Identifying external interventions in a computer system with segmentation for a device, in particular for

By implementing methods of distinguishing separation and security module identification violations in the transport tool computer system, the problem of difficulty in identifying and responding to zone intrusions in the transport tool in a timely manner in the prior art is solved, and more efficient network security management is achieved.

CN120226005APending Publication Date: 2025-06-27ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380079084.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-09-16
Filing Date
2023-09-06
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art is difficult to identify intrusion attempts in different areas of transportation vehicles in a timely manner and respond accordingly, making it difficult to effectively prevent cybersecurity threats.

Method used

By implementing division separation in the computer system, system modules and system resources are allocated to different zones, and security modules are designed to identify violations of system resource allocation criteria, multi-zone security management of transport tool computer systems is realized.

Benefits of technology

Improves the security of computer systems, enables faster and more explicit identification and response to potential cybersecurity threats, and reduces the probability of successful attacks spreading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120226005A_ABST
    Figure CN120226005A_ABST
Patent Text Reader

Abstract

One aspect of the present disclosure relates to a computer system for providing multiple functions for a device, particularly for a vehicle. A computer system of a first aspect has a plurality of system modules configured to provide functionality for a device, a plurality of system resources, and a security module. Further, a first number of system modules and / or portions of system modules of the plurality of system modules are assigned to a first zone of the plurality of zones. Further, a second number of system modules and / or portions of system modules of the plurality of system modules are assigned to a second zone of the plurality of zones. A region of a first aspect is a logically and / or physically demarceable unit in a computer system, wherein a first number of system resources of a plurality of system resources is allocated to the first region. Further, a second number of system resources of the plurality of system resources is allocated to the second zone. The security module of the first aspect is designed to identify violations on a criterion for allocating a first number of system resources of the plurality of system resources for the first zone and on a criterion for allocating a second number of system resources of the plurality of system resources for the second zone.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to techniques for providing multiple functions for devices, especially for vehicles. Related aspects relate to computer-implemented methods and computer programs. Background Art

[0002] Recently, vehicles have been networked with each other and / or with a backend located in the cloud to an increasing extent. More precisely, a vehicle has one or more interfaces through which data is received and / or sent during the operation of the vehicle, and this data is in turn used for operating the vehicle. Additionally, the complexity of the components and their software of vehicles is constantly increasing, especially in combination with autonomous or semi-autonomous vehicles and the demand for "smarter mobility", which means integrating vehicles into the digital world. Therefore, cyber-security plays an increasingly important role in the software and hardware development of modern vehicles. Furthermore, in the case of some methods of the prior art regarding cyber-security, problems arise from a variety of applications provided by different manufacturers and executed on different systems in vehicles.

[0003] In this regard, some methods of the prior art are based on the concept of zone separation, i.e., the concept of separating trusted zones within an electronic control unit (ECU), thereby isolating more strongly exposed components from less exposed components in order to reduce the attack surface.

[0004] However, some methods of the prior art are unable to: timely identify intrusion attempts in different zones and respond accordingly.

[0005] Therefore, there is a need to develop new and efficient techniques that can solve some or all of the above problems. Summary of the Invention

[0006] A first general aspect of the present disclosure relates to a computer system for providing multiple functions for a device, particularly for a vehicle. The computer system of the first aspect has a plurality of system modules, a plurality of system resources, and a security module, wherein the plurality of system modules are configured to provide functions for the device. In addition, a first number of system modules and / or a portion of the system modules among the plurality of system modules are assigned to a first zone among a plurality of zones. Further, a second number of system modules and / or a portion of the system modules among the plurality of system modules are assigned to a second zone among the plurality of zones. The zones of the first aspect are logically and / or physically delimit able units in the computer system, wherein a first number of the plurality of system resources are assigned to the first zone. In addition, a second number of the plurality of system resources are assigned to the second zone. The security module of the first aspect is designed to identify violations of the criteria regarding the assignment of the first number of the plurality of system resources to the first zone and regarding the assignment of the second number of the plurality of system resources to the second zone.

[0007] A second general aspect of the present disclosure relates to a computer-implemented method for providing multiple functions for a device, particularly for a vehicle, by a computer system. The method of the second aspect includes implementing a partition separation in the computer system. In addition, the method includes providing multiple functions for the device, particularly for the vehicle. Finally, the method includes identifying violations of the criteria regarding the assignment of system resources that are assigned to at least two zones among the plurality of zones.

[0008] A third general aspect of the present disclosure relates to a computer program that includes instructions which, when executed by a computing system, cause the computing system to perform the computer-implemented method according to the second general aspect.

[0009] The techniques of the first to third general aspects may have one or more of the following advantages.

[0010] On the one hand, compared with some techniques in the prior art, the present technique can achieve a stronger differentiation of security requirements in a computer system (such as a vehicle computer) by partitioning the computer system into zones (for example, the zones may have different levels of trust relative to each other), and the system modules of the computer system are assigned to the corresponding zones (for example, according to the criticality of the functions provided by these system modules for the device). Thus, the partition separation in the computer system of the present technique can reduce the probability that a successful manipulation in one zone spreads to other zones.

[0011] Secondly, the techniques of the present disclosure can identify interventions in a computer system more efficiently compared to some techniques of the prior art. In particular, a violation of the guidelines for allocating system resources to different zones (e.g., an unauthorized access of a zone to system resources) may indicate the presence of an intervention, or if the guidelines for allocating system resources to zones are adhered to (e.g., these zones only access permitted system resources), then no intervention has occurred.

[0012] Thirdly, the present technology provides the possibility of identifying such guideline violations (and e.g., collecting said guideline violations and reacting accordingly) in a centralized manner in the computer system of a device (e.g., in a means of transportation) via a security module. Thus, compared to some techniques of the prior art, the present technology enables a faster and more definitive assessment of whether there is an intervention in the entire computer system.

[0013] Some terms are used in the present disclosure in the following manner:

[0014] A "system module" may include hardware and / or software units that provide multiple functions for a device (e.g., for a means of transportation). A system module may include one or more processors, controllers, control units, (communication) interfaces, network components, software applications, software architectures, all other software and / or hardware components, parts of the foregoing or any combination thereof, or may be one or more of the foregoing implementations of a system module. A system module or parts thereof may be arranged in a zone or a sub-zone.

