, and compares it with the key calculated by the electronic control unit. If they match, the electronic control unit is activated; otherwise, it is locked or disconnected, ensuring hardware and software compatibility.

Benefits of technology

It significantly improves the reliability and safety of the vehicle during operation, avoiding hardware failures and safety issues caused by software and hardware incompatibility, especially in the braking and power electronic control units.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117087602B_ABST
    Figure CN117087602B_ABST
Patent Text Reader

Abstract

The application provides a vehicle control system and a vehicle control method. The vehicle control system comprises at least one domain controller and at least one electronic control unit connected with the domain controller, the domain controller stores software for controlling the electronic control unit, and is configured to perform the following operations: sending a security seed to the electronic control unit; calculating a security key according to the security seed, and controlling the electronic control unit to calculate the security key according to the security seed; comparing the security key calculated by itself with the security key calculated by the electronic control unit; if the two security keys are consistent, determining that the electronic control unit is a matching electronic control unit, and controlling the electronic control unit through the stored software; and if the two security keys are inconsistent, determining that the electronic control unit is not a matching electronic control unit, and locking the electronic control unit. The vehicle control method is executed by the vehicle control system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle control technology, and more specifically, to an on-board control system and a vehicle control method. Background Technology

[0002] Automotive electronic / electrical architecture (EEA) refers to the design of a vehicle's hardware and software, including sensors, actuators, electronic control units, wiring harnesses, and operating systems, to achieve efficient signal transmission and wiring layout within the vehicle. EEA design needs to comprehensively consider customer functional requirements, ease of installation, configuration, and maintenance, as well as costs, and requires a degree of forward-thinking. In the era of functional vehicles, the user experience was essentially fixed once the car left the factory. However, in the era of intelligent vehicles, cars can be continuously upgraded to meet increasingly sophisticated user demands. The evolution of EEA from a distributed to a centralized architecture is a prerequisite for this transformation and also a prerequisite for software-defined vehicles.

[0003] In the past, the distributed architecture of electronic control units (ECUs) in vehicles resulted in a massive number of ECUs and deep coupling between hardware and software, making vehicle upgrades difficult. Currently, automotive electrical and electronic architectures are evolving from distributed ECU architectures to centralized domain controller architectures. In a centralized domain controller structure, the ECU software is transferred to a more powerful domain controller, which centrally processes data and controls each ECU, achieving efficient utilization of computing power and coordinated vehicle functions. Furthermore, because the ECU hardware and software are decoupled, ECUs can use standard components, and vehicle upgrades can be easily achieved through software upgrades within the domain controller, thus realizing software-defined vehicles. However, in the existing centralized domain controller architecture, the domain controller cannot implement effective policies to ensure the consistency of ECU hardware and software. This can lead to potential compromises in vehicle reliability and safety due to hardware and software mismatches in the ECUs.

[0004] Therefore, there is an urgent need in this field for a technical solution that can ensure the hardware and software matching of the electronic control unit, thereby ensuring the reliability and safety of the vehicle. Summary of the Invention

[0005] To address the problems in the prior art, this invention proposes an improved vehicle control system, comprising at least one domain controller and at least one electronic control unit (ECU) signal-connected to the domain controller. The domain controller stores software for controlling the ECU and is configured to perform the following operations:

[0006] Send a security seed to the electronic control unit;

[0007] The security key is calculated based on the security seed, and the electronic control unit is controlled to calculate the security key based on the security seed.

[0008] The system compares the security key it calculates with the security key calculated by the electronic control unit.

[0009] If the two security keys match, the electronic control unit (ECU) is determined to be a matched ECU, and the ECU is controlled via the stored software; and

[0010] If the two security keys do not match, it is determined that the electronic control unit is not a matching electronic control unit, and the electronic control unit is locked.

[0011] According to an optional embodiment of the present invention, the domain controller and the matching electronic control unit store the same cryptographic algorithm and are configured to calculate a security key based on a security seed using the cryptographic algorithm.

[0012] According to an optional embodiment of the present invention, both the domain controller and the matching electronic control unit are integrated with a hardware security module, and both the security seed and the cryptographic algorithm originate from the hardware security module.

[0013] According to an optional embodiment of the present invention, the domain controller is further configured to: if it is determined that the electronic control unit is a matched electronic control unit, inform the driver that the electronic control unit has started successfully, and / or send a start success signal to the electronic control unit.

