Vehicle control unit comprising a separation system for at least one security-related network line over network
By designing a separation system in the vehicle control unit, limiting the output transmission of the communication equipment, and cutting off the power supply of the safety-related actuator, the problem of difficulty in effectively protecting the vehicle control unit in the case of a network attack in the prior art is solved, and higher security and resource optimization are achieved.
Patent Information
- Application Number
- CN202411674327.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-11-21
- Publication Date
- 2025-05-23
AI Technical Summary
In the prior art, when protecting the security-related communication network of a vehicle control unit, it is difficult to effectively protect in the event of a network attack, and the protection measures are complex and resource consumption is large.
A separation system is designed for at least one security-related network line, through the coordinated work of the hardware security module and the logic operator, limit the output transmission of the communication device, prevent the propagation of malicious messages, and cut off the power supply of the security-related actuator when a network security abnormality is detected.
It effectively prevents the spread of malicious messages through network attacks, improves the security of vehicle control units, simplifies the security update and detection process, and optimizes the management resources of the communication network.
Smart Images

Figure CN120034350A_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This patent application claims the priority of Italian Patent Application No. 102023000024639 filed on November 21, 2023, the entire disclosure of which is incorporated herein by reference. Technical Field
[0003] The invention relates to a vehicle control unit comprising a separation system for at least one safety-relevant network line due to a cyber attack and to an associated road vehicle.
[0004] In more detail, the invention may advantageously, but not exclusively, be applied to high performance road vehicles (eg fully electric or hybrid road vehicles), to which explicit reference will be made in the following description without loss of generality. Background Art
[0005] Thermal vehicles as well as hybrid or electric vehicles (EV / PHEV / BEV) are known which are provided with at least one electric machine which is electrically connected to an electric power storage system, ie a battery pack, and mechanically connected to drive wheels in order to transmit torque to the drive wheels.
[0006] The electrical system of a hybrid vehicle or electric vehicle generally includes a circuit with high voltage (relatively speaking, it can also have a nominal voltage of only 48 volts) and high power, to which the motor is connected; the high voltage circuit includes a storage device (provided with at least one electrochemical battery pack, such as lithium-ion or polymer batteries) and a bidirectional DC-AC electronic power converter, which is connected to the storage device on the DC side and to the motor on the AC side and realizes the function of controlling the motor.
[0007] The electrical system of these vehicles also includes an electrical circuit with a low voltage (typically with a nominal voltage of 12 volts) to which all auxiliary power services - for example, control units of all vehicle subsystems, infotainment systems, anti-theft systems, passenger compartment lighting systems, exterior lights, the electric starter motor of the thermal engine in the case of hybrid vehicles, etc. - are connected.
[0008] Among other things, the low voltage circuit usually also includes a so-called BMS (Battery Management System) of a high voltage storage device.
[0009] The low voltage circuit also powers one or more vehicle control units (also called VCUs) which act as interfaces between the various control units and their respective systems. These control units are responsible for controlling the communications between the various vehicle systems. These communications occur over one or more known networks such as CAN networks (Controller Area Networks), LIN networks (Local Interconnect Networks), Ethernet or other networks that require special wiring to communicate with the above control units.
[0010] The aforementioned VCUs are subject to increasingly stringent safety requirements, since they control, for example, CAN lines that interact with safety-related actuators (eg, the aforementioned electric motors, brakes, steering wheels, active suspension, other vehicle electric motors, etc.).
[0011] It is well known that commercial vehicles are increasingly connected to the Internet, which increasingly exposes them to malicious cyber attacks.
[0012] In particular, as far as cybersecurity is concerned, there are some possibilities for generating malicious attack paths by exploiting the so-called "cascading", i.e. the connection between one control unit and another. In particular, messages different from those actually sent by the upstream control unit are maliciously injected into the downstream control unit, replacing or overwriting certain information communications between the control units. If the information content of these communications is a command or trigger that initiates a reaction, it may cause an undesired behavior of the product (in this case, the vehicle), thus compromising not only its cybersecurity but also - as a rule - the safety of the users on board the vehicle, who may have undesired, even serious, behavior, given that all the essential safety equipment is controlled by these control units.
[0013] The importance of managing possible cyber attacks against vehicle control units is obvious.