[0015] "Zone" can be a logically (functionally) and / or physically (spatially) delimit able unit in a system. In other words, if two or more zones are separated from each other on a software basis (e.g., representing different logical models in software), then the two or more zones are logically delimited from each other, while if two or more zones are separated from each other spatially (e.g., located in different computing units or parts thereof), then the two or more zones form a physically delimit able unit. A zone can include one or more system modules and / or a part or parts of a system module or multiple system modules. A zone can be defined, i.e., determined, by its constituent parts. All system modules or parts of system modules assigned to a zone can form the zone. A zone can include various computing units, computing cores, controllers, control units, storage units, peripherals, (communication) interfaces, network components, software applications, software architectures, bus systems (e.g., CAN bus system in a vehicle), all other software and / or hardware components, parts of the above, or any combination thereof. Multiple zones can form a total system (e.g., an entire computer system). In some examples, a "zone" can be subdivided into two or more "sub - zones", which can together form the zone. A "sub - zone" can be a logically (functionally) and / or physically (locally) delimit able sub - unit of a zone. Similar to a zone, a sub - zone can include one or more system modules or parts thereof assigned to the corresponding zone.

[0016] The term "system resource" can represent any resource that (at least in part) enables the execution of one or more functions of a computer system for a device (e.g., for a vehicle) as a whole. A "system resource" can be a software and / or hardware component that provides services to system modules. For example, system resources can include one or more memories, one or more peripherals (e.g., in - vehicle and / or out - of - vehicle peripherals), system resources linked to an energy supply device, or any combination thereof. The term "software component" (or "software") can in principle be every part of the software of a component (e.g., a control device) of the present disclosure. In particular, a software component can be a firmware component of a component of the present disclosure. "Firmware" is software that is embedded in an (electronic) component and provides basic functions there. The firmware is firmly connected functionally to the respective hardware of the component (such that one is not available without the other). The firmware can be stored in non - volatile memory, such as flash memory or EEPROM. Zones of the present disclosure can be permitted or prohibited access to system resources. For example, access to system resources can be permitted to a zone through access rights (more on this further below). "System resources" can be assigned to a zone or sub - zone, or can be separated independently of the partitioning in a computer system, i.e., cannot be assigned to a zone or sub - zone.

[0017] The term "system resources" can also denote "communication resources" (e.g., including a bus system, in particular a CAN bus system or a part thereof in a vehicle, or a bus system or a part thereof), and the communication resources can include, for example, the characteristics of a communication connection via one or more transmission paths in a computer system in the case of multipath communication (e.g., using multipath TCP), and the characteristics can be described as a set of transmission parameters (e.g., by means of data rate, transmission capacity, transmission delay, transmission bandwidth, transmission reliability, or any combination thereof). The corresponding communication can be carried out, for example, via one or more radio networks (e.g., 5G, LTE mobile radio network, or WLAN network) or via a near-field communication connection or Bluetooth between internal and / or external modules / components of a vehicle. For example, the communication resources can include a communication interface (e.g., one or more of I2C, SPI, CAN, LIN, USB, PCIe, Bluetooth, and Wi-Fi).

[0018] "Memory" can be a data memory or can also be a data carrier on / wherein data is stored. The memory can be read from or written to by a computer and / or any type of peripheral device. The memory can be a semiconductor memory and / or a magnetic memory or a memory based on a technology not mentioned here. The memory can be a volatile memory and / or a non-volatile memory. The memory can include one of DRAM, RAM, ROM, EPROM, HDD, SDD, etc. on / wherein data is stored.

[0019] "Peripheral device" can be a component that can be connected to a (central) computing unit. Such a component may need to be controlled by the computing unit and, if necessary, initialized. The component can be a "vehicle component". The peripheral device can include a part of a computer or a computer that provides functionality that cannot be provided by the computing core itself but can be provided by additional hardware. For example, the peripheral device can include an analog-to-digital converter (ADC), safety-related peripherals, security-related peripherals (MPU, MMU, or others), a timer or an interface, such as an SPI interface (Serial Peripheral Interface) or other interfaces mentioned above.

[0020] The term "vehicle component" is understood to mean any internal component of a vehicle. A vehicle component can be an engine (e.g., an internal combustion engine, an electric motor, a hybrid engine, or a fuel cell or part of an engine such as a turbocharger), a control device (e.g., an engine control device), a battery or other energy consumption system, a component of the powertrain (e.g., a transmission), an assistance system (e.g., a braking assistant, a lane keeping assistant, a parking assistant), an air conditioning system, a sensor or sensor system (e.g., a camera-based system, a lidar system, a radar system, an ultrasonic sensor system) or an electronic system for controlling functions of the interior space. A vehicle component can also be part of one of the above systems, or a combination of several (or parts thereof) of the above systems.

[0021] The "computer system" of the present disclosure may include (e.g., a central) vehicle computer (English: "Vehicle Computer") (e.g., the vehicle computer may constitute the computer system). The computer system may include systems within the vehicle (e.g., system modules and / or vehicle components in the sense further defined above). In some cases, the computer system may also include systems outside the vehicle (e.g., vehicle external peripherals, data cloud systems, other components or any combination thereof). In this regard, the "vehicle computer" is a highly integrated class of electronic vehicle control devices, characterized by multiple times the computing power compared to microcontroller-based ECUs. The VC is implemented with at least one microprocessor and a communication interface. In addition, the vehicle computer may include one or more physical or virtual switches, a system-on-chip (SoC) hardware having multiple CPU cores, coprocessors, and a high-performance graphics card, on which, for example, multiple virtual machines execute different operating systems with the aid of a hypervisor, and the virtual machines are connected via a virtual switch (e.g., implemented in the hypervisor). Alternatively or additionally, the VC may use container technology based on containers to provide virtual resources. Complex software for various tasks with various requirements, especially for time-critical and safety-critical functions, typically runs on the VC. The VC communicates with other systems in the vehicle, especially with vehicle components, user interfaces, and with other VCs or ECUs (each combination of these alternatives is equally conceivable). In addition, the VC may communicate with vehicle external systems, such as with cloud systems, smartphones, charging infrastructure, traffic management technology, or other vehicles. In addition, the computer system may include a bus system, by means of which multiple logical / physical communication connections can be realized between different components of the computer system (e.g., by means of corresponding physical communication channels). A possible example of such a bus system in the vehicle field is a controller area network bus system (CAN bus system).