[0014] According to an optional embodiment of the present invention, the domain controller is further configured to: inform the driver of the electronic control unit startup failure if it is determined that the electronic control unit is not a matched electronic control unit, and / or send a startup failure signal to the electronic control unit.

[0015] According to an optional embodiment of the present invention, the domain controller is further configured to: send a security seed to the electronic control unit if a start request is received from the electronic control unit within a predetermined time after the vehicle starts; and determine that the electronic control unit is not a matched electronic control unit if no start request is received from the electronic control unit within the predetermined time after the vehicle starts; and wherein the matched electronic control unit is further configured to: send a start request to the domain controller after the vehicle starts.

[0016] According to an optional embodiment of the present invention, the domain controller is further configured to: send a security seed to the electronic control unit if a start request is received from the electronic control unit; determine that the electronic control unit is not a matching electronic control unit if the number of times the security seed is sent reaches a predetermined number and the two security keys are inconsistent; and wherein the matching electronic control unit is further configured to: send a start request to the domain controller after the vehicle is started.

[0017] According to an optional embodiment of the invention, the domain controller is further configured to inform the driver that the number of times the electronic control unit has been started has exceeded if it is determined that the electronic control unit is not a matched electronic control unit.

[0018] According to an optional embodiment of the present invention, the domain controller is further configured to: send a startup failure signal to the electronic control unit if the number of times the security seed is sent is less than a predetermined number and the two security keys are inconsistent; and wherein the matching electronic control unit is further configured to: send a startup request to the domain controller again if a startup failure signal is received.

[0019] According to an optional embodiment of the present invention, the domain controller is further configured to: detect the connection status of the electronic control unit, and if it is detected that the electronic control unit has been disconnected and reconnected, perform the operation.

[0020] According to an optional embodiment of the present invention, the vehicle control system includes a plurality of domain controllers, each domain controller being signal-connected to a plurality of electronic control units and configured to perform the operation for each electronic control unit.

[0021] According to an optional embodiment of the present invention, the vehicle control system includes a chassis domain controller, which is signal-connected to the brake electronic control unit and configured to perform the operation for the brake electronic control unit.

[0022] Similarly, to address the problems in the prior art described above, this invention also proposes an improved vehicle control method, executed by an onboard control system as described herein, and comprising the following steps:

[0023] S10: The domain controller sends a security seed to the electronic control unit;

[0024] S20: The domain controller calculates the security key based on the security seed, and controls the electronic control unit to calculate the security key based on the security seed;

[0025] S30: The domain controller compares the security key it calculates with the security key calculated by the electronic control unit. If the two security keys match, proceed to S40; if the two security keys do not match, proceed to S50.

[0026] S40: The domain controller determines that the electronic control unit (ECU) is a matched ECU and controls the ECU via the stored software; and

[0027] S50: The domain controller determines that the electronic control unit is not a matched electronic control unit and locks the electronic control unit.

[0028] According to an optional embodiment of the present invention, the vehicle control method further includes the following steps:

[0029] S01: Timing begins after the vehicle starts; and

[0030] S02: If the domain controller receives a start request from the electronic control unit within a predetermined time after vehicle startup, then execute S10; if the domain controller does not receive a start request from the electronic control unit within the predetermined time after vehicle startup, then execute S50; and

[0031] The matching electronic control unit is also configured to send a start request to the domain controller after the vehicle is started.

[0032] According to an optional embodiment of the present invention, S30 is as follows: the domain controller compares the security key calculated by itself with the security key calculated by the electronic control unit; if the two security keys are consistent, then S40 is executed; if the number of attempts is less than a predetermined number and the two security keys are inconsistent, then S03 is executed; if the number of attempts reaches the predetermined number and the two security keys are inconsistent, then S50 is executed.

[0033] Both S40 and S50 also involve: resetting the number of attempts to zero; and

[0034] The vehicle control method also includes the following steps:

[0035] S03: Increase the number of attempts by 1; and

[0036] S04: If the domain controller receives a start request from the electronic control unit, return to S10; if the domain controller does not receive a start request from the electronic control unit, execute S50; and wherein the matching electronic control unit is further configured to send a start request to the domain controller after the vehicle is started.

[0037] According to an optional embodiment of the present invention, S03 further comprises: sending a start-up failure signal to the electronic control unit; and

[0038] The matching electronic control unit is further configured to send a startup request to the domain controller again if a startup failure signal is received.