[0014] To date, the most important control units each include their own hardware and software security systems that recognize possible cyber attacks and block them. Some known examples include the compilation of known monitoring software in specific modules that are specially shielded in terms of security, known as HSM (Hardware Security Module) or SHE (Secure Hardware Extension) or even HTA (Hardware Trust Anchor) and finally TPM (Trusted Platform Module).
[0015] However, the decentralization of these safety systems would require constant updating of all control units, which would have to be revalidated after each update and testing. This results in significant expenditure in terms of economic and time resources.
[0016] In general, therefore, there is a need to improve the protection of safety-related communication networks, especially in the event of a cyberattack. At the same time, it is important to avoid overloading the control units, whose number of communication lines is still limited. Furthermore, since they are critical components, it is also important not to distort their previously proven architecture. Summary of the invention
[0017] The object of the invention is to provide a vehicle control unit comprising a separation system for at least one safety-relevant network line due to a cyber attack and a related road vehicle which are at least partially free from the above-mentioned disadvantages and which at the same time are simple and economical to manufacture and implement.
[0018] According to the present invention, a vehicle control unit and an associated road vehicle are provided as claimed in the associated independent claim attached hereto and preferably, but not necessarily, in any dependent claim directly or indirectly dependent on the independent claim, the vehicle control unit comprising a separation system for at least one safety-related network line due to a cyber-attack.
[0019] The appended claims describe preferred embodiments of the invention and form an integral part of the description. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In the following, some embodiments of the invention will be described by way of non-limiting examples and with reference to the accompanying drawings, in order to allow a better understanding of the invention, in which:
[0021] - Figure 1 is a schematic perspective view of a road vehicle according to an embodiment of the invention, with details omitted for greater clarity;
[0022] Figure 2 yes Figure 1 Schematic diagram of a non-limiting embodiment of an electrical system of a road vehicle. DETAILED DESCRIPTION
[0023] exist Figure 1 , numeral 1 generally indicates a road vehicle having two front wheels 2 and two rear wheels 3, at least one pair of which (or all) receive torque from an electric or hybrid powertrain system 4. The powertrain system 4 is preferably, but not in a limiting manner, purely electric (i.e. comprising only one or more electric motors) or hybrid (i.e. comprising an internal combustion heat engine and at least one electric motor).
[0024] In the drawings, the same numerals and the same reference letters represent the same elements or components having the same function.
[0025] For the purposes of the present invention, the term "second" component does not imply the existence of a "first" component. In fact, these terms are only used as labels to improve clarity and should not be construed in a limiting manner.
[0026] The elements and features included in different preferred embodiments, including the accompanying drawings, may be combined with each other without thereby exceeding the scope of protection of this patent application, as described below.
[0027] In particular, the road vehicle 1 includes an electrical system 5, which includes: a high-voltage HV circuit 6 (relatively speaking), which, for example, has a nominal voltage of 800 or 400 or 48 volts in a non-limiting manner; and a low-voltage LV circuit 7, which, for example, has a nominal voltage of 12 volts.
[0028] It should be noted that the circuit 6 is defined as a "high-voltage" circuit because it has a nominal voltage (800V, 400V, 48V) greater than the nominal voltage (12V) of the circuit 7, that is, the definition of "high voltage" should be interpreted as relating to the separate electrical system 5 and relative to the circuit 7 having a nominal voltage of 12 volts.
[0029] According to some preferred non-limiting embodiments, the low-voltage LV circuit 7 includes an electrical energy storage system 8 (which obviously has the same voltage as the circuit 7), that is, a battery, such as a lead or lithium-ion battery. In addition, the low-voltage LV circuit 7 includes a plurality of electrical loads 9, each of which is designed to absorb only the electrical energy required for its own operation (that is, these electrical loads 9 are not capable of generating electrical energy). In other words, the storage system 8 is configured to supply power to the plurality of electrical loads 9.
[0030] Advantageously, but not necessarily, the successive electrical loads 9 include, for example, an alarm system, an infotainment system, an inverter and / or a BMS and / or a steer-by-wire electronic control unit 39, an active suspension, external lights, an air conditioning system (not shown), the drive of the windows, a radio, a navigation system, etc. As emphasized in the introduction of the specification, some of the electrical loads 9 (for example, via the CAN network described below) are safety-related actuators 10, such as motors for moving the vehicle, brakes, steering wheels, active suspensions, etc.