[0022] In other cases, a "computer system" may include an embedded system (e.g., an embedded system may constitute a computer system). An embedded system is an electronic computer or computer incorporated into a technical context. An embedded system may perform regulatory, control, monitoring functions or tasks for data processing herein. In further other examples (or additionally), a "computer system" may include one or more electronic control units (ECUs) (e.g., one or more ECUs may constitute a computer system).

[0023] A "function" may be each task (or subtask) performed during the operation of a device. A function may relate to the control, regulation or monitoring of a device or a part of the device (e.g., a component of the device). Additionally or alternatively, a function may relate to data or signal processing in the device (e.g., a communication function). The term "function" in the field of vehicles includes control-based vehicle functions, such as the functions of a driving or parking assistance system, functions for autonomous or semi-autonomous driving, functions of an entertainment system, and functions for receiving, transmitting and storing various data between different systems (e.g., system modules and / or vehicle components) of a computer system (or any combination of the above functions). Within the scope of the present disclosure, functions associated with an air conditioning system and / or an electronic system for controlling the functions of an interior space are also conceivable. A corresponding "system module" may be responsible for the executability of the function, which may communicate, for example, with corresponding other systems, such as components (e.g., vehicle components), other system modules within the vehicle, or functional units external to the vehicle (as already mentioned above) or a combination thereof.

[0024] A "software architecture" may be a description of the structured and / or hierarchical arrangement of system components and their relationships in a software system, where the system components may be software parts, and their relationships to each other and their characteristics may be described by the software architecture. For example, the "AUTOSAR" (Automotive Open System Architecture) software architecture is an open and standardized software architecture for electronic control units (ECUs) in the automotive field. For example, the "AUTOSAR Classic Platform" and the "AUTOSAR Adaptive Platform" are two different software architectures.

[0025] A "security module" (such as a central "security module") can be a component for identifying violations of the criteria for allocating (or in other words "rationing") (the allotted) system resources to respective zones (such as including system modules). In addition, the security module of the present disclosure can be used for the purpose of centrally collecting and processing the identified violations (more on this below). The security module can be a hardware unit that can have its own memory, pre-configured hardware logic, one or more registers, and internal data connections. (For example, the register can contain a storage area or describe the storage area.) In addition, the security module can include respective logical and / or physical connections to the zones (such as including system modules). In this regard, the security module can have one or more interfaces to the outside, such as to a zone, to a computing core, to one or more communication connections, or any combination thereof. The security module can be part of a processor (Central Processing Unit, CPU). In some cases, the security module can be integrated into a vehicle computer or designed as an independent component (such as an in-vehicle or out-of-vehicle component), which communicates with the vehicle computer, for example (in the latter case, the computer system of the present disclosure can include the vehicle computer and the security module). The security module can communicate to the outside through a corresponding communication protocol (such as with system modules, components, other components of the computer system, or any combination thereof).

[0026] A "domain controller" can include peripherals implemented in hardware and manage access rights to, for example, memory and / or external peripherals. The domain controller can isolate different peripherals and / or protect the system's memory, where the domain of the domain controller can be a coherent area with equal access rights to the peripherals and / or memory. For example, the domain controller can be an Extended Ressource Domain Controller (XRDC), which is a hardware-implemented peripheral of the S32G274A processor. The latter is a high-performance in-vehicle network processor of the S32G2 series from semiconductor manufacturer NXP and is a system-on-chip (SoC) including a microcontroller (μC) and a microprocessor component (μP component).

[0027] A "computing core" refers to the central part of a microprocessor, where there can also be multiple computing cores in the microprocessor. The computing core can perform arithmetic and / or logical operations on the input data and / or information.

[0028] A "means of transportation" can be any device for transporting passengers and / or goods. The means of transportation can be a motor vehicle (such as a passenger car or a truck), but it can also be a rail vehicle. The means of transportation can also be a motor vehicle, a non-motor vehicle, and / or a two-wheeled or three-wheeled vehicle driven by human power. However, floating and flying devices can also be means of transportation. The means of transportation can operate autonomously, or at least semi-autonomously, or be assisted. For example, the means of transportation in the present disclosure can include partial or fully autonomous robots (such as industrial robots). BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 Schematically shows an exemplary embodiment of a computer system 100 for providing multiple functions for a device by partitioning multiple zones. Figure 1 The computer system includes four zones 20-23 (dashed boxes), six system modules 30-35, and a security module 10. In addition, two computing units 40, 41 and five interfaces 50-54 are shown in this figure.

[0030] Figure 2 Illustrates an exemplary embodiment of a computer system (for simplicity, without the third zone 22), in addition to Figure 1 the embodiments of, the computer system has peripherals 60, 61, two memories 62, 63, and a domain controller 70.

[0031] Figure 3a is a flowchart that shows (for example, in the case of using the computer system shown in Figure 1 or Figure 2 ) an embodiment of a computer-implemented method provided by the computer system according to the first aspect.

[0032] Figure 3b Represents a flowchart that shows other possible method steps according to the second aspect. DETAILED DESCRIPTION

[0033] First, according to Figure 1 and 2 describe the technology for providing multiple functions for a device (especially for a means of transportation) and the exemplary structure of a computer system. Then, Figure 3a and 3b clarify other aspects related to the method of the present disclosure.

[0034] A first general aspect relates to a computer system 100 (such as a vehicle computer) for providing a plurality of functions for a device, in particular for a vehicle (such as a vehicle operating autonomously or semi - autonomously), wherein the computer system comprises a plurality of system modules 30 - 35 (such as hardware and / or software units, as already mentioned above), a plurality of system resources 60 - 63 (such as memories, in - vehicle and / or out - of - vehicle peripherals, communication resources, such as all or part of a bus system, see the above discussion), and a security module 10. Possible embodiments of such a computer system 100 are shown in Figure 1 and 2 . The plurality of system modules of the first general aspect are configured to provide functions for the device (such as functions for controlling, regulating, or monitoring the device, as already mentioned above).

