Electronic control unit for vehicle comprising interactive black box and method for operating such electronic control unit

By introducing interactive black box and security coprocessor into the vehicle electronic control unit, the system failure problem caused by the untrustworthy boot loader is solved, and diagnostic and update methods are provided to ensure the stable operation of the system.

CN120344969APending Publication Date: 2025-07-18SCHAEFFLER TECHNOLOGIES AG & CO KG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380083910.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-08
Filing Date
2023-12-05
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, when the electronic control unit of the vehicle is no longer trustworthy, the user cannot understand the reason and the system fails, lacks diagnostic means, resulting in the system being unavailable and the application code cannot be updated.

Method used

An interactive black box is introduced in the electronic control unit, including a secure coprocessor and memory, to authenticate and verify the integrity of the bootloader and application code, and to download support information codes instead of the bootloader when it is not trusted, providing diagnostic functions and external communication means.

Benefits of technology

Allows users to understand why bootloaders and application code are no longer executed, reduces the cost of failures and malicious intrusions, ensures that the system continues to run and provides diagnostic and update possibilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120344969A_ABST
    Figure CN120344969A_ABST
Patent Text Reader

Abstract

The invention relates to an electronic control unit (2) for a vehicle, the electronic control unit (2) comprising a main processor (4), a memory device (6) storing a boot loader (18) and an application code (13), an interactive black box (8) comprising a security co-processor (20) and a memory (22), the memory (22) of the interactive black box (8) storing an assistance information code (24), and a plurality of application cores (10), the support information code (24) is configured to implement at least one diagnostic function of the electronic control unit (2) when executed by the main processor (4), and the security coprocessor (20) is configured to authenticate and verify integrity of the boot loader (18) within the plurality of application cores (10).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to an electronic control unit for a vehicle, in particular a motor vehicle, which comprises a main processor, a memory device, an interactive black box and a plurality of application cores. The present invention relates to the fields of electronics and information security, and more precisely to the secure start-up of an electronic control unit loaded in a vehicle and the execution of an authenticated application code on such an electronic control unit. The present invention also relates to an operating method for such an electronic control unit and a computer program product for implementing specific steps of the method. The electronic control unit is, for example, a microcontroller, but is not limited thereto within the framework of the present invention.

[0002] In the prior art, electronic control units for vehicles, especially motor vehicles, are known, which typically include a main processor, a memory device, an interactive black box, and a plurality of application cores. Such an electronic control unit (referred to as an ECU, which stands for "Electronic Command Unit" in English) is, for example, a microcontroller. The memory device is connected to the main processor via a data communication bus and stores a boot loader and application code intended to be executed by the main processor (such application code is, for example, intended to allow software blocks for driving the vehicle, such as software blocks belonging especially to motor control or also to an electrical storage battery). The boot loader (also called "Boot Loader" in English) corresponds to a software layer rather than application code and includes a plurality of startup sequences. The boot loader is configured to request authentication and verification of the integrity of the application code stored in the memory device when executed by the main processor, and is configured to execute the application code on the application cores when the application code has been authenticated. The interactive black box (also called the HSM module, which stands for "Hardware Security Module" in English) includes a security coprocessor and a memory. The security coprocessor (also called "Trust Anchor" in English) is the only element that the electronic control unit trusts in a persistent manner. The security coprocessor is connected to the main processor via a data communication bus and is configured to authenticate and verify the integrity of the application code stored in the memory device, and is configured to authorize the execution of the application code on the application cores. The security coprocessor thus is responsible for ensuring the security functions within the electronic control unit and more generally forms part of a so-called "Secure Boot" mechanism, which includes a series of levels, each level involving the execution of a new information code portion after the necessary verification of code integrity and the optional decryption of protected content. The security coprocessor corresponds to the first level. In fact, vehicle users and manufacturers need to ensure in the future that the application code executed by the dedicated electronic control unit in the vehicle is sufficiently trusted to be executed. "Sufficiently trusted" means that the unit is in a trusted mode to be executed and is also in a state where it is guaranteed that no one can modify the content of the non-volatile internal memory of the unit, which is dedicated to storing software allowing the operating system to be executed. The interactive black box and thus the security coprocessor is the first module executed by the electronic control unit and is responsible for authorizing the execution of the application code by the boot loader on the application cores.

