Sensor

By introducing hardware security modules to the sensor to store encryption keys and combining structural shielding measures, the unauthorized access problem of vehicle sensor systems is solved, and the secure and reliable transmission and storage of data is achieved, ensuring the security of the vehicle system.

CN120455961APending Publication Date: 2025-08-08KNORR BREMSE SYSTEME FUER NUTZFAHIZEUGE GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510132391.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-02-06
Filing Date
2025-02-06
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing vehicle sensor systems have security risks of unauthorized access, and it is difficult to effectively prevent unauthorized data access and tampering.

Method used

The hardware security module is introduced into the sensor to store the encryption key, and data encryption and decryption verification is carried out through the processing device. At the same time, structural masking measures are used to prevent wireless access and ensure the security of the sensor.

Benefits of technology

It realizes the secure and reliable transmission and storage of sensor data, prevents unauthorized access and tampering, and ensures safe and reliable communication of the vehicle system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455961A_ABST
    Figure CN120455961A_ABST
Patent Text Reader

Abstract

The invention relates to a sensor (1) for a vehicle, in particular a commercial vehicle, comprising: a housing (11), a measurement interface (2), which is designed to detect a measurement variable of the vehicle and to generate raw measurement data (3) describing the measurement variable, and a sensor (3), which is designed to detect the measurement variable of the vehicle, -processing means (4) which are designed to process the raw measurement data (3) into measurement data (5); a data interface (6) which is designed for data exchange of the sensor (1) with another transmitter or receiver and is connected to the processing means (4) for the data exchange; a storage section (7), which is designed to store at least one encryption key (8) and to provide the at least one encryption key exclusively to the processing means (4), the processing means (4) being designed to store the at least one encryption key (8) and to provide the at least one encryption key (8) only to the processing means (4). Data sent or received via the data interface (6) is encrypted, decrypted or verified by means of the at least one key (8), the storage section (7) being designed as a hardware security module or in a hardware security module. Further, a system, a vehicle and a method are disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a sensor for detecting a measured variable of a vehicle. The invention also relates to a system, a vehicle and a method. Background Art

[0002] The increasing digitalization of vehicles offers a variety of advantages. Primarily, it enables the implementation of safety functions such as electronic stability control or brake regulation. Existing functions, such as vehicle level control or oil level measurement, can also be simplified. To enable the updating of these functions in existing vehicles—for example, to correct software errors or simply install new software versions—it is necessary to expose the vehicle's software and / or hardware architecture to the outside world via appropriately designed interfaces, enabling appropriate access.

[0003] However, these interfaces, as well as data lines that are not conceived as interfaces but that enable access, for example, wirelessly or via subsequently soldered connections, also offer the possibility of unauthorized access to the digital vehicle system or at least to its subsystems, such as electronic stability control, brake control, or other of the aforementioned functions. Hereinafter, measures for increasing the threshold for preventing such unauthorized access will be referred to as "measures for increasing network security," where "network security" itself describes the threshold for preventing such unauthorized access.

[0004] Legislation already takes cybersecurity or its improvement into account. For example, there are regulations concerning the security of vehicles against cyberattacks (e.g., UNECE R 155) and regulations describing the requirements for updating software in vehicle controllers (UNECE R 156). The latter regulation, in particular, requires vehicle manufacturers to provide a Software Update Management System (SUMS). SUMS should ensure that updates to software functions crucial for type approval (e.g., exhaust, brake, and engine control) are developed and validated in such a way that they continue to function in a legally compliant manner even after the update. Furthermore, UNECE R 156 requires such updates to be "safe and reliable," without further elaboration. The term "safe" refers to security against functional faults (bugs) in the software itself. The term "reliable" refers to security against tampering during the update process. Thus, for example, update mechanisms should prevent the installation of malicious software and debugging software, both of which constitute unauthorized access. Summary of the Invention

[0005] The object of the present invention is therefore to propose measures in order to increase network security, in particular in the case of sensors.