[0031] In addition, the road vehicle 1 includes a vehicle network 11 that can be based on one or more known communication protocols (which will not be further detailed), such as CAN (shown in a non-limiting embodiment in Figure 2 ), LIN or Ethernet. Obviously, other types of vehicle networks or combinations of the above networks can also be used.
[0032] The vehicle network 11 is configured to establish (data) communication between the above-mentioned electrical loads 9 and corresponding control units (known and not described in detail below) and between the latter and at least one control unit 12 of the type described below. In particular, in view of the above, it is also particularly relevant for the safety of the driver and possible passengers that the control units 12, 39 and - in general - all vehicle loads 9 are also protected from the perspective of cybersecurity, which, if compromised during operation of the vehicle 1, could also lead to malfunctions or blockages of some vehicle systems.
[0033] In practice, the road vehicle 1 comprises a control unit 12 which is powered by the low-voltage circuit 7 , in particular by the storage system 8 .
[0034] The control unit 12 is preferably a dominant control unit (also called vehicle control unit or VCU for short), in particular for connecting to a vehicle network 11, more particularly for example to a CAN network. In detail, the control unit 12 controls the communication of other vehicle control units placed at a lower logic level on the vehicle network 11. In other words, the VCU 12 serves as a dominant controller of the preferably electric or hybrid road vehicle 1. For example, without limitation, the control unit 12 is configured to read signals of sensors mounted on the vehicle (e.g. brakes), the HVIL or a connection to a charger, and act accordingly in order to balance the energy of the system, optimize torque, control the motor (i.e. electric machine), the high voltage (HV) battery pack and the on-board charging system until the charger is blocked.
[0035] The control unit 12 comprises two macro elements.
[0036] The first macro element is a processing device 13 , in particular a microcontroller 14 , which is configured and programmed to process output data sets OD during normal operation as a function of input data sets ID coming from at least one vehicle network 11 .
[0037] A second macro element is a communication device 15 , in particular a transceiver 16 , bidirectionally connected to the processing device 13 and the vehicle network 11 .
[0038] The communication device 15 is configured to receive input data sets ID from the at least one vehicle network 11 and transmit them to the processing device 13, and to receive output data sets OD from the processing device and transmit them to the vehicle network 11. In other words, the communication device 15 represents a circuit allowing the microcontroller 14 to work and communicate with the rest of the road vehicle 1 (and therefore with the electrical loads 9) on the vehicle network 11 (for example on a CAN network).
[0039] In particular, it is important to avoid the transmission device 15 from transmitting malicious or incorrect messages to one or more auxiliary control units 39 connected to the master control unit 12, or from not transmitting safety-critical messages.
[0040] The communication device 15 is also configured to operate selectively between a transmission mode ST and a standby mode. In the transmission mode ST, the communication device 15 communicates freely with the vehicle network 11 (during normal functional operation) and the auxiliary unit 39 bidirectionally. In the standby mode, the communication device 15 can only receive signals from the vehicle network 11 (when the vehicle is turned off, for example, after turning the key, or in the case of problems with the processing device 13, as discussed in more detail below).
[0041] Advantageously, the control unit 12, in particular the processing device 13 (i.e., the microcontroller 14), includes a hardware security module 30 configured to detect network security anomalies.
[0042] Advantageously, the control unit 12 includes a separation system 19 for at least some lines of the vehicle network 11 relevant in terms of security (e.g., CAN-like, for the auxiliary control unit).
[0043] In particular, the security module is a hardware trust anchor HTA module (of a known type and not described in detail below).
[0044] For example, within the HTA module, network security software mechanisms are assigned precisely because it is specifically protected and isolated within the microcontroller 14. These mechanisms intercept attacks by interrupting or sending signals that disable communication with the auxiliary unit 39 to be protected (or multiple auxiliary units 39 if necessary), as described below. In this way, attacks on the auxiliary unit 39 are not only insecure in terms of network security but also in terms of the safety of the driver or passengers of the road vehicle. In other words, the control unit 12 implements a protection mechanism upstream of the control unit to be protected, imposing a barrier that prohibits attacks from passing through by spreading malicious messages / instructions (cascading).