[0003] However, when one of the start-up sequences of the bootloader is no longer trustworthy (and thus no longer certifiable), the bootloader cannot be executed by the main processor of the electronic control unit. Then, when it comes to the application code within the unit, it becomes non-executable, the unit becomes inoperative in the vehicle, and the end user of the vehicle does not understand the reason. In fact, in the currently used systems, the electronic control unit does not provide any means for the user to communicate with it in order to understand the reason why the bootloader and the application code are no longer executed within the system and / or to attempt to execute an update of the application code within the unit. In particular, the user does not have any diagnostic means to distinguish between a hardware memory problem (especially on the memory device) or a malicious attack (of the type of intentional damage) on the unit.

[0004] The object of the present invention is to overcome the drawbacks of the prior art by proposing an electronic control unit for a vehicle, in particular a motor vehicle, which provides the user or the vehicle manufacturer with the possibility of understanding the reason why the bootloader and the application code are no longer executed within the system while also allowing the electronic control unit to continue to execute in a dedicated mode in order to provide communication and diagnostic means with the outside.

[0005] To this end, the present invention thus relates, in its broadest acceptability, to an electronic control unit for a vehicle, the electronic control unit comprising a main processor, a memory device, an interactive black box, and a plurality of application cores, the memory device being connected to the main processor via a data communication bus and storing a bootloader and application code intended to be executed by the main processor on the plurality of application cores, the bootloader comprising a plurality of startup sequences and being configured to, when executed by the main processor: request authentication and verification of the integrity of the application code stored in the memory device, and being configured to execute the application code on the plurality of application cores when the application code has been authenticated, the interactive black box comprising a security coprocessor and a memory, the security coprocessor being connected to the main processor and the memory device via a data communication bus, and being configured to authenticate and verify the integrity of the application code stored in the memory device, and being configured to authorize the execution of the application code on the plurality of application cores, the application cores being connected to the main processor via a data communication bus, the memory of the interactive black box storing support information code, the support information code being intended to be executed by the main processor on the plurality of application cores, and being configured to implement at least one diagnostic function of the electronic control unit when executed by the main processor, and in that the security coprocessor is further configured to: authenticate and verify the integrity of the bootloader within the plurality of application cores, and if the bootloader is not authenticated, download the support information code from the memory of the interactive black box to the memory device to install the support information code in place of the first startup sequence of the bootloader, and cause the main processor to execute the support information code on the plurality of application cores.

[0006] Thanks to the presence of the support information code configured as such in the memory of the interactive black box, the electronic control unit for a vehicle according to the present invention provides the user or the vehicle manufacturer with the possibility of understanding the reason why the bootloader and the application code are no longer executed within the system while also allowing the electronic control unit to continue to execute in a dedicated mode in order to provide communication and diagnostic means with the outside. Such diagnostic means directly loaded in the electronic control unit advantageously allows reducing the cost and time for diagnosing and handling possible hardware failures or malicious intrusions in the system, and avoids having to take the unit out of service when the origin of the unauthenticated bootloader is unknown.

[0007] According to a specific technical feature of the present invention, the memory of the interactive black box is a non-volatile memory, preferably a flash memory. Such a non-volatile memory is only readable and writable by the security coprocessor, which allows improving the security of the electronic control unit, especially with regard to the use and authentication of the support information code.

[0008] According to another specific technical feature of the present invention, the memory device comprises a non-volatile memory, preferably a flash memory.

[0009] According to another specific technical feature of the present invention, the data communication bus is a CAN (Controller Area Network in English) bus or a bus compliant with the Ethernet protocol.

[0010] Advantageously, the compressed image of the support information code is stored in the memory of the interactive black box. This allows optimizing the consumption of memory resources within the interactive black box.

[0011] Advantageously, the support information code is stored in the application part of the memory of the interactive black box. This allows facilitating the update of the support information code by the end user of the electronic control unit or the vehicle manufacturer.

[0012] Advantageously, the security coprocessor is also configured to authenticate the support information code and verify its integrity. This allows further improving the security related to the use of the support information code within the electronic control unit.