[0006] This object is achieved by the subject matter of the independent claim. Advantageous developments are the subject matter of the dependent claims.

[0007] A sensor for a vehicle, in particular a commercial vehicle, is disclosed. The sensor comprises the following elements:

[0008] -case;

[0009] a measuring interface, which is designed to detect a measured variable of the vehicle and is designed to generate raw measurement data describing the measured variable;

[0010] a processing device configured to process the raw measurement data into measurement data;

[0011] The sensor preferably further comprises the following elements:

[0012] a data interface, which is designed for exchanging data between the sensor and other transmitters or receivers and is connected to the processing device for this data exchange;

[0013] a memory section which is designed to store at least one encryption key and to make the at least one encryption key available only to the processing device, wherein

[0014] The processing device is designed to encrypt, decrypt or authenticate data sent or received via the data interface using at least one key, wherein:

[0015] The memory section is designed as a hardware security module or is designed in a hardware security module.

[0016] Arranging the at least one key in a hardware security module configured as a memory section has the advantage that the at least one key is thereby protected against unauthorized access. Without a corresponding counterpart, the at least one key can prevent unauthorized reading or modification of data, such as measurement data, raw measurement data, or sensor software.

[0017] The hardware security module can be implemented in particular via SHE (Secure Hardware Extension) or via the Evita Lite, Intermediate or Full version standard.

[0018] The hardware security module makes it possible to implement encryption functions for data exchange, in particular via the data interface of the sensor.

[0019] The storage section can be configured as a memory that is structurally separate from the processing device. As a result, the storage section can be placed relatively freely in the housing of the sensor.

[0020] Alternatively, it may be provided that the memory section and the processing device are designed as a structural unit. This provides a complete module that can be easily installed in the sensor housing. The processing device can be designed at least partially, and preferably completely, as part of a hardware security module. This protects the critical functions of the sensor that are implemented using the processing device.

[0021] Preferably, the data received via the data interface is application data or program code, or these data contain application data or program code. In this way, the sensor can be updated. Preferably, the processing device is configured to verify the data received via the data interface. To this end, the data preferably contains an encryption key, a hash value, or an encrypted signature. These encryption keys, hash values, or encrypted signatures can be compared by the processing device with encryption keys, hash values, or encrypted signatures stored in a storage segment. If the comparison shows that the key, hash value, or encrypted signature of the data is as expected by the processing device, the processing device will evaluate the received data as correct and credible and initiate corresponding actions, such as installing or accepting application data or updating the sensor software.

[0022] Preferably, the data transmitted via the data interface are measurement data or status information of the sensor, or these data contain such measurement data or status information. In this case, the sensor, preferably the processing device, is designed to provide the transmitted data with an encryption key, a hash value, or an encrypted signature from the hardware security module, in particular from a memory section, so that other receivers can perform a corresponding comparison of the keys in order to ensure that the sensor can be trusted as a data source and that the transmitted data is correct.

[0023] This can be implemented within the framework of secure onboard communication (SecOC), so that the communication between sensors and other receivers can be carried out securely and reliably.

[0024] Preferably, at least one key is associated with the sensor's identification and / or a manufacturer-specific identification and / or a customer-specific identification. This allows a correspondingly configured system, such as the one described further below, in which the sensor is located to check whether the sensor is intended for or configured for the system. This allows for the identification of unsuitable copies or impermissible configurations of the sensor. The system can then be configured to discontinue use of the sensor. Further conceivable measures for corresponding systems are described further below.

[0025] Alternatively or additionally, within the framework of a method for checking the permissibility of a combination of such a system and such a sensor for a vehicle, a check can be performed to determine whether the sensor is intended for the system or is configured for the system. For example, such a method is described further below. This makes it possible to perform a corresponding check during or before assembly of the sensor and system. This check can thus be performed at an early stage in the manufacturing process, for example, at a parts supplier that manufactures or assembles the system and sensor combination. For this purpose, the required key and other information can be provided to the parts supplier by, for example, the client (e.g., the vehicle manufacturer) or the supplier.