[0045] In particular, the network security software mechanisms (of a known type and not further detailed below, also because they are highly dependent on the vehicle model and corresponding critical aspects) are conceptual mechanisms based on the protection of the protocol (i.e., the information content exchanged between the control unit 12 and the functional auxiliary unit 39 for the functionality of the road vehicle 1). For example, these mechanisms can include: monitoring the timing of information exchange between the control unit 12 and the auxiliary unit 39 or the degree of congestion of the vehicle network 11 (e.g., CAN network), which provides for the exchange of information messages within a substantially predetermined time that should not change by more than a specific threshold, except in the presence of network attacks.
[0046] The separation system 19 is configured to restrict the communication device 15 to a (separate) standby mode in the event of an abnormality in the processing device 13 or a network security abnormality detected by the hardware security module 30 .
[0047] In other words, in the event of a fault in the microcontroller 14, or in the event of a threat detected by the software contained in the HTA, the partitioning system 19 blocks the outgoing transmission from the communication device 15. In this way, non-warranted messages that could compromise the safety of the road vehicle 1 are not propagated to other vehicle control units or electrical loads 9.
[0048] Thus, in particular, the road vehicle 1 comprises a plurality of auxiliary control units 39 connected to the control unit 12 , the safety of these auxiliary control units 39 being entirely entrusted to the partitioning system 19 , in particular the safety module.
[0049] According to some non-limiting embodiments not shown here, the partitioning system 19 is configured to restrict the communication device 15 to a (separate) standby mode even in the event of an anomaly in the auxiliary processing device 17. In other words, the partitioning system 19 blocks output transmissions from the communication device 15 in the event of a malfunction in at least one of the microcontroller 14 and the companion chip 18 (except for the possibility of a network attack detected by the security module 30).
[0050] Preferably, but not by way of limitation, as described below, the control unit 12 also comprises an auxiliary processing device 17 , in particular an auxiliary / companion chip 18 , which monitors the operation of the processing device 13 and the supply of power to the communication device 15 .
[0051] Therefore, as mentioned above, the control unit 12 is preferably a VCU that also operates according to functional safety. Therefore, the information exchanged on the vehicle network 11 can be of great value for the safety of the vehicle and its users. Thanks to the partitioning system 19, the outgoing communication from the unit 12 (and therefore the transmissions of the transceiver 16) can be selectively enabled or disabled depending on the health state of the control unit 12, in particular the microcontroller 14. Therefore, in addition to the blocks that can be commanded by the HTA, if the microcontroller 14 is not in good health due to its failure or a possible cyber attack, it is prevented from sending incorrect information or instructions to the rest of the road vehicle 1.
[0052] In particular, the partitioning system 19 comprises a first output 21 (physical output, i.e., pin) on the processing device 13 and a first input 22 on the communication device 15 connected to the first output 21. The first input 22 is configured to receive a signal ST from the first output 21 to cause the communication device 15 to receive from the vehicle network 11, i.e., for enabling at least the standby mode.
[0053] Preferably, but not in a limiting way, the enable signal ST is a hardware signal, ie a binary signal transmitted via a cable or a trace.
[0054] Advantageously, but not in a limiting manner, the partitioning system 19 comprises a logic operator 20 comprising at least two inputs connected respectively to the processing device 13 and to the hardware security module 30, and an output connected to the communication device 15. Preferably, but not in a limiting manner, according to an embodiment not shown here, the logic operator 20 comprises a third input connected to the auxiliary processing device 17.
[0055] according to Figure 2 In a preferred non-limiting embodiment, the partitioning system 19 comprises, on the processing device 13, a second output 23 for transmitting an enable signal mEN, and, on the hardware security module, a third output 34 for a network security good health signal ISH (in general, and in particular with respect to the software present in the HTA) of the control unit 12. In detail, the signals emitted by the second output 23 and the third output 34 are concentrated in the logic operator 20, which provides the enable signal EN as an output.
[0056] According to some non-limiting embodiments not shown here, the control unit 12 comprises, on the auxiliary processing device 17, a fourth output 24 for a good health signal SH of the power supply of the processing device 13 or of the auxiliary processing device 17 in general and in particular. In detail, the signal emitted by the fourth output 24 is collected in the logic operator 20 together with the two other signals mEN and ISH.