[0013] According to a specific technical feature of the present invention, the security coprocessor is also configured to execute instructions for re - initializing the electronic control unit.

[0014] Advantageously, the support information code is also configured to, when executed by the main processor, implement the following functions: uploading the application code from the memory device to the memory of a third - party device connected to the electronic control unit. This allows the user of the third - party device to be able to restore the possibly damaged application code. The memory of such a third - party device is, for example, a random access memory (mémoire vive) block or still a non - volatile storage device of the flash memory type. Advantageously, the support information code is configured to be able to verify the integrity and authenticity of the application code uploaded to the memory of the third - party device.

[0015] The present invention also relates to an operating method for an electronic control unit of a vehicle as described above, the method comprising the following steps:

[0016] - Verifying, by the security coprocessor, the integrity of the bootloader among the plurality of application cores;

[0017] - If the verification of the integrity of the bootloader among the plurality of application cores is affirmative, then authenticating, by the security coprocessor, the bootloader, and:

[0018] ο Sending, by the bootloader, a request for authentication and verification of the integrity of the application code stored in the memory device, destined for the security coprocessor;

[0019] ο Authenticating, by the security coprocessor, and verifying the integrity of the application code stored in the memory device;

[0020] ο The security coprocessor authorizes the execution of the application code on the multiple application cores; and

[0021] ο The main processor executes the application code on the multiple application cores via a bootloader;

[0022] - If the verification of the integrity of the bootloader in the multiple application cores is negative, then:

[0023] ο The security coprocessor downloads support information code from the memory of the interactive black box to a memory device;

[0024] ο The security coprocessor installs the support information code to replace the first startup sequence of the bootloader; and

[0025] ο The main processor executes the support information code on the multiple application cores. Advantageously, if the verification of the integrity of the bootloader in the multiple application cores is negative, the method further includes the steps of authenticating the support information code and verifying its integrity by the security coprocessor. This allows for further improvement in the security related to the use of support information code within the electronic control unit.

[0026] According to a specific technical feature of the present invention, if the verification of the integrity of the bootloader in the multiple application cores is negative, the method further includes the step of the security coprocessor executing instructions for re - initializing the electronic control unit. After this re - initialization, the electronic control unit can no longer communicate externally in order to provide communication and diagnostic means to the user or vehicle manufacturer by executing the support information code.

[0027] According to a specific implementation variant of the present invention, the step of the security coprocessor verifying the integrity of the bootloader within the multiple application cores includes: verifying the integrity of the first startup sequence of the bootloader in the multiple application cores; and verifying the integrity of the flash bootloader module in the multiple application cores. Only when the results of both verifications are positive is the verification of the integrity of the bootloader in the multiple application cores positive.

[0028] The present invention also relates to a computer program product that includes a set of program code instructions which, when executed by a processor, configure the processor to implement one or more steps of the method described above. The computer program product constitutes support information code, and the processor is the main processor.

[0029] The embodiments of the present invention will be described below by way of non - limiting examples with reference to the accompanying drawings, in which:

[0030] - Figure 1 is a schematic representation of an electronic control unit for a vehicle according to the present invention; and

[0031] - Figure 2 is a logic diagram illustrating Figure 1 the operating method of the electronic control unit.

[0032] Referring to Figure 1 ,, Figure 1 illustrates an electronic control unit 2 according to an embodiment of the present invention. The electronic control unit 2 is installed in a vehicle, in particular a motor vehicle (such a vehicle is not shown in the figures for clarity reasons), and is for example intended to drive specific physical elements of the vehicle, in particular such as a control motor or also an electrical storage battery. The electronic control unit 2 is for example a microcontroller implanted on a specific chip, which is not limited within the framework of the present invention.

[0033] The electronic control unit 2 includes a main processor 4, a memory device 6, an interaction black box 8 and a plurality of application cores 10. The information system 2 also includes a data communication bus 12 connecting these various elements. The memory device 6 is connected to the main processor 4 via the data communication bus 12 and stores an application code 13, the application code 13 being intended to be executed by the main processor 4 on the application cores 10 in order to in particular allow driving specific software blocks of the various physical elements belonging to the aforementioned vehicle. The memory device 6 also stores a bootloader 18, for example stored in a region or partition different from the region or partition for storing the application code 13. The memory device 6 typically includes a non-volatile memory, preferably a flash memory, in which the application code 13 and the bootloader 18 are stored (under different partitions and / or in different layers).