[0026] The sensor's identification identifier is preferably a part number and / or serial number and / or vehicle identification number and / or ECU ID and / or manufacturer's name. These part numbers and / or serial numbers and / or vehicle identification numbers and / or ECU ID and / or manufacturer's name are uniquely assigned to the sensor by the manufacturer during production or later during vehicle manufacture or assembly. These numbers can thus be used to identify permitted sensors, or, possibly, to identify inadmissible sensors based on errors in these numbers. In particular, sensors can be assigned to specific vehicles or systems, such as braking systems or driving dynamics control systems.

[0027] The memory segment is preferably designed to store program components of the processing device and / or raw measurement data and / or measurement data in the memory segment, wherein the program components and / or raw measurement data and / or measurement data are authorized using at least one key. This protects this type of information and prevents it from being used without the corresponding encryption key. Unauthorized access is thus prevented.

[0028] Preferably, the sensor, in particular the processing device, is designed to check the authenticity of the transmitter of data or communications directed to the sensor, which are provided with an encryption key and received via an interface, or of communications received via an interface. The sensor, in particular the processing device, is further preferably designed to output a notification via the interface, deactivate the sensor itself or the system in which it is located, or place the sensor in a safe and reliable state if the sender's origin, received data, or communications directed to the sensor are classified as untrustworthy. This prevents the use of undesired application data or undesired program code by the sensor, in particular the processing device.

[0029] The following describes a possible way to structurally protect the sensor from unwanted or unauthorized access from the outside, in particular from unwanted wireless access from the outside. This can be done in conjunction with the above-described embodiment of the sensor or independently thereof. The sensor already described above is to be understood as a common element not only of the sensors described above but also of the sensors described below:

[0030] A sensor for a vehicle is disclosed. The sensor comprises the following elements:

[0031] -case;

[0032] a measuring interface, which is designed to detect a measured variable of the vehicle and is designed to generate raw measurement data describing the measured variable;

[0033] a processing device configured to process the raw measurement data into measurement data;

[0034] The sensor is preferably protected, in particular structurally protected, against unauthorized access.

[0035] The sensor preferably has at least one protective measure against unauthorized access, in particular a structural protective measure.

[0036] Preferably, at least one subarea or the entire sensor is structurally shielded against wireless access, in particular unauthorized wireless access. To this end, at least one subarea or the entire sensor includes a shield against wireless access as a structural protective measure. Wireless access can be understood as inductive, capacitive, and / or optical access. Advantageously, a corresponding shield is provided to shield the electromagnetic field generated by the current flow within the sensor, thereby preventing external access to the data within the sensor. It is also advantageous if the shield prevents external access via the electromagnetic field. In this way, unauthorized access to the data within the sensor, or even tampering with the data, is eliminated. The shield against optical access can, in particular, relate to a measuring interface that can be configured for optically detecting a measured variable. In this way, appropriately positioned shielding elements can prevent the detection of the measured variable from being distorted by light or radiation. The corresponding shield can also prevent damage to light-sensitive sensor components (such as chips, semiconductors, resistors, or diodes).

[0037] Preferably, the shielding of the sub-areas is achieved by shielding elements, which are arranged within the housing of the sensor or in or on one or more walls of the housing. These shielding elements can be made of special alloys that effectively shield electromagnetic fields. Preferably, the shielding elements are positioned so as to completely or at least partially and to a sufficient extent shield the following areas: at which the corresponding wireless coupling elements can be placed. If the housing is made of plastic, the shielding elements can be cast into the plastic material of the housing. If the shielding elements are applied to the walls of the housing (inner or outer walls), this can be achieved in particular by gluing, plugging, or clamping. Alternatively, the housing of the sensor consists of the shielding elements. This then enables comprehensive and complete shielding. If the shielding elements are arranged within the housing, they can preferably form the encapsulation of the sub-areas, so that the housing is then particularly preferably located within the housing.