[0057] In particular, the partitioning system 19 includes a second input terminal 25 on the communication device 15, the second input terminal 25 is connected to the logic operator 20 to receive an enable signal EN, which is configured to enable the communication device 15 to transmit to the vehicle network 11 only when a transmission enable signal mEN from the processing device 13 (i.e., from the microcontroller 14) and a network security good health signal ISH from the control unit 12 (if necessary, also a good health signal SH from the supporting chip 18) coexist, that is, to enable the transmission mode.
[0058] Advantageously, but not in a limiting manner, according to what has been described above, the logic operator 20 is an AND port 26. Obviously, additional or different operators may also be used which achieve substantially the same purpose as described above, namely, being able to selectively disable the output transmission of the transceiver 16 to the vehicle network 11 in the event of a malfunction of the microprocessor 14 or of the hardware security module 30 (or, if necessary, of the companion chip 18, for example due to an incorrect / insufficient power supply, a malfunction or an external attack), in the event of a logic rejection of the signals mEN and ISH (and, if necessary, SH).
[0059] Therefore, preferably, but not in a limiting manner, not only the signals emitted by the second output terminal 23 and the third output terminal 34 are concentrated in the logic operator 20, but also the signal emitted by the fourth output terminal 24 is concentrated in the logic operator 20, thereby affecting the enable signal EN.
[0060] Advantageously, but not in a limiting manner, the low voltage circuit 7 is directly connected to the auxiliary processing device 17 and to the communication device 15. In particular, the auxiliary processing device 17 supervises the correct power supply to the control unit 12, as described above.
[0061] In particular, the vehicle 1 comprises a plurality of safety-related actuators 10 , the power supply of which is affected by a good health signal mSN (voluntary signal, ie for voluntarily disabling the power supply to the actuators 10 ) from a processing supply device 13 and a good health signal SH from an auxiliary processing device 17 .
[0062] Preferably, but not by way of limitation, the auxiliary processing device 17 provides a communication power supply signal CS which allows the communication device 15 to have a stable power supply and in particular to always be powered on reception even if the microcontroller 14 is not operating.
[0063] according to Figure 2 In a preferred but non-limiting embodiment of the invention, the fourth output 24 can be connected (directly, in hardware) to a system 27 for cutting off the vehicle safety actuators 10, which is configured to cut off (i.e. disconnect) the power supply to at least part of the actuators 10 related to vehicle safety in the absence of a good health signal SH. The absence of such a signal may occur, for example, in the event of a problem with the storage system 8 or the associated power supply cables; in such a case, it is suspected that the control unit 12 may not function correctly, and the cutting system 27 is activated by the signal mSH or SH in order to disable the safety-related actuators 10 (for example, by limiting them or disconnecting their power supply).
[0064] exist Figure 2In a non-limiting embodiment, the processing device 13 comprises a fifth (dedicated and separate) output 28 for the good health signal mSH, which can be connected to a system 27 for cutting off the vehicle safety actuator 10, which in the absence of the good health signal mSH (or the good health signal SH) cuts off / disables at least a part of the vehicle safety actuator 10. In this way, in addition to protecting the network security and blocking malicious messages, the safety of the user is improved even in the event of a malfunction.
[0065] According to some preferred non-limiting embodiments not shown herein, the control unit 12 includes a plurality of communication devices 15 (to which the information disclosed above is still applicable with appropriate modifications), which are at least partially connected to the same separation system 19, which constrains the plurality of communication devices 15 to a standby mode in the event of an abnormality in the processing device 13 or a network security abnormality detected by the hardware security module 30 (or, also but not limited to, an abnormality in the auxiliary processing device 17).
[0066] In other words, the disclosed information is considered to be capable of modulation.
[0067] For example, the control unit 12 may include six or seven communication devices 15, some or all of which are disabled from communicating with the outside, for example when the microcontroller 14 does not have a guaranteed operation in general and in particular in terms of network security. Obviously, the communication devices 15 may all belong to the same vehicle network 11, such as a CAN network, or may belong to different networks 11.
[0068] Thus, preferably, but not in a limiting manner, when the microcontroller 14 is not operating correctly, the transceiver 16 can be selectively switched off by means of the signal mEN, which one then preferably disconnects.