[0039] According to an optional embodiment of the present invention, the vehicle control method further includes the following steps:

[0040] S05: The domain controller detects the connection status of the electronic control unit; and

[0041] S06: If the domain controller detects that the electronic control unit has been disconnected and reconnected, then execute S10; otherwise, return to S05.

[0042] The present invention may be embodied in the illustrative embodiments shown in the accompanying drawings. However, it should be noted that the drawings are merely illustrative, and any variations contemplated under the teachings of this invention should be considered to be included within the scope of this invention. Attached Figure Description

[0043] The accompanying drawings illustrate exemplary embodiments of the invention. These drawings should not be construed as necessarily limiting the scope of the invention, wherein:

[0044] Figure 1 This is a schematic layout diagram of an in-vehicle control system according to one embodiment of the present invention;

[0045] Figure 2 This is a schematic layout diagram of an in-vehicle control system according to another embodiment of the present invention;

[0046] Figure 3 This is a schematic flowchart of a vehicle control method according to one embodiment of the present invention;

[0047] Figure 4 This is a schematic flowchart of a vehicle control method according to another embodiment of the present invention;

[0048] Figure 5 This is a schematic flowchart of a vehicle control method according to another embodiment of the present invention; and

[0049] Figure 6 This is a schematic flowchart of a vehicle control method according to another embodiment of the present invention. Detailed Implementation

[0050] Further features and advantages of the invention will become more apparent from the following description with reference to the accompanying drawings. Exemplary embodiments of the invention are illustrated in the drawings, and the figures are not necessarily drawn to scale. However, the invention can be implemented in many different forms and should not be construed as necessarily limited to the exemplary embodiments shown herein. Rather, these exemplary embodiments are provided merely to illustrate the invention and to convey its spirit and essence to those skilled in the art.

[0051] This invention aims to provide an improved vehicle control system and a vehicle control method executed by the vehicle control system. The vehicle control system according to the invention is applicable to vehicles with a domain controller centralized architecture (also referred to as a domain controller centralized electronic and electrical architecture), and due to its novel design, it can significantly improve the reliability and safety of vehicles with the aforementioned architecture during operation. Specifically, unlike the distributed architecture of electronic control units (ECUs), in the centralized architecture of domain controllers, numerous ECUs are divided into various regions according to function or area, and controlled by the domain controllers (DCUs) of each region. That is, the software of each ECU is transferred to the domain controller of its respective region, and the domain controller processes the data from various sensors on behalf of the ECUs within that region. This achieves decoupling of the ECU hardware and software. The vehicle control system according to the present invention can verify the compatibility between the software stored in the domain controller and the corresponding ECU hardware before the domain controller controls each ECU, thereby avoiding a series of problems caused by software-hardware incompatibility, such as hardware failure, hardware malfunction, etc., especially when it comes to braking and power ECUs, it can avoid safety issues caused by such incompatibility. In summary, the vehicle control system according to the present invention can perform handshake verification between the software and hardware of each ECU, thereby significantly improving the reliability and safety of the vehicle during operation.

[0052] The following describes in detail, with reference to the accompanying drawings, optional but non-limiting embodiments of the vehicle control system and vehicle control method according to the invention, which can achieve the various advantages of the vehicle control system and vehicle control method according to the invention, both mentioned and unmentioned.

[0053] refer to Figure 1 The diagram shows a schematic layout of an onboard control system according to one embodiment of the present invention. Figure 1As shown, vehicle 10 includes a body 100 and an onboard control system 200 mounted on the body 100. The onboard control system 200 includes multiple domain controllers 210a-e and multiple electronic control units 220. Specifically, each domain controller 210a-e is connected to some of the multiple electronic control units 220 via signals and stores multiple control software or control programs, wherein each control software is used to control one of the multiple electronic control units 220. In this configuration, each domain controller 210a-e and the multiple electronic control units 220 it controls can form a regional control platform, thereby realizing the functions of various regions of the vehicle. For example, in... Figure 1 In the illustrated embodiment, the vehicle is divided into multiple functional domains according to its functions. That is, multiple electronic control units with similar functions are integrated into one functional domain so that the domain controller can perform similar operations to control the various electronic control units. Therefore, the above architecture can also be called a centralized functional domain controller architecture. The multiple functional domains may include a power domain, chassis domain, body domain, cockpit domain, and autonomous driving domain. Each functional domain is provided with a corresponding domain controller, namely, a power domain controller 210a that controls the vehicle's powertrain, a chassis domain controller 210b that controls the vehicle's driving behavior and driving posture, a body domain controller 210c that controls various body functions, a cockpit domain controller 210d that controls various electronic information system functions in the cockpit, and an autonomous driving domain controller 210e that controls autonomous driving functions. Each domain controller 210a-e realizes various functions of the vehicle by controlling the corresponding multiple electronic control units 220. For example, the power domain controller 210a controls the power battery electronic control unit, the engine electronic control unit, etc., and the chassis domain controller 210b controls the steering assist electronic control unit, the braking electronic control unit, etc. Since the domain controller processes sensor parameters in place of the individual electronic control units, it can achieve comprehensive processing of various sensor parameters and centralized and full utilization of chip computing power compared to the distributed architecture of electronic control units.