[0035] In the present technology, a first number of system modules 30, 31 and / or a part of the system modules among the plurality of system modules are assigned to a first zone 20 of a plurality of zones 20 - 23. Furthermore, a second number of system modules 32 and / or a part of the system modules among the plurality of system modules are assigned to a second zone 21 of the plurality of zones. Here, a zone is a logically and / or physically delimit able unit in the computer system (as further defined above). For example, in the computer system 100, one or more, two or more, three or more, four or more, five or more, six or more, ten or more, twenty or more, fifty or more, one hundred or more zones can be separated out. In a non - limiting example of Figure 1 , four zones 20, 21, 22 and 23 and six system modules 30 to 35 are shown. Two system modules 30, 31 (the first number of system modules in this example) are assigned to the first zone 20, while one system module 32 (the second number of system modules in this example) is assigned to the second zone 21 (such an arrangement is also shown in an embodiment of Figure 2 ). In the same way as for the two zones 20 and 21, one or more other system modules or parts thereof that are not assigned to one of the two zones can be assigned to corresponding other zones different from the first and second zones. In an example of Figure 1 , three system modules 33, 34 and 35 are assigned to a third zone 22.

[0036] In some cases, one or more, two or more, three or more, four or more, five or more, six or more, ten or more, twenty or more, fifty or more, one hundred or more system modules (e.g., processors or other implementations of system modules as defined above) or portions thereof (e.g., computing cores) may be arranged in a zone. For example, the first zone 20 may include a portion (e.g., two computing cores) of a plurality of computing cores (e.g., four computing cores) of a processor, and the second zone 21 may include another portion (e.g., the two remaining computing cores) of the plurality of computing cores of the processor (not shown in the figure). For example, a first software application may be executed on the computing cores of the processor allocated to the first zone 20, and a second software application may be executed on at least one computing core allocated to the second zone 21. In some examples, a zone may include an interface, a bus system, or a portion thereof. In Figure 1 FIG., an exemplary first zone 20 including a first interface 50 and a second interface 51, a second zone 21 including an interface 52, and a third zone 22 including an interface 53 are shown. For example, the interface may include a CAN bus interface, a CAN-FD bus interface, and / or a GMAC port.

[0037] In the technology of the present disclosure, a first quantity of system resources 60-62 (e.g., software and / or hardware components) among a plurality of system resources 60-63 is allocated to the first zone 20. In addition, a second quantity of system resources 62, 63 among the plurality of system resources is allocated to the second zone 21 among the plurality of zones. In some cases, the second quantity of system resources 62 may be different from the first quantity of system resources. As already mentioned above, "system resources" may provide corresponding services for system modules and are, for example, required for the executability of one or more functions of a computer system. Here, the second quantity of system resources 62, 63 may be more restricted than the first quantity of system resources 60-62. For example, the second quantity of system resources may include fewer system resources than the first quantity of system resources. Alternatively or additionally, the second zone 21 may have less access to the same or other system resources, as will be elaborated in more detail below. In Figure 2 a non-limiting example, two peripheral devices 60, 61 and one memory 62 (the first quantity of system resources in this example) are allocated to the first zone 20 (e.g., by means of a domain controller 70, more details about which will be provided below), while two memories 62, 63 (the second quantity of system resources in this example) are allocated to the second zone 21. In Figure 2In the example, the same system resource, i.e., the memory 62, is allocated to two zones 20, 21, while the other system resources 60, 61, 63 are allocated to the first zone 20 and the second zone 21 respectively. In some cases, the same system resource can be allocated to two or more zones. In other cases, a system resource can only be allocated to a corresponding zone and cannot be allocated to another zone.

[0038] The security module 10 of the present disclosure is designed to identify violations of the criteria regarding the allocation of the first quantity of system resources 60 - 62 out of the multiple system resources to the first zone 20 and the criteria regarding the allocation of the second quantity of system resources 62, 63 out of the multiple system resources to the second zone 21. As will be further elaborated below, for example, the first and / or second zone (e.g., the system modules allocated to these zones) may access unauthorized system resources due to external intervention (or in other words, an intrusion from outside). For example, the first zone 20 may perform a write access to the memory 62, although this zone can only perform a read access to the memory, and there will be more on this below. In addition, the security module 10 can be designed to identify violations of the criteria regarding the allocation of system resources to other zones (e.g., for all the remaining zones, such as the Figure 1 third and fourth zones 22, 23). The security module 10 of the first aspect may include one or more logical and / or physical connections to one of the multiple zones (e.g., one or respective logical and / or physical connections to the first and second zones among the multiple zones). In Figure 1 and 2 the example, such connections are shown by solid lines from the security module 10 to the respective zones 20, 21, 22.

[0039] In the computer system 100 of the first aspect, the first zone 20 may be more trustworthy than the second zone 21, i.e., the less trustworthy zone, where the risk of manipulation of the more trustworthy zone is lower than the risk of manipulation of the less trustworthy zone. Here, manipulation may include external intervention (or in other words: an intrusion from outside, such as a cyber - attack), and such external intervention reduces the operating security of the device. In addition, in some cases, the third zone 22 among the multiple zones may be more trustworthy than the first zone 20 or equally trustworthy as the first zone 20. In other cases, the third zone 22 may be more trustworthy than the second zone 21 or equally trustworthy as the second zone 21, while being less trustworthy compared to the first zone. In still other cases, the third zone 22 may be less trustworthy compared to the second zone 21 and the first zone 20. In this way, the other zones (e.g., all zones) among the multiple zones can also be classified: how trustworthy the other zones (e.g., all zones) are relative to each other.

[0040] To what extent one of the multiple zones is more or less trustworthy, i.e., the trustworthiness level can be based on the partitioning of zones 20 - 23 according to the security level (“Security-Level”). The computer system of the present disclosure can have at least two security levels, but can also have more than two security levels (e.g., more than five). The trustworthiness level or security level can be determined by configuring the corresponding zones (e.g., the system modules contained therein). For example, the degree of protection or the scale of protective measures of the system modules in protected zones 20 - 23, such as being protected from being exploited by manipulation in the scope of external intervention, can determine whether zones 20 - 23 are more or less trustworthy or which security level the zones have (e.g., the presence of specific hardware- and / or software-based protective measures in the system modules of the zones). In addition, for example, the scale of communication between the system modules arranged in the corresponding zones and external systems, such as the backend, can determine which trustworthiness level the zone has or which security level the zone has. For example, a zone that communicates mainly or only within the computer system may be more trustworthy than a zone that communicates at least partially with external systems (e.g., the backend, other devices, such as transportation vehicles or infrastructure components).