[0034] The bootloader 18 is presented in the form of a program code, in other words, in the form of an information instruction set intended to be executed by the main processor 4. More precisely, the bootloader 18 corresponds to a software layer that is not the application code 13, includes a plurality of startup sequences, and is configured to request authentication of the application code 13 and verification of integrity when executed by the main processor 4, and is configured to execute the application code 13 on the application cores 10 when the application code 13 has been authenticated.

[0035] The interactive black box 8 includes a secure coprocessor 20 and a memory 22 that stores support information code 24. The secure coprocessor 20 is connected to the main processor 4 and the memory device 6 via a data communication bus 12. The secure coprocessor 20 is configured to authenticate and verify the integrity of the application code 13 stored in the memory device 6, and is configured to authorize the execution of the application code 13 on the application core 10. As will be described in detail later, the secure coprocessor 20 is also configured to authenticate and verify the integrity of the boot loader 18 within the application core 10, and if the boot loader 18 is not authenticated, download the support information code 24 from the memory 22 of the interactive black box 8 to the memory device 6 to install the support information code 24 in place of the first startup sequence of the boot loader 18, and cause the support information code to be executed by the main processor 4 on the application core 10. Preferably, the secure coprocessor 20 is also configured to authenticate and verify the integrity of the support information code 24. Also preferably, the secure coprocessor 20 is also configured to execute instructions for reinitializing the electronic control unit 2.

[0036] The memory 22 of the interactive black box 8 is typically a non-volatile memory, preferably a flash memory. The support information code 24 is intended to be executed on the application core 10 by the main processor 4, and is configured to implement at least one diagnostic function of the electronic control unit 2 when executed by the main processor 4. Preferably, in addition to the diagnostic function of the electronic control unit 2, the support information code 24 is also configured to implement the following functions when executed by the main processor 4: uploading the application code 13 from the memory device 6 to the memory of a third-party device connected to the information system 2 (for clarity, such a third-party device is not shown in Figure 1 ). Also preferably, a compressed image of the support information code 24 is stored in the memory 22 of the interactive black box 8. Also preferably, the support information code 24 is stored in the application portion of the memory 22 of the interactive black box 8.

[0037] The data communication bus 12 is typically a CAN (Controller Area Network in English) bus or a bus compliant with the Ethernet protocol, which is not limited in the framework of the present invention.

[0038] Now will be referred to Figure 2 Describe an operating method of the electronic control unit 2 according to an embodiment of the present invention.

[0039] The method includes an initial step 30, during which the interactive black box 8 is initialized by the main processor 4.

[0040] The method includes the following step 32, during which the secure co-processor 20 verifies the integrity of the boot loader 18 within the application core 10. Preferably, verifying 32 the integrity of the boot loader 18 within the application core 10 includes verifying the integrity of the first startup sequence of the boot loader 18 within the application core 10, and verifying the integrity of the flash boot loader module within the application core 10.

[0041] If the verification 32 of the integrity of the boot loader 18 within the application core 10 is affirmative (in other words, when and only when the results of the two verifications mentioned above are affirmative), the secure co-processor 20 authenticates the boot loader 18, and the method proceeds to the next step 34. Otherwise (in other words, if at least one of the two verifications mentioned above is negative), the secure co-processor 20 does not authenticate the boot loader 18, and the method proceeds to the next step 36.

[0042] During step 34, the main processor 4 initializes the boot loader 18. The method then includes the following step 38, during which the boot loader 18 sends a request to the secure co-processor 20 to authenticate and verify the integrity of the application code 13 stored in the memory device 6.

[0043] During step 40, which comes after step 38, the secure co-processor 20 verifies the integrity of the application code 13 stored in the memory device 6. In Figure 2 a particular embodiment, the application code 13 is divided into high-level application code and application code for reprogramming the high-level application code. According to this particular embodiment, step 40 thus begins with a stage 41 of verifying the integrity of the high-level application code stored in the memory device 6.