[0054] refer to Figure 2 The diagram illustrates a schematic layout of an in-vehicle control system according to another embodiment of the present invention. Figure 1 The implementation shown differs in that, by merging the various functional domains, the functional domain controller can be upgraded to a more powerful and versatile position domain controller. Due to its superior computing power, this position domain controller no longer needs to perform similar calculations, thus enabling it to control multiple electronic control units that are geographically close but may have different functions. Specifically, as... Figure 2As shown, the vehicle is no longer divided by function, but by location into multiple location domains. This means that multiple electronic control units (ECUs) in close proximity are integrated into one location domain, allowing the domain controller to perform calculations to control these ECUs. Therefore, this architecture can also be called a centralized location domain controller architecture. These multiple location domains can include a front left domain, a front right domain, a rear left domain, and a rear right domain. Each location domain has a corresponding domain controller: a front left domain controller 210f controls the ECUs on the front left side of the vehicle; a front right domain controller 210g controls the ECUs on the front right side; a rear left domain controller 210h controls the ECUs on the rear left side; and a rear right domain controller 210i controls the ECUs on the rear right side. Each domain controller 210f-i controls its corresponding multiple ECUs 220 to implement various vehicle functions. Because the domain controllers connect to ECUs in close proximity, wiring harnesses can be arranged nearby, communication interfaces can be reduced, and hardware expansion is easier. New hardware can be connected to the corresponding domain controller based on its location.

[0055] It is worth mentioning that, although in both architectures described above, the domain controller is only connected to the electronic control unit, this is merely an example. The domain controller can also be connected to other components with similar functions (in a functional domain controller centralized architecture) or similar locations (in a location domain controller centralized architecture) as needed, and this obviously also falls within the protection scope of this invention.

[0056] Because the software controlling each electronic control unit (ECU) is stored in its respective domain controller, each ECU can use standard components, which facilitates the implementation of a software-defined vehicle. However, regardless of the domain controller centralized architecture, software-hardware compatibility is required to ensure the reliable implementation of each function. Therefore, at least one domain controller 210 of the vehicle control system 200 is configured to perform the following operations to determine whether at least one associated ECU 220 is a matched ECU:

[0057] S100: Send a security seed to the electronic control unit 220;

[0058] S200: Calculates a security key based on a security seed, for example, through a cryptographic algorithm, and controls the electronic control unit 220 to calculate the security key based on the security seed;

[0059] S300: Compare the security key calculated by itself with the security key calculated by the electronic control unit 220;

[0060] S400: If the two security keys match, the electronic control unit 220 is determined to be a matched electronic control unit, and the electronic control unit 220 is controlled by its own stored software;

[0061] S500: If the two security keys do not match, it is determined that the electronic control unit 220 is not a matched electronic control unit, and the electronic control unit 220 is locked or the signal connection with the electronic control unit 220 is disconnected; and

[0062] The matching electronic control unit may store the same cryptographic algorithm and is configured to: calculate a security key using the same cryptographic algorithm based on a security seed from the domain controller 210, and send the security key to the domain controller 210.

[0063] In the above configuration, the domain controller 210 and the electronic control unit (ECU) whose software is matched with it (hereinafter referred to as the matched ECU) are pre-loaded with the same cryptographic algorithm. Therefore, they can calculate the same security key based on the same security seed (and possibly the same random parameters, such as time, event, etc.). Thus, if the domain controller 210 determines that a certain ECU 220 is a matched ECU, the domain controller 210 can control the ECU 220 through its own stored software to enable it to start and run normally. However, if a certain ECU 220 is not a matched ECU, then the ECU 220 will at least not be loaded with the same cryptographic algorithm, and therefore cannot generate the same security key. This will also cause the domain controller 210 to determine that the ECU 220 is not a matched ECU and lock or disconnect its signal connection. Therefore, under the above configuration, the domain controller 210 will only control the matched electronic control units to allow them to start and run, while locking the mismatched electronic control units or disconnecting their signal connection to prevent them from starting. This can avoid a series of problems caused by software and hardware mismatch (such as steering assist malfunction or even brake failure), thereby significantly improving the reliability and safety of the vehicle.