[0041] In some examples, zones can be partitioned into untrusted zones and trusted zones in terms of their trustworthiness. As described herein, two zones 20, 21 may be, for example, trustworthy, while a third less trustworthy zone 22 may be, for example, untrusted (see Figure 1 and 2 ). The computer system 100, such as the computer system of a transportation vehicle, may be, for example, a target of a cyber-attack, which may render a safety-critical function, such as the braking function in a transportation vehicle, inoperative or manipulate a safety-critical function, such as the braking function in a transportation vehicle, such that a dangerous situation may occur. The more trustworthy zones 20, 21 are those in which manipulation is less likely compared to the less trustworthy zone 22. For example, a zone 22 that includes multimedia functions and has many interfaces for communicating with the backend can be a less trustworthy zone 22 because the probability of external intervention in the communication channel with the backend is higher compared to the case of a zone 20 that mainly includes functions that only require information from within the transportation vehicle and / or only execute processes within the transportation vehicle. In addition, the security module 10 that oversees violations of the criteria for allocating system resources to different zones can be assigned to a first zone 20 among the multiple zones, or to another zone 23 that is more trustworthy than the first zone among the multiple zones. In some cases, the security module 10 can be assigned to the most trustworthy zone 23 among the multiple zones (e.g., the security module 10 can be assigned to the fourth most trustworthy zone 23, as elucidated in Figure 1 and 2 ).

[0042] In the present technology, the functions provided by the system modules may be of different criticalities for the running safety of the device. The first more critical function among the multiple functions may be provided by the system modules 30, 31 in the first zone 20, while the second less critical function among the multiple functions may be provided by the system module 32 in the second zone 21. In some cases, two or more system modules (e.g., all system modules) in the second zone may provide corresponding functions that are less critical compared to all the functions provided by the system modules in the first zone. In addition to dividing the zones 20 - 23 according to the trust level, i.e., the safety level, the zones are thus additionally classified in terms of their relevance to the running safety (e.g., by means of the safety level or "Safety-Level"), i.e., the criticality of the zone functions for the running safety of the device. Here, the zone 20 whose manipulation may lead to serious dangerous situations is more critical than the zone 21 whose manipulation may not lead to serious dangerous situations or may lead to less serious dangerous situations. For example, the zone 21 including multimedia functions may be less critical compared to the zone 20 including braking functions. In the foregoing example, the probability of a dangerous situation occurring due to the malfunction of music in the interior space of the vehicle is not as high as the probability of a dangerous situation that may be caused by the inoperability of the vehicle's brakes. In addition, the zone 23 assigned to the safety module 10 may be more critical than one or more (e.g., all) of the other zones. Returning to Figure 1 the example: The fourth zone 23 is more critical than the other three zones 20, 21, and 22. The zones can be classified according to the safety level or safety grade or their relevance to the running safety of the device in any suitable manner. In some examples, the classification can be carried out by means of the Automotive-Safety-Integrity-Level (ASIL) classification, where the classification can include five levels (QM (least critical), ASIL-A, ASIL-B, ASIL-C, and ASIL-D (most critical)). For example, the relevance of the zone to the running safety, i.e., the criticality, can be derived from the severity, frequency, controllability, or any combination thereof of the safety hazards in the respective zone.

[0043] In the present disclosure, one or more more trusted zones 20, 21 may be formed on the first computing unit 40 of the computer system, and one or more less trusted zones 22 may be formed on the second computing unit 41 of the computer system. Figure 1An example of such a computer system 100 is shown (e.g., the computer system 100 may include a vehicle computer, a system-on-chip, or an embedded system, see also the further definitions above), the computer system having a first computing unit 40 and a second computing unit 41. For example, a first trusted zone 20 and a second trusted zone 21 may be formed on the same computing unit 40, and a third untrusted zone 22 may be formed on the second computing unit 41. For example, zones 20 and 21 may be logically separated from each other on a software basis. In some examples, the third zone 22 may be physically, i.e., spatially, separated from the first zone 20 and / or the second zone 21 by forming the third zone on the second computing unit 22.

[0044] In the present technology, corresponding access rights to system resources can be assigned to zones in a plurality of zones. In other words, access to system resources by a zone can be prohibited or permitted through access rights. The access rights may include permitted read, write, execute access or any combination thereof by the zone to the corresponding system resources. In some cases, one or more access rights assigned to a zone may remain unchanged over time (e.g., the access rights may be predefined before or during the operation of the computer system). In other cases, one or more access rights assigned to a zone may change over time (e.g., at startup of the computer system, the zone is allowed to use the system resources in a read-only manner, and at another point in time, the zone is allowed to use the same system resources in a read-and-write manner). In one example, if a predetermined criterion is met, access by a zone to system resources can be classified as permitted. Further, if the predetermined criterion is not met, access by the same zone to system resources can be classified as not permitted. The predetermined criterion may be a criterion related to the context information of the device and / or a plurality of devices, e.g., related to the context information of a vehicle (or its vehicle components) and / or a fleet. For example, the context information of a vehicle (or its vehicle components) may include information about the operating state of the vehicle (or its vehicle components) and / or information about the predetermined rules for operating the vehicle (or its vehicle components). (This definition can be similarly extended to the entire fleet.) In another example, the predetermined criterion may require that the expected number of messages to be sent by a zone (e.g., via a CAN bus system) within a predetermined time period must be less than or equal to a predetermined value (or must be greater than or equal to a predetermined value). In other examples, the predetermined criterion may include a predetermined order of sending data from the zone and / or a predetermined range included in a particular type of data sent (e.g., values are between a predetermined value and another predetermined value and / or include a predetermined pattern therein). In still other examples, the predetermined criterion may include one or more of the above criteria.

[0045] In some cases, compared to the first area's access to the first quantity of system resources, the second area may be assigned less access to the second quantity of system resources. Returning to Figure 2 Example: The first area 20 in multiple areas may be granted access rights to use the memory 62 for reading and writing or for reading, writing, and executing software applications. The first area may be more trustworthy than the second less trustworthy area 21. On the other hand, the second less trustworthy area 21 may be granted access rights to use the memory 62 for reading, while the rights for writing and / or for executing software applications are prohibited.