[0044] If the stage 41 of verifying the integrity of the high-level application code is affirmative, the secure co-processor 20 authenticates the high-level application code and authorizes the execution of the high-level application code on the application core 10, and the method proceeds to the next step 42. Otherwise, the secure co-processor 20 does not authenticate the high-level application code, and the method proceeds to the next stage 44.

[0045] During step 42, the main processor 4 executes the high-level application code on the application core 10 via the boot loader 18.

[0046] During stage 44, the boot loader 18 sends a request to the secure co-processor 20 to authenticate and verify the integrity of the application code for reprogramming stored in the memory device 6.

[0047] During stage 46 after stage 44, the security coprocessor 20 verifies the integrity of the application code for reprogramming stored in the memory device 6.

[0048] If the verification 46 of the integrity of the application code for reprogramming is affirmative, the security coprocessor 20 authenticates the application code for reprogramming and authorizes the execution of the application code for reprogramming on the application core 10, and the method proceeds to the next step 48. Otherwise, the security coprocessor 20 does not authenticate the application code for reprogramming and does not authorize the execution of the application code for reprogramming on the application core 10. During step 48, the main processor 4 executes the application code for reprogramming on the application core 10 via the bootloader 18.

[0049] During step 36, the security coprocessor 20 downloads the support information code 24 from the memory 22 of the interactive black box 8 to the memory device 6.

[0050] Preferably, during step 50 after step 36, the security coprocessor 20 verifies the integrity of the support information code 24 and authenticates the support information code 24 if necessary.

[0051] During step 52 after step 50, the security coprocessor 20 installs the support information code 24 to replace the first startup sequence of the bootloader 18.

[0052] Preferably, during step 54 after step 52, the security coprocessor 20 executes instructions for re-initializing the electronic control unit 2.

[0053] During step 56 after step 54, the main processor 4 restarts in an authenticity session and executes the support information code 24 on the application core 10. Executing the support information code 24 on the application core 10 thus allows the implementation of at least one diagnostic function in order to enable external communication with the electronic control unit 2 and to allow the user of the unit 2 or the vehicle manufacturer to understand the reason why the bootloader 18 and the application code 13 are no longer executed within the system and / or to attempt to perform an update of the application code 13 within the unit 2. According to a particular embodiment of the invention, executing the support information code 24 on the application core 10 may also allow the uploading of the application code 13 from the memory device 6 to the memory of a third-party device connected to the electronic control unit 2 (for reasons of clarity, such a third-party device is not represented in the figures). According to this particular embodiment, the third-party device is for example a random access memory block or still a non-volatile storage device of the flash memory type. The support information code 24 may be configured, for example, to be able to authenticate and verify the integrity of the application code 13 uploaded to the memory of the third-party device.

[0054] The electronic control unit 2 for a vehicle according to the present invention provides the user or the vehicle manufacturer with the possibility of understanding the reasons why the bootloader and the application code are no longer executed within the system while also allowing the electronic control unit to continue to execute in a dedicated mode in order to provide communication and diagnostic means with the outside.

Claims

1. An electronic control unit (2) for a vehicle, the electronic control unit (2) comprising a main processor (4), a memory device (6), an interactive black box (8) and a plurality of application cores (10), the memory device (6) being connected to the main processor (4) via a data communication bus (12) and storing a bootloader (18) and application code (13) intended to be executed by the main processor (4) on the plurality of application cores (10), the bootloader (18) comprising a plurality of startup sequences and being configured to, when executed by the main processor (4): request authentication and verification of integrity of the application code (13) stored in the memory device (6), and being configured to execute the application code (13) on the plurality of application cores (10) when the application code (13) has been authenticated, the interactive black box (8) comprising a security coprocessor (20) and a memory (22), the security coprocessor (20) being connected to the main processor (4) and the memory device (6) via a data communication bus (12), and being configured to authenticate and verify the integrity of the application code (13) stored in the memory device (6), and being configured to authorize execution of the application code (13) on the plurality of application cores (10), the application cores (10) being connected to the main processor (4) via a data communication bus (12), characterized in that, The memory (22) of the interactive black box (8) stores a support information code (24), which is intended to be executed by the main processor (4) on the plurality of application cores (10), and is configured to implement at least one diagnostic function of the electronic control unit (2) when executed by the main processor (4). The secure co-processor (20) is further configured to: authenticate and verify the integrity of the bootloader (18) within the plurality of application cores (10), and if the bootloader (18) is not authenticated, download the support information code (24) from the memory (22) of the interactive black box (8) to the memory device (6) to install the support information code (24) in place of the first startup sequence of the bootloader (18), and cause the main processor (4) to execute the support information code (24) on the plurality of application cores (10).