[0064] Specifically, S400 further includes: informing the driver that the electronic control unit 220 has started successfully, and / or sending a start-success signal to the electronic control unit 220. Specifically, S500 further includes: informing the driver that the electronic control unit 220 has failed to start, and / or sending a start-failure signal to the electronic control unit 220. With the above configuration, the driver can be promptly informed whether the electronic control unit 220 has started successfully.

[0065] According to an optional embodiment of the present invention, S100 involves: if a start request is received from the electronic control unit 220 within a predetermined time T after the vehicle starts, a safety seed is sent to the electronic control unit 220; if no start request is received from the electronic control unit 220 within the predetermined time T after the vehicle starts, it is determined that the electronic control unit 220 is not a matched electronic control unit, and the signal connection between the electronic control unit 220 and the electronic control unit 220 is locked or disconnected. Furthermore, the matched electronic control unit is also configured to send a start request to the domain controller 210 after the vehicle starts.

[0066] If a certain electronic control unit 220 is not a matched electronic control unit, then that electronic control unit 220 may not issue a start request at all. The above configuration takes this situation into account. Under the above configuration, the domain controller 210 can start timing after the vehicle starts. If no start request is received by the time the timing t reaches the predetermined time T, it is assumed that the electronic control unit 220 will not issue a start request. Therefore, the domain controller 210 determines that the electronic control unit 220 is not a matched electronic control unit and resets the timing t to zero. Of course, it will also lock or disconnect the signal connection with the electronic control unit 220. Conversely, if the domain controller 210 receives a start request from the electronic control unit 220 within the predetermined time T, it will also reset the timing t to zero and perform the judgment as described above. It is worth mentioning that the predetermined time T can be preset according to parameters such as the general reaction time of the electronic control unit and the driver's patience time.

[0067] According to an optional embodiment of the present invention, S100 involves sending a security seed to the electronic control unit 220 if a start request is received from the electronic control unit 220; and S500 involves determining that the electronic control unit 220 is not a matched electronic control unit if the number of times the security seed is sent reaches a predetermined number N and the two security keys are inconsistent, and locking or disconnecting the signal connection between the electronic control unit 220 and the matched electronic control unit 220. Furthermore, the matched electronic control unit is configured to send a start request to the domain controller 210 after the vehicle is started.

[0068] With the above configuration, mismatched electronic control units (ECUs) can be prevented from sending multiple boot requests in an attempt to force a start. For example, if the predetermined number of attempts N is set to 3, the ECU can only attempt to start a maximum of three times. If the third attempt still fails to generate the correct security key, the ECU will be locked or disconnected from the domain controller 210. Of course, if the correct security key is generated within three attempts, the ECU can start and operate normally.

[0069] In particular, the S500 also informs the driver that the number of startup attempts of the electronic control unit 220 has exceeded the limit.

[0070] Specifically, the operations performed by domain controller 210 also include:

[0071] S600: If the number of times the security seed is sent is less than the predetermined number N and the two security keys are inconsistent, a startup failure signal is sent to the electronic control unit 220. Additionally, the matching electronic control unit is configured to send a startup request to the domain controller 210 again if a startup failure signal is received.

[0072] Even a matched electronic control unit (ECU) may fail to generate or send the correct security key due to interference with the signal connection to the domain controller. With the above configuration, the matched ECU also has multiple startup attempts, thus ensuring successful startup.

[0073] According to an optional embodiment of the present invention, both the domain controller 210 and the matching electronic control unit are integrated with a hardware security module, and the security seed and the cryptographic algorithm both originate from the hardware security module. In this configuration, since the hardware security module can generate more complex security seeds and calculate security keys using more complex cryptographic algorithms, it can prevent mismatched electronic control units from maliciously reverse-engineering the cryptographic algorithm, thereby further improving the reliability and security of the vehicle.

[0074] According to an optional embodiment of the present invention, the operations performed by the domain controller 210 further include:

[0075] S700: Detect the connection status of the electronic control unit 220. If it is detected that the electronic control unit 220 has been disconnected and reconnected, perform other operations to determine whether the electronic control unit 220 is a matched electronic control unit.