[0038] Alternatively or additionally, it can be provided that the shielding of the subareas is achieved by a multi-layer construction of the sensor, and that the subarea to be shielded is shielded by a layer of another component of the sensor arranged above the subarea or by a correspondingly arranged shielding element. In particular, it can be provided that the sensor has a multi-layer PCB construction (printed circuit board construction) in the housing. In this case, specific lines or components to be shielded, such as communication lines or debugging lines, can be shielded by other elements printed above or arranged above and insulated from the lines or components, such as power supply lines.

[0039] It is also possible to provide a layered structure formed from multiple circuit boards. Here, the circuit board to be shielded can be positioned so that it is covered by the other circuit boards relative to the nearest housing wall. Furthermore, shielding elements, preferably plate-shaped shielding elements, can also be incorporated into this layered structure.

[0040] Preferably, especially as a structural protective measure, the sensor is configured to disable this sensor when the housing is opened without authorization. This can be achieved in a non-destructive manner, so that when this sensor is activated again, for example, by using one or more encryption keys provided for this purpose, this sensor can be used again. But it is also possible to provide that the sensor is permanently disabled due to its damage. For example, this can be achieved by the targeted overload of the circuit of the sensor. The opening of the housing can be achieved by the detection device, for example sensor detection on the housing, if the housing is opened, then the detection device outputs a signal. It can be provided that, when receiving corresponding unpacking via the data interface by the sensor, the opening of the housing is allowed. At this, this can be verified by the key stored in the storage section again. Preferably, the detection device is configured on the housing and is configured to detect the opening of the housing. This sensor can be configured to be used for, when the housing is opened, by the detection device, corresponding signal outputs to the processing device or outputs to other receivers outside the sensor, for example, via the interface of the sensor.

[0041] Preferably, the sensor is an angle sensor, and the measured variable detected via the measurement interface is a measured variable describing the rotational movement of a rotatable element. The rotatable element can be, in particular, a steering column or a vehicle steering element from whose rotational movement the steering angle can be determined. In this case, the sensor is designed as a steering angle sensor.

[0042] Preferably, the sensor is a rotational speed sensor. Preferably, the measured variable detected via the measurement interface is the yaw rate of the vehicle on which the sensor is located. In this case, the sensor is designed as a yaw rate sensor. Alternatively or additionally, it can also be provided that the measured variable detected via the measurement interface is the pitch rate and / or roll rate of the vehicle.

[0043] Preferably, the sensor is an acceleration sensor, wherein the measured variable detected via the measurement interface is the acceleration of the vehicle in which the sensor is located. The acceleration sensor can be uniaxial or multiaxial, so that it can detect acceleration in only one axis (the longitudinal axis, the transverse axis, or the height axis of the vehicle) or in several or all three axis directions.

[0044] Preferably, the sensor is designed as a combination of the above-mentioned rotational speed sensor and the above-mentioned acceleration sensor. In particular, the sensor can be designed to detect not only the yaw rate, pitch rate and roll rate, but also the acceleration in all three axis directions.

[0045] The sensor is preferably a pressure sensor, wherein the measured variable detected via the measuring interface is pressure. The sensor may in particular be a brake pressure sensor. Thus, in the case of fluid-actuated brakes (e.g., pneumatic or hydraulic brakes), the brake pressure can be detected safely and reliably.

[0046] Preferably, the sensor is a force sensor, wherein the measured variable detected via the measurement interface is force. The sensor can, in particular, be a braking force sensor. This allows for safe and reliable detection of the braking force in fluid-actuated brakes (e.g., pneumatic or hydraulic brakes) as well as in electromechanically actuated brakes. The detected force can, in particular, be the application force of a friction brake.

[0047] Preferably, the sensor is a rotational speed sensor, wherein the measured variable detected via the measurement interface is the rotational speed. This can be the wheel rotational speed or the motor rotational speed. In particular, this can be an active rotational speed sensor.