2. The electronic control unit (2) according to claim 1, characterized in that The memory (22) of the interactive black box (8) is a non-volatile memory, preferably a flash memory.

3. The electronic control unit (2) according to claim 1 or 2, characterized in that, A compressed image of the support information code (24) is stored in the memory (22) of the interactive black box (8).

4. The electronic control unit (2) according to any one of claims 1 to 3, characterized in that, The support information code (24) is stored in the application part of the memory (22) of the interactive black box (8).

5. The electronic control unit (2) according to any one of claims 1 to 4, characterized in that, The secure co-processor (20) is further configured to authenticate and verify the integrity of the support information code (24).

6. The electronic control unit (2) according to any one of claims 1 to 5, characterized in that, The secure co-processor (20) is further configured to execute instructions for re-initializing the electronic control unit (2).

7. The electronic control unit (2) according to any one of claims 1 to 6, characterized in that, The support information code (24) is further configured to, when executed by the main processor (4), implement the following function: upload the application code (13) from the memory device (6) to the memory of a third-party device connected to the electronic control unit (2).

8. A method for operating an electronic control unit (2) for a vehicle according to any one of claims 1 to 7, characterized in that, The method includes the following steps: - verifying (32) the integrity of the bootloader (18) in the plurality of application cores (10) by the secure co-processor (20); - if the verification (32) of the integrity of the bootloader (18) in the plurality of application cores (10) is affirmative, authenticating the bootloader by the secure co-processor, and: ο sending (38) a request for authentication and integrity verification of the application code (13) stored in the memory device (6) by the bootloader (18) to the secure co-processor (20); ο authenticating and verifying (40, 41, 44, 46) the integrity of the application code (13) stored in the memory device (6) by the secure co-processor (20); ο authorizing the execution of the application code (13) on the plurality of application cores (10) by the secure co-processor (20); and ο executing (42, 48) the application code (13) on the plurality of application cores (10) by the main processor (4) via the bootloader (18); - If the verification (32) of the integrity of the bootloader (18) in the plurality of application cores (10) is negative, then: ο The security coprocessor (20) downloads (36) the support information code (24) from the memory (22) of the interactive black box (8) to the memory device (6); ο The security coprocessor (20) installs (52) the support information code (24) to replace the first startup sequence of the bootloader (18); and ο The main processor (4) executes (56) the support information code (24) on the plurality of application cores (10).

9. The method according to claim 8, wherein If the verification (32) of the integrity of the bootloader (18) in the plurality of application cores (10) is negative, the method further includes the step (50) of the security coprocessor (20) authenticating the support information code (24) and verifying its integrity.

10. The method according to claim 8 or 9, characterized in that, If the verification (32) of the integrity of the bootloader (18) in the plurality of application cores (10) is negative, the method further includes the step (54) of the security coprocessor (20) executing instructions for reinitializing the electronic control unit (2).

11. The method according to any one of claims 8 to 10, characterized in that, The step of the security coprocessor (20) verifying (32) the integrity of the bootloader (18) in the plurality of application cores (10) includes: verifying the integrity of the first startup sequence of the bootloader (18) in the plurality of application cores (10); and verifying the integrity of the flash bootloader module in the plurality of application cores (10). The verification (32) of the integrity of the bootloader (18) in the plurality of application cores (10) is positive if and only if the results of the two verifications are positive.

12. A computer program product (24), characterized in that, It includes a set of program code instructions that, when executed by a processor (4), configure the processor to implement one or more of the steps of the method according to any one of claims 8 to 11. The computer program product constitutes the support information code (24), and the processor is the main processor (4).