[0046] In some examples, as shown in Figure 2 the computer system may have a domain controller 70, which contains multiple domains (the latter not shown in this figure). The domain controller 70 may contain one or more, two or more, three or more, four or more, five or more, six or more, seven or more, eight or more domains. In the first aspect of the present technology, at least the first area 20 may be assigned to the first domain among multiple domains, and the first domain may have the same access rights to system resources for the first area. In addition, at least the second area may be assigned to the second domain among multiple domains, and the second domain may have the same access rights to system resources for the second area, where the second domain is assigned less access rights to system resources than the first domain (as already described in conjunction with the first and second areas above). In other words, in some examples, system modules and / or parts of system modules with the same access rights may be assigned to domains, or system modules and / or parts of system modules that require the same access rights to system resources to provide corresponding functions may be assigned to domains. In some examples, the domain controller may be configured to allow or disallow access to system resources through the system module 70. In some examples, access rights to system resources may be assigned (e.g., by means of the domain controller 70) based on the principle of least privilege (PoLP). That is, each area only has access rights to the system resources required for the area to perform its tasks. In other words: The system modules assigned to each area only have access rights to the system resources required for the area to provide its respective functions. In some examples, a credibility level ("security level") may be assigned to domains. For example, a lower credibility level may be assigned to the first domain (e.g., domain 0) among multiple domains (e.g., five domains) than to the fifth domain (e.g., domain 5).

[0047] In some examples, the domain controller 70 can be used to assign access rights to the peripherals 60, 61 and / or memories 62, 63 to the zones 20, 21. For example, a domain can include logical / physical regions that have the same access rights to the memory 63 and / or the peripherals 61, 62. Additionally, in one of the multiple zones (e.g., in the first zone 20 or in another zone), a system module and / or a part of the system module can include a first software architecture, while in another of the multiple zones (e.g., in the second zone 21 or in another zone), another system module and / or a part of the system module can include a second software architecture. For example, in the first zone 20, the system modules 30, 31 and / or a part of the system module can include an AUTOSAR-Classic software architecture, while in another zone 21, the system module 32 and / or a part of the system module can include an AUTOSAR-Adaptive software architecture. For example, in the first zone 20, the system modules 30, 31 and / or a part of the system module can be configured to execute a first operating system (e.g., Windows), while in the second zone 21, the system module 32 and / or a part of the system module can be configured to execute a second operating system (e.g., Linux).

[0048] In the present technology, a violation of the guidelines regarding the allocated system resources for a zone can correspond to an unauthorized access by the zone to the system resources for which access rights have not been allocated to the corresponding zone. For example, a violation of the guidelines regarding the allocation of a first quantity of system resources out of a plurality of system resources to the first zone can correspond to one or more unauthorized accesses by the first zone to one or more of the system resources for which access rights have not been allocated to the first zone. Alternatively or additionally, a violation of the guidelines regarding the allocation of a second quantity of system resources out of a plurality of system resources to the second zone can correspond to one or more unauthorized accesses by the second zone to one or more of the system resources for which access rights have not been allocated to the second zone. For example, if even though the first zone (e.g., the system module assigned to the zone) can only access the system resources in a read-only manner, but the first zone attempts to access the system resources (e.g., memory) in a write mode, a violation of the guidelines regarding the system resources allocated to the first zone (or another zone) may occur. In another example, if even though the first zone (e.g., the system module assigned to the zone) does not have the access rights to execute the system resources (e.g., software application), but the first zone attempts to execute the system resources, a violation of the guidelines regarding the system resources allocated to the first zone (or another zone) may occur.

[0049] In the present technology, the security module 10 can furthermore be configured to communicate with one or more zones 20, 21, 22 (e.g., all zones) (e.g., as already described above, in the case of using corresponding logical and / or physical connections). Thereby, the security module can be configured to collect information about the access of one or more of the multiple zones (e.g., each zone) to system resources. Such information (e.g., in the form of digital or analog signals, messages, etc.) can be provided to the security module by the respective zones, for example. In some cases, the security module can be configured to send a request for obtaining information about the access of a zone to system resources to the zone, and the zone can transmit the said information to the security module. Such a request can be made, for example, regularly at each predetermined time interval, and / or irregularly if the respective successive time intervals are different. For example, the said information can be stored in a register of the zone, e.g., in a system module (e.g., a storage unit) assigned to the zone, such that the security module can read the said information. Alternatively or additionally, the zone itself can send the said information to the security module (e.g., regularly at each predetermined time interval, and / or irregularly if the respective successive time intervals are different), without the security module making the request. Furthermore, the security module can compare the information about the access of one or more zones to system resources with information about the criteria for allocating system resources to these zones. For example, the information about the allocation criteria can be stored in the security module or in another system module with which the security module can communicate. Based on the comparison result, the security module of the present technology can, in some cases, identify whether a violation of the criteria for allocating system resources to one or more zones has occurred. If, for example, the information about the access of a zone to system resources is inconsistent with the information about the criteria for allocating system resources to the zone (e.g., because at least one unauthorized access of the zone to system resources has been determined), the security module can classify the comparison result as a violation of the criteria. As further mentioned above, a violation of the criteria for allocating system resources to the respective zones can occur due to external intervention in the computer system (e.g., the zone or one or more system modules of the zone).

[0050] In addition, the security module 10 of the first aspect or another module may be configured such that the security module 10 or another module triggers a reaction in the manipulated area in order to mitigate the impact of the manipulation caused by an external intervention in the computer system. The security module is in communication connection with the other module (for example, in order to notify the module of a corresponding violation of the allocation criterion in the case of using corresponding signals, for example). Here, the manipulated area may correspond to the area targeted by the identified violation of the criterion regarding the system resources allocated to this area. Here, the reaction may include taking countermeasures against the identified violation in the manipulated area. In some cases, such countermeasures may include changing the access rights to the system resources allocated to the manipulated area. For example, if the area has two or more different access rights for using the system resources (for example, in the Figure 2 example, area 20 may use the memory 62 in a read, write, and execute manner), then as a countermeasure, the number of access rights for using the system resources may be reduced (for example, as a countermeasure, area 20 is allowed to use the memory 62 only in a read manner).