[0069] Conversely, in the event of a cyber attack, the module 30 will disable the transceiver 16 in a manner guaranteed by the HTA by means of the signal ISH (ie by making said signal absent from the logic operator 20 ), while preventing all transmissions from the latter to the control unit 39 , thus ensuring that the entire component enters a safe state at vehicle level.
[0070] According to further non-limiting embodiments not shown here, for example to save resources on the control unit, some or all of the connections of the partitioning system 19 can be actual BUS inside the control unit 12. In this way, commands can be merged to several communication devices 15 in a single row. By doing so, the auxiliary control units 39 can be selectively protected, blocking attacks before they can reach them.
[0071] Advantageously, but not in a limiting manner, the signals ISH and mSH are hardware signals controlled by the microcontroller 14 ; in particular, the signal ISH is controlled by the hardware network security module 30 , ie by the HTA. On the other hand, the signal SH is a hardware signal controlled by the auxiliary chip 18 .
[0072] According to the embodiment shown herein, the microcontroller 14 (in particular the HTA) allows the security level to be increased due to the fact that the communication ports of the control unit (i.e., the communication device 15) are blocked from transmitting outputs in order to prevent incorrect and malicious information from being sent to the auxiliary control units 39, i.e., to those control units that are at a lower level in the information transmission.
[0073] Advantageously, but not in a limiting manner, the communication device 15 is configured to receive a wake-up signal WU from the vehicle network 11, which is sent to the auxiliary processing device 17, which in turn sends a reset signal RST to the processing device 13, so as to be able to exit the standby mode by entering the transmission mode. In other words, in the event of a problem or a network attack, the control unit 12 ensures that no erroneous messages or instructions are transmitted to the outside, but is still able to receive erroneous messages or instructions from the outside, so as to be able to wake up possibly.
[0074] exist Figure 2 In a non-limiting embodiment, in order to ensure that the communication device 15 is powered even in the event of a failure of the microprocessor 14, the communication device 15 preferably receives a power supply signal VB from the storage system 8 and a communication power supply signal CS from the companion chip 18. In this way, the companion chip 18 turns off the power supply to the communication device 15, and thus preferably controls and checks it cyclically. By doing so, the (input) communication performed by the communication device 15 can be performed independently of the processing device 13.
[0075] Preferably, but not in a limiting manner, when the power supply is stable, the microcontroller 14 can control the operating state of the transceiver 16 through two signals ST and EN, the former putting the transceiver 16 in a reception-only state, while the enable signal EN enables the transceiver 16 to be fully operational even in transmission.
[0076] According to the above, therefore, a switch-off of the transmission is ensured which, however, is not permanent but can be restored for example due to the will of the driver who, by turning the key or other action, can trigger the wake-up signal WU and thus a reset RST of the microcontroller 14 .
[0077] according to Figure 2In a preferred but non-limiting embodiment, the companion chip 18 is a device which, on the one hand, allows (for example by means of the signal CS) to ensure the correct power supply to the control unit 12 and, on the other hand, has monitoring functions associated with the microcontroller 14.
[0078] Therefore, in detail, the companion chip 18 continuously checks whether the microcontroller 14 is operating normally. This is done by means of the exchange of known Q\A (i.e., so-called question / answer) signals, which are Figure 2 In other words, the companion chip 18 continuously queries the microcontroller 14 and expects a specific answer from the latter. When the microcontroller 14 does not answer or does not answer correctly, the companion chip 18 reacts by signaling the good health signal SH (i.e., by disabling the good health signal SH, thereby indicating that good health no longer exists).
[0079] In this way, in use, the companion chip 18 indicates that anything the microcontroller 14 is doing is not warranted and therefore intervenes by switching off the safety-related actuator 10 and by disabling output transmissions of the transceiver 16, thereby quickly blocking the message output by the microcontroller 16 that it is not working correctly.
[0080] exist Figure 2 In a non-limiting embodiment of the invention, the companion chip 18 can also receive an error signal ER from the microcontroller 14, which is provided by a complex stored (safety) logic inside the microcontroller 14. This error signal ER, which is used, for example, in the event that the microcontroller detects a problem or becomes aware of an external attack, always allows a safety reaction of the type described above to be generated by the companion chip 18.