[0076] Under the above configuration, if the electronic control unit 220 is replaced, the domain controller 210 will actively verify whether the electronic control unit 220 is a matching electronic control unit, instead of waiting for the electronic control unit 220 to send a startup request before performing the above verification. This helps operators to promptly identify whether the replaced electronic control unit 220 is a matching electronic control unit.

[0077] According to an optional embodiment of the present invention, the vehicle control system 200 includes a chassis domain controller 210b and a brake electronic control unit signal-connected to the chassis domain controller 210b. The chassis domain controller 210b is configured to perform the operation of determining whether the brake electronic control unit is a matched electronic control unit. Since vehicle safety is primarily affected by braking performance, the above configuration can ensure the reliable realization of vehicle braking performance, thereby ensuring vehicle safety.

[0078] According to an optional embodiment of the invention, each domain controller 210 of the vehicle control system 200 is configured to perform the operation to determine whether each electronic control unit 220 associated with it is a matched electronic control unit. Under this configuration, the matching electronic control units 220 associated with each domain controller 210 can be comprehensively verified, thereby maximizing the reliability and safety of the vehicle.

[0079] It is worth noting that although different combinations and variations of the operations performed by the domain controller have been described above in different embodiments, these combinations and variations can be combined with each other to form implementations not described herein, provided they do not contradict each other. For example, an implementation that limits the sending time of startup requests can be combined with an implementation that limits the number of times startup requests are sent. Those skilled in the art will understand that these undescribed implementations also fall within the scope of protection of this invention. Furthermore, the order in which these operations are described does not represent the order in which they are executed. Where there is no contradiction, these operations can be executed in any order or simultaneously.

[0080] Corresponding to the various operations performed by the domain controllers described above, this invention also proposes a vehicle control method performed by an onboard control system. (See reference) Figure 3 The diagram illustrates a schematic flowchart of a vehicle control method according to one embodiment of the present invention. Figure 3 As shown, the vehicle control method is executed by at least one domain controller 210 of the vehicle control system to determine whether at least one electronic control unit 220 associated therewith is a matched electronic control unit, and includes the following steps:

[0081] S10: Domain controller 210 sends a security seed to electronic control unit 220;

[0082] S20: Domain controller 210 calculates a security key based on a security seed (e.g., via a cryptographic algorithm) and controls electronic control unit 220 to calculate a security key based on the security seed;

[0083] S30: Domain controller 210 compares the security key it calculates with the security key calculated by electronic control unit 220. If the two security keys match, proceed to S40; if the two security keys do not match, proceed to S50.

[0084] S40: Domain controller 210 determines that electronic control unit 220 is a matched electronic control unit and controls electronic control unit 220 through its own stored software;

[0085] S50: Domain controller 210 determines that electronic control unit 220 is not a matched electronic control unit, and locks or disconnects the signal connection between electronic control unit 220 and electronic control unit 220; and

[0086] The matching electronic control unit may store the same cryptographic algorithm and is configured to: calculate a security key using the same cryptographic algorithm based on a security seed from the domain controller 210, and send the security key to the domain controller 210.

[0087] Specifically, S40 further comprises: the domain controller 210 informing the driver that the electronic control unit 220 has started successfully, and / or sending a start-up success signal to the electronic control unit 220. Specifically, S50 further comprises: the domain controller 210 informing the driver that the electronic control unit 220 has failed to start, and / or sending a start-up failure signal to the electronic control unit 220.

[0088] refer to Figure 4 The diagram illustrates a schematic flowchart of a vehicle control method according to another embodiment of the present invention. Figure 4 As shown, the vehicle control method also includes the following steps:

[0089] S01: Timing starts after the vehicle is started;

[0090] S02: If the domain controller 210 receives a start request from the electronic control unit 220 within a predetermined time T after the vehicle starts, then execute S10; if the domain controller 210 does not receive a start request from the electronic control unit 220 within the predetermined time T after the vehicle starts, then execute S50; and

[0091] The matching electronic control unit is also configured to send a start request to the domain controller 210 after the vehicle is started.

[0092] refer to Figure 5 The diagram illustrates a schematic flowchart of a vehicle control method according to yet another embodiment of the present invention. Figure 5As shown, S30 involves: the domain controller 210 comparing the security key it calculates with the security key calculated by the electronic control unit 220; if the two security keys match, then S40 is executed; if the number of attempts n < the predetermined number N, and the two security keys do not match, then S03 is executed; if the number of attempts n = the predetermined number N, and the two security keys do not match, then S50 is executed; and the vehicle control method further includes the following steps:

[0093] S03: Increase the number of attempts n by 1;

[0094] S04: If the domain controller 210 receives a startup request from the electronic control unit 220, then return to S10; if the domain controller 210 does not receive a startup request from the electronic control unit 220, then execute S50.