[0051] In other cases, the countermeasure may include blocking access to the system resources allocated to the manipulated area (for example, as a countermeasure, area 20 is prohibited from accessing the memory 62). In still other cases, the countermeasure in the manipulated area may include shutting down the manipulated area. In addition, the countermeasure may include sending information about the identified violation of the criterion in the manipulated area (for example, in the form of a digital or analog signal, message, etc.) and / or other relevant information (for example, also in the form of a digital or analog signal, message, etc.) from the security module 10 to the system modules 30, 31 belonging to the manipulated area 20. For example, the context information further described above for the device and / or multiple devices, such as the context information of the vehicle (or its vehicle components) and / or the fleet, may belong to other relevant information. Alternatively or additionally, the countermeasure may include sending information about the identified violation of the criterion in the manipulated area and / or other relevant information from the security module 10 to the system modules 32 - 35 belonging to other non-manipulated areas. Instead of or in addition to the above two alternatives, the countermeasure may include sending information about the identified violation of the criterion in the manipulated area and / or other relevant information from the security module to an external system (for example, a backend, other devices, such as a vehicle or an infrastructure component). In some cases, the security module 10 (or the other module mentioned above) may thus be further configured to execute a routine (for example, a software program or code, such as compiled code) as a reaction in the manipulated area. For example, one or more of the above countermeasures may be implemented in the computer system 100 according to the routine.

[0052] Instead of or in addition to the reaction (possibly) triggered in the manipulated area, the safety module 10 or other modules in communication connection with the safety module can be configured in the present technology such that the safety module or other modules trigger a reaction in the non-manipulated area in order to mitigate the impact of the manipulation caused by external intervention in the computer system. Here, the reaction can include taking countermeasures in the non-manipulated area as a result of a violation identified in the manipulated area. In some cases, such countermeasures can include changing the access rights to system resources allocated to the non-manipulated area. For example, if Figure 2 the first area 20 of Figure 2 is the manipulated area, and the second (non-manipulated) area 21 has two or more different access rights for using system resources (for example, area 21 can use the memory 63 in read, write, and execute modes), then as a countermeasure, the number of access rights for using the system resources by the second non-manipulated area 21 can be reduced (for example, as a countermeasure, area 21 is allowed to use the memory 63 only in read mode). In other cases, the countermeasure can include blocking access to system resources allocated to the non-manipulated area (for example, as a countermeasure, area 21 is prohibited from accessing the memory 63). In still other cases, the countermeasure in the non-manipulated area can include shutting down the non-manipulated area. In some cases, the safety module 10 (or other modules mentioned above) can thus be further configured to execute routines (such as the routines mentioned above) as a reaction in the non-manipulated area. For example, one or more of the above countermeasures can be implemented in the computer system 100 according to this routine.

[0053] As described in detail above, the safety module 10 can send information about violations of the criteria identified in the manipulated area and / or other relevant information to the system modules 30-35 belonging to the manipulated area 20 and / or other non-manipulated areas 21, 22. (As already mentioned, any information can exist, for example, in the form of digital or analog signals, messages, etc.) Alternatively or additionally, one or more of the plurality of system modules (for example, all system modules) can be configured to query the safety module 10 for information about violations identified in one or more manipulated areas or for other relevant information (the so-called "Polling" - a term known to those skilled in the art). For example, such queries can be made regularly at each predetermined time interval and / or irregularly if the respective successive intervals are different. In addition, the safety module 10 can be configured to provide the information to one or more system modules (for example, send and / or allow the system modules to read the information). In addition, each of one or more of the plurality of system modules can be configured to identify from the information about the identified violations: whether a violation of the criteria for allocating system resources to one or more of the plurality of areas has occurred. In addition, if a violation of the criteria for allocating system resources to at least one of the plurality of areas has been identified, each of one or more of the plurality of system modules can be configured to trigger a reaction in the respective area to which the system module is assigned (for example, in a non-manipulated or manipulated area, depending on which area the respective system module is assigned to). Here, the reaction can include taking countermeasures in the area to which the system module is assigned. For example, the countermeasures can include one or more countermeasures already described in connection with the safety module. In some cases, the countermeasures can also include changing access rights or blocking access to the system resources allocated to the area to which the system module is assigned. In other cases, the countermeasures can include shutting down the area to which the system module is assigned.

[0054] A second general aspect of the present disclosure relates to a computer-implemented method for providing a plurality of functions for a device, in particular for a means of transport, by means of a computer system 100. In some cases, the method of the second aspect can be provided by the computer system 100 according to the first general aspect (for example, by the computer system shown in Figure 1 or 2 or by another computer system). The method is exemplarily shown in Figure 3a and 3b The method steps of the corresponding independent claims are in Figures 3a to 3bThe main claims of the first aspect are shown in the boxes drawn with solid lines, while the method steps of some dependent claims are shown in the boxes represented by dashed lines. The method of the second aspect includes implementing a 200-segmentation in a computer system. In addition, the method includes providing more than 300 functions for a device, especially for a means of transportation. Finally, the method includes identifying 400 violations of the criteria regarding the allocation of system resources, where the system resources are allocated to at least two of the multiple zones 20-23.

[0055] In addition, the step "implement 200" of the second general aspect may include dispatching 210 a first quantity of system modules 30, 31 and / or parts of system modules among the multiple system modules to a first zone 20 of at least two zones 20-23. In addition, the step "implement 200" may include dispatching 220 a first quantity of system resources 60-62 among the multiple system resources 60-63 to the first zone. In addition, the step "implement 200" may include dispatching 230 a second quantity of system modules 32 and / or parts of system modules among the multiple system modules to a second zone 21 of at least two zones 20-23. In addition, the step "implement 200" may include dispatching 240 a second quantity of system resources 62, 63 among the multiple system resources 60-63 to the second zone 22. In this technology, system modules or parts thereof that do not belong to the first and second zones and their respective system resources may be dispatched to corresponding other zones different from the first and second zones, also in the same way as for the first and second zones. In the method of the second aspect, dispatching system resources to a zone may further include dispatching corresponding access rights to the system resources to that zone.