[0081] As mentioned above, in Figure 2 In a non-limiting embodiment, the companion chip 18 can also send the above reset signal RST to the microcontroller 14 to start waking up the microcontroller 14 normally (when turned on and following the previous constraints to the above standby configuration). In particular, when the companion chip believes that everything is normal at the control unit system level, it allows the microcontroller 14 to start or resume its normal activities.
[0082] Although the invention described above relates to specific embodiments, it should not be considered limited to said embodiments, since its scope of protection also includes all those variants, changes or simplifications covered by the appended claims, such as different types of storage systems, different types of processing or communication equipment, different types of signals exchanged for the same purpose as described above, etc.
[0083] The embodiments described herein may be combined with one another without thereby exceeding the protection scope of the present invention.
[0084] The advantages associated with the control unit and the related road vehicle 1 are significant and obvious.
[0085] Firstly, besides providing for the cut-off / disabling of safety-related actuators, the safety of the control unit is definitely improved, avoiding the propagation of incorrect messages.
[0086] Furthermore, VCU manufacturers typically already provide components (ie, HTA) for monitoring network security and blocking the spread of malicious messages; therefore, the present invention is simple to implement even in existing vehicles.
[0087] Another advantage of the present invention is that control units connected downstream (locally) of the VCU (i.e. auxiliary control units) can be protected without having to implement security protocols inside them, thereby simplifying any operations for updating the method for detecting malicious attacks.
[0088] Furthermore, the resources of the microcontroller dedicated to the management of the communication networks can be optimized. For example, for X vehicle networks connected in groups of Y (where Y<X), the pins dedicated to the signals ST and EN are reduced from 2*Y to 2*X. For example, 10 communication networks connected in groups of two require the allocation of four pins on the microcontroller 14 instead of twenty pins.
[0089] List of reference numerals
[0090] 1Road Vehicles
[0091] 2 front wheels
[0092] 3 rear wheels
[0093] 4 Powertrain System
[0094] 5 Electrical System
[0095] 6 High voltage circuit
[0096] 7 Low voltage circuit
[0097] 8 Storage System
[0098] 9 Electrical load
[0099] 10Safety-related actuators
[0100] 11Vehicle Network
[0101] 12Control Unit
[0102] 13. Processing equipment
[0103] 14 Microcontroller
[0104] 15Communication equipment
[0105] 16 transceivers
[0106] 17 Auxiliary processing equipment
[0107] 18 supporting chips
[0108] 19 partition system
[0109] 20 logic operators
[0110] 21 First output terminal
[0111] 22 First input terminal
[0112] 23 Second output terminal
[0113] 24 Fourth output terminal
[0114] 25 Second input terminal
[0115] 26AND port
[0116] 27 Cut-off system
[0117] 28 Fifth output terminal
[0118] 30Hardware Security Module
[0119] 34 Third output terminal
[0120] 39 Auxiliary control unit
[0121] CS communication power supply
[0122] EN enable signal
[0123] ER error signal
[0124] HTA Hardware Trust Anchor
[0125] ID Input Data
[0126] ISH Good Cybersecurity Health Signal
[0127] mEN transmission enable signal
[0128] mSH Good Health Voluntary Signal
[0129] OD output data
[0130] RST reset signal
[0131] SH Good health signal
[0132] ST receives the enable signal
[0133] VB power supply signal
[0134] WU wake-up signal
Claims
1. A vehicle control unit (12), comprising: a processing device (13), in particular a microcontroller (14), configured and programmed to process an output data set (OD) during normal operation from an input data set (ID) from at least one vehicle network (11); a communication device (15), in particular a transceiver (16), bidirectionally connected to the processing device (13) and the vehicle network (11); wherein the communication device (15) is configured to receive the input data set (ID) from the at least one vehicle network (11) and transmit it to the processing device (13), and to receive the output data set (OD) from the processing device (13) and transmit it to the vehicle network (11); wherein the communication device (15) is configured to selectively operate between a transmission mode and a standby mode, wherein in the transmission mode, the communication device (15) can communicate bidirectionally with the vehicle network (11), and in the standby mode, the communication device (15) can only receive from the vehicle network (11); The control unit (12) comprises a hardware security module (30), wherein the hardware security module (30) is configured to detect network security anomalies; The control unit (12) comprises a separation system (19) configured to selectively constrain the communication device (15) in the standby mode in the event of a network security anomaly detected by the security hardware module (30) or in particular in the event of an anomaly in the processing device (13).