[0095] S40 and S50 both involve: resetting the number of attempts n to zero; and

[0096] The matching electronic control unit is also configured to send a start request to the domain controller 210 after the vehicle is started.

[0097] Specifically, S03 also includes: sending a start failure signal to the electronic control unit 220; and

[0098] The matching electronic control unit is further configured to send a startup request to the domain controller 210 again after receiving a startup failure signal.

[0099] In particular, S50 also includes the following: the domain controller 210 informs the driver that the number of startup attempts of the electronic control unit 220 has exceeded the limit.

[0100] refer to Figure 6 A schematic flowchart of a vehicle control method according to another embodiment of the present invention is shown. Figure 6 As shown, the vehicle control method also includes the following steps:

[0101] S05: Domain controller 210 detects the connection status of electronic control unit 220;

[0102] S06: If the domain controller 210 detects that the electronic control unit 220 has been disconnected and reconnected, then execute S10; if the domain controller 210 does not detect that the electronic control unit 220 has been disconnected and reconnected, then return to S05.

[0103] Specifically, the vehicle control method is executed by the chassis domain controller 210b of the onboard control system to determine whether the associated braking electronic control unit is a matched electronic control unit.

[0104] Specifically, the vehicle control method is executed by each domain controller 210 of the vehicle control system to determine whether each electronic control unit 220 associated with it is a matched electronic control unit.

[0105] The foregoing has described in detail, with reference to the accompanying drawings, optional but non-limiting embodiments of the vehicle control system and vehicle control method according to the present invention. For those skilled in the art, modifications and additions to the technology and structure, as well as recombinations of features in the various embodiments, should obviously be considered within the scope of the invention without departing from the spirit and essence of this disclosure. Therefore, such modifications and additions conceivable under the teachings of this invention should be considered part of the invention. The scope of the invention includes equivalent technologies known at the time of filing and equivalent technologies not yet foreseen.

Claims

1. An onboard control system comprising at least one domain controller and at least one electronic control unit (ECU) signal-connected to the domain controller, the domain controller storing software for controlling the ECU and configured to perform the following operations: Send a security seed to the electronic control unit; The security key is calculated based on the security seed, and the electronic control unit is controlled to calculate the security key based on the security seed. The system compares the security key it calculates with the security key calculated by the electronic control unit. If the two security keys match, the electronic control unit is determined to be a matched electronic control unit that matches the software stored in the domain controller, and the electronic control unit is controlled by the stored software. as well as If the two security keys do not match, it is determined that the electronic control unit is not a matching electronic control unit, and the electronic control unit is locked.

2. The vehicle control system according to claim 1, wherein, The domain controller and the matching electronic control unit store the same cryptographic algorithm and are configured to calculate a security key based on a security seed using the cryptographic algorithm.

3. The vehicle control system according to claim 2, wherein, Both the domain controller and the matching electronic control unit are integrated with a hardware security module, and the security seed and the cryptographic algorithm both originate from the hardware security module.

4. The vehicle control system according to any one of claims 1 to 3, wherein, The domain controller is also configured to: if it determines that the electronic control unit is a matched electronic control unit, inform the driver that the electronic control unit has started successfully, and / or send a start success signal to the electronic control unit.

5. The vehicle control system according to any one of claims 1 to 4, wherein, The domain controller is also configured to: inform the driver of the electronic control unit startup failure if it is determined that the electronic control unit is not a matched electronic control unit, and / or send a startup failure signal to the electronic control unit.

6. The vehicle control system according to any one of claims 1 to 5, wherein, The domain controller is further configured to: send a security seed to the electronic control unit if a start request is received from the electronic control unit within a predetermined time after the vehicle starts; and determine that the electronic control unit is not a matched electronic control unit if no start request is received from the electronic control unit within the predetermined time after the vehicle starts; and wherein the matched electronic control unit is further configured to: send a start request to the domain controller after the vehicle starts.

7. The vehicle control system according to any one of claims 1 to 5, wherein, The domain controller is also configured to: if a start request is received from the electronic control unit, send a security seed to the electronic control unit; if the number of times the security seed is sent reaches a predetermined number and the two security keys are inconsistent, determine that the electronic control unit is not a matched electronic control unit; and wherein the matched electronic control unit is further configured to: send a start request to the domain controller after the vehicle is started.