[0048] The sensor is preferably a position sensor, wherein the measured variable detected via the measurement interface is, in particular, the position of a movable element. For example, the movable element is a shifting element of a transmission or an actuating element for actuating a clutch. In this way, the shifting position or clutch position in the transmission can be detected safely and reliably.

[0049] Preferably, the sensor is a level sensor, wherein the measured variable detected via the measuring interface is the level of the body of the vehicle in which the sensor is located. This can improve the safety of level control of such a vehicle.

[0050] Preferably, the sensor is an oil level sensor, wherein the measured variable detected via the measuring interface is the oil level. This may be the oil level of an electrically driven compressor.

[0051] The sensor is preferably designed to detect whether an unauthorized data connection is established or is established with the sensor. This can be verified by using a cryptographic key from a storage area or by a hash value or cryptographic signature generated by the processing device. If an unauthorized data connection is detected, the sensor is preferably designed to deactivate or place the data connection in a safe and secure state or to interrupt the data connection. The data connection can be CAN-based.

[0052] A system, in particular a control system, a regulating system, or a monitoring system, for a vehicle, in particular a commercial vehicle, having a sensor as described above is disclosed. The system is configured to determine whether the sensor is permitted to be used in the system by comparing at least one encryption key of the sensor with at least one encryption key of the system.

[0053] The system is preferably further designed to, if an impermissible sensor is detected by the system, deactivate the sensor, output a message, or deactivate the system or transfer the system to a safe and reliable state.

[0054] This prevents the use of sensors in the system that are not permitted for the system.

[0055] The system is preferably designed as a steering control system, for example, with a sensor designed as an angle sensor. Alternatively, the system can be designed as a vehicle dynamics control system, for example, with a sensor designed as an angle sensor, a rotational speed sensor, an acceleration sensor, a pressure sensor, a force sensor, and / or a rotational speed sensor. Alternatively, the system can be designed as a level control system, for example, with a sensor designed as a level sensor.

[0056] A vehicle, in particular a commercial vehicle, is disclosed, having a sensor as described above or having a system as described above.

[0057] A method for checking the admissibility of a combination of a system for a vehicle, in particular a control system, a regulating system or a monitoring system, with a sensor as described above is disclosed, wherein the method comprises the following steps:

[0058] - providing a system, in particular a system as described above, wherein the system has an encryption key;

[0059] - providing a sensor as described above;

[0060] - comparing at least one encryption key of the sensor with at least one encryption key of the system;

[0061] If it is determined via the comparison that the sensor is permissible for the system, the system is activated with the aid of the sensor.

[0062] In this way, it is possible to determine when first assembling a system and a sensor, whether to use a sensor that is permitted for the system. Later, when replacing a sensor due to maintenance work or repair work, this type of inspection can also be carried out. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Hereinafter, the present invention will be described in more detail with reference to the accompanying drawings.

[0064] Figure 1 A sensor according to a first embodiment is shown.

[0065] Figure 2 A sensor according to a second embodiment is shown. DETAILED DESCRIPTION

[0066] Figure 1 A sensor 1 according to a first embodiment is shown.

[0067] A sensor 1 for a vehicle is shown. The sensor 1 has the following elements:

[0068] - housing 11;

[0069] a measuring interface 2 , which is designed to detect a measured variable of the vehicle and is designed to generate raw measurement data 3 describing the measured variable;

[0070] a processing device 4 designed to process the raw measurement data 3 into measurement data 5;

[0071] a data interface 6 , which is designed for exchanging data between the sensor 1 and other transmitters or receivers and is connected to the processing device 4 for this data exchange;

[0072] a memory section 7 which is designed to store at least one encryption key and to make this encryption key available only to the processing device 4 , wherein

[0073] The processing device 4 is designed to encrypt, decrypt or authenticate data transmitted or received via the data interface 6 using at least one key, wherein

[0074] The memory section 7 is designed as a hardware security module or is designed in a hardware security module.

[0075] This key can be sent to the processing device 4 via the data connection 8 shown.

[0076] Measuring interface 