2. The control unit (12) according to claim 1, wherein the security module (30) is a hardware trust anchor (HTA) module.
3. A control unit (12) according to claim 1 or 2, wherein the partitioning system (19) comprises a first output terminal (21) on the processing device (13) and a first input terminal (22) on the communication device (15) connected to the first output terminal (21), the first input terminal (22) being configured to receive from the first output terminal (21) a signal (ST) for causing the communication device (15) to receive from the vehicle network (11), i.e. for enabling at least the standby mode.
4. A control unit (12) according to any of the preceding claims, wherein the separation system (19) comprises a logic operator (20) which is connected at an input end to the processing device (13) and the hardware security module (30) and at an output end to the communication device (15).
5. A control unit (12) according to claim 4, wherein the partition system (19) comprises a second output (23) on the processing device (13) for transmitting an enable signal (mEN) and a third output (34) on the hardware security module for a network security health signal (ISH) of the control unit (12); the second output (23) and the third output (34) are concentrated in the logic operator (20), which itself provides the enable signal (EN) as output; The partitioning system (19) comprises a second input terminal (25) on the communication device (15), the second input terminal (25) being connected to the logic operator (20) to receive the enable signal (EN), the enable signal (EN) being configured to allow the communication device (15) to transmit to the vehicle network (11) only when the transmission enable signal (mEN) of the control unit (12) and the network security health signal (ISH) coexist, that is, to enable the transmission mode.
6. The control unit (12) according to claim 5, wherein the logic operator (20) is an AND port (26).
7. A control unit (12) according to claim 5 or 6, comprising an auxiliary processing device (17), in particular a supporting chip (18), wherein the auxiliary processing device (17) supervises the operation of the processing device (13) and the power supply of the communication device (15); the auxiliary processing device (17) comprises a fourth output terminal (24) for a good health signal (SH) of the auxiliary processing device (17), wherein the fourth output terminal (24) can be connected to a system (27) for cutting off a vehicle safety actuator, and the system (27) is configured to cut off at least a part of the actuator (10) related to vehicle safety in the event that the good health signal (SH) of the auxiliary processing device (17) fails.
8. The control unit (12) according to claim 7, wherein the second output terminal (23), the third output terminal (34) and the fourth output terminal (24) are concentrated to the logic operator (20), and the logic operator (20) outputs the enable signal (EN) from itself.
9. A control unit (12) according to claim 7 or 8, wherein the processing device (13) comprises a fifth output terminal (28) for a good health signal (mSH) of the processing device (13), and the fifth output terminal (28) can be connected to the system (27) for cutting off the vehicle safety actuator, and the system (27) cuts off at least a part of the vehicle safety actuator in the absence of the good health signal (mSH) of the processing device (13).
10. A control unit (12) according to any one of the preceding claims, comprising a plurality of communication devices, which are at least partially connected to the same separation system (19), and in the event that the processing device (13) fails or a network security anomaly is detected by the hardware security module, the separation system (19) constrains the plurality of communication devices to the standby mode.
11. A control unit (12) according to any of the preceding claims, wherein the communication device (15) is configured to receive a wake-up signal (WU) from the vehicle network (11), which signal is transmitted to the auxiliary processing device (17), and the auxiliary processing device (17) in turn sends a reset signal (RST) to the processing device (13) so as to be able to exit the waiting mode by entering the transmission mode.
12. A road vehicle (1) comprising: four wheels (2, 3), at least one pair of wheels (2, 3) being driven; a powertrain system (4), which is preferably electric or hybrid; A low voltage circuit (7), which in particular comprises a low voltage storage system (8); A control unit (12) according to any one of the preceding claims, the control unit (12) being powered by the low voltage circuit (7); A vehicle network (11) connects the control unit (12) to one or more electrical loads (9).
13. The vehicle according to claim 12, wherein the low voltage circuit is directly connected to the auxiliary processing device (17) and the communication device (15), wherein the auxiliary processing device (17) supervises the correct power supply of the control unit (12).
14. The vehicle according to claim 12 or 13, comprising a plurality of auxiliary control units (39) connected to the control unit (12), the safety of which is entirely entrusted to the partitioning system (19), in particular the security module (30).