8. The vehicle control system according to claim 7, wherein, The domain controller is also configured to inform the driver that the number of times the electronic control unit has been attempted to start has exceeded the limit if it is determined that the electronic control unit is not a matched electronic control unit.

9. The vehicle control system according to claim 7 or 8, wherein, The domain controller is further configured to send a startup failure signal to the electronic control unit if the number of times the security seed is sent is less than a predetermined number and the two security keys are inconsistent; and the matching electronic control unit is further configured to send a startup request to the domain controller again if it receives the startup failure signal.

10. The vehicle control system according to any one of claims 1 to 9, wherein, The domain controller is also configured to detect the connection status of the electronic control unit, and if it detects that the electronic control unit has been disconnected and reconnected, then perform the operation.

11. The vehicle control system according to any one of claims 1 to 10, comprising a plurality of domain controllers, each domain controller being signal-connected to a plurality of electronic control units and configured to perform the operation for each electronic control unit.

12. The vehicle control system according to any one of claims 1 to 10, comprising a chassis domain controller, the chassis domain controller being signal-connected to the brake electronic control unit and configured to perform the operation for the brake electronic control unit.

13. A vehicle control method, executed by an on-board control system according to any one of claims 1-12, and comprising the following steps: S10: The domain controller sends a security seed to the electronic control unit; S20: The domain controller calculates the security key based on the security seed, and controls the electronic control unit to calculate the security key based on the security seed; S30: The domain controller compares the security key it calculates with the security key calculated by the electronic control unit. If the two security keys match, proceed to S40; if the two security keys do not match, proceed to S50. S40: The domain controller determines that the electronic control unit is a matched electronic control unit that matches the software stored in the domain controller, and controls the electronic control unit through the stored software; and S50: The domain controller determines that the electronic control unit is not a matched electronic control unit and locks the electronic control unit.

14. The vehicle control method according to claim 13, further comprising the following steps: S01: Timing starts after the vehicle is started; as well as S02: If the domain controller receives a start request from the electronic control unit within a predetermined time after vehicle startup, then execute S10; if the domain controller does not receive a start request from the electronic control unit within the predetermined time after vehicle startup, then execute S50; and The matching electronic control unit is also configured to send a start request to the domain controller after the vehicle is started.

15. The vehicle control method according to claim 13 or 14, wherein, S30 is as follows: The domain controller compares the security key it calculates with the security key calculated by the electronic control unit. If the two security keys match, then S40 is executed; if the number of attempts is less than the predetermined number and the two security keys do not match, then S03 is executed; if the number of attempts reaches the predetermined number and the two security keys do not match, then S50 is executed. Both S40 and S50 also involve: resetting the number of attempts to zero; and The vehicle control method also includes the following steps: S03: Increase the number of attempts by 1; and S04: If the domain controller receives a startup request from the electronic control unit, return to S10; if the domain controller does not receive a startup request from the electronic control unit, execute S50; and The matching electronic control unit is also configured to send a start request to the domain controller after the vehicle is started.

16. The vehicle control method according to claim 15, wherein, S03 also includes: sending a start failure signal to the electronic control unit; and The matching electronic control unit is further configured to send a startup request to the domain controller again if a startup failure signal is received.

17. The vehicle control method according to any one of claims 13-16, further comprising the following steps: S05: The domain controller detects the connection status of the electronic control unit; and S06: If the domain controller detects that the electronic control unit has been disconnected and reconnected, then execute S10; otherwise, return to S05.

18. A domain controller configured to be signal-connected to at least one electronic control unit, the domain controller storing software for controlling the electronic control unit and configured to perform the following operations: Send a security seed to the electronic control unit; The security key is calculated based on the security seed, and the electronic control unit is controlled to calculate the security key based on the security seed. The system compares the security key it calculates with the security key calculated by the electronic control unit. If the two security keys match, the electronic control unit is determined to be a matched electronic control unit that matches the software stored in the domain controller, and the electronic control unit is controlled by the stored software. as well as If the two security keys do not match, it is determined that the electronic control unit is not a matching electronic control unit, and the electronic control unit is locked.

Citation Information

Patent Citations

  • On-vehicle diagnosis security verification method

    CN102255901A

  • Unlocking and locking control method and system for electronic steering lock

    CN116767138A