[0056] The third general aspect of the present disclosure relates to a computer program that includes instructions which, when executed by a computing system, cause the computing system to execute the computer-implemented method according to the present disclosure.

[0057] The present disclosure further relates to a computer-readable medium (such as a DVD or solid-state memory) that contains the computer program of the third general aspect.

[0058] The present disclosure further relates to a signal (such as an electromagnetic signal according to a wireless or wired communication protocol) that encodes the computer program of the third general aspect.

Claims

1. A computer system (100) for providing multiple functions to a device, in particular to a means of transportation, wherein the computer system has a plurality of system modules (30 - 35), a plurality of system resources (60 - 63) and a security module (10), wherein the plurality of system modules are configured to provide functions for the device, wherein a first number of system modules (30, 31) and / or a part of the system modules among the plurality of system modules are assigned to a first zone (20) among a plurality of zones (20 - 23), wherein a second number of system modules (32) and / or a part of the system modules among the plurality of system modules are assigned to a second zone (21) among the plurality of zones, wherein a zone is a logically and / or physically delimit able unit in the computer system, wherein a first number of system resources (60 - 62) among the plurality of system resources (60 - 63) are assigned to the first zone (20), wherein a second number of system resources (62, 63) among the plurality of system resources (60 - 63) are assigned to the second zone (21), wherein the security module (10) is designed to identify violations of the criteria regarding the assignment of the first number of system resources (60 - 62) among the plurality of system resources to the first zone (20) and the criteria regarding the assignment of the second number of system resources (62, 63) among the plurality of system resources to the second zone (21).

2. The computer system according to claim 1, wherein the first zone (20) is more trustworthy than the second less trustworthy zone (21), wherein the risk of manipulation of the more trustworthy zone is lower than the risk of manipulation of the less trustworthy zone.

3. The computer system according to claim 1 or 2, wherein the functions provided by the system modules are of different criticality for the running safety of the device, wherein a first more critical function among the plurality of functions is provided by the system modules (30, 31) of the first zone (20), and a second less critical function among the plurality of functions is provided by the system module (32) of the second zone (21).

4. The computer system according to any one of claims 1 to 3, wherein corresponding access rights to system resources are assigned to the zones among the plurality of zones, wherein fewer access rights to the second number of system resources are assigned to the second zone than the access rights to the first number of system resources assigned to the first zone.

5. The computer system according to claim 4, wherein the access rights include permitted read, write, execute access or any combination thereof by the zone to the corresponding system resources, optionally wherein one or more access rights assigned to a zone remain unchanged over time or change over time.

6. The computer system according to claim 4 or 5, wherein if a predetermined criterion is met, the access by the zone to the system resources is classified as permitted, and if the predetermined criterion is not met, the access by the same zone to the system resources is classified as not permitted, wherein the predetermined criterion includes one or more of the following criteria: Predetermined criteria related to the context information of the device and / or multiple devices; The expected number of messages sent by the area within a predetermined time period is less than or equal to a predetermined value; The area sends data in a predetermined order and / or whether the sent data includes a range.

7. The computer system according to any one of claims 4 to 6, wherein a violation of the criteria regarding the allocated system resources for an area corresponds to an unauthorized access by the area to the system resources for which access rights have not been allocated to the corresponding area.

8. The computer system according to any one of claims 1 to 7, wherein the security module (10) is assigned to the first area (20) among the multiple areas, or is assigned to another area (23) among the multiple areas that is more trustworthy than the first area, or is assigned to the most trustworthy area (23) among the multiple areas.

9. The computer system according to any one of claims 1 to 8, wherein the security module is configured to: Collect information about the access of one or more of the multiple areas to system resources, wherein the information is provided to the security module by the respective area; Compare the information about the access of the one or more areas to system resources with the information about the criteria for allocating system resources to these areas; and Identify based on the comparison result: whether a violation of the criteria for allocating system resources to the one or more areas has occurred.

10. The computer system according to any one of claims 1 to 9, wherein the security module or another module in communication connection with the security module is configured such that the security module or the other module triggers a reaction in the manipulated area to mitigate the impact of the manipulation caused by external intervention in the computer system, wherein the manipulated area corresponds to the area for which a violation of the criteria for allocating the system resources of the area has been identified, wherein the reaction includes taking countermeasures against the identified violation within the manipulated area.

11. The computer system according to any one of claims 1 to 10, wherein the security module or another module in communication connection with the security module is configured such that the security module or the other module triggers a reaction in the non-manipulated area to mitigate the impact of the manipulation caused by external intervention in the computer system, wherein the reaction includes taking countermeasures in the non-manipulated area as a result of the identified violation in the manipulated area.

12. The computer system according to any one of claims 1 to 11, wherein one or more of the multiple system modules are configured to query the security module 10 for information about the identified violations in one or more manipulated areas or for other relevant information; wherein the security module is configured to provide the information to the one or more system modules; and wherein each of one or more of the multiple system modules is further configured to: Identify from the information about the identified violations: whether a violation of the criteria for allocating system resources to one or more of the multiple areas has occurred; and If a violation of the criteria for allocating system resources to at least one of the plurality of zones has been identified, a reaction is triggered in the respective zone to which the system module is allocated.

13. A computer-implemented method for providing a plurality of functions for a device, in particular for a means of transport, by means of a computer system (100), the method comprising the steps of: implementing (200) zoning in the computer system (100); providing (300) a plurality of functions for the device, in particular for the means of transport; and identifying (400) a violation of the criteria for allocating system resources, the system resources being allocated to at least two of the plurality of zones (20 - 23).

14. The computer-implemented method according to claim 13, wherein implementing (200) zoning in the computer system further comprises: dispatching (210) a first quantity of system modules (30, 31) and / or parts of system modules of the plurality of system modules to a first zone (20) of the at least two zones (20 - 23); dispatching (220) a first quantity of system resources (60 - 62) of the plurality of system resources (60 - 63) to the first zone (20); dispatching (230) a second quantity of system modules (32) and / or parts of system modules of the plurality of system modules to a second zone (21) of the at least two zones (20 - 23); dispatching (240) a second quantity of system resources (62, 63) of the plurality of system resources (60 - 63) to the second zone (22).

15. A computer program comprising instructions which, when executed by a computing system, cause the computing system to perform the computer-implemented method according to claim 13 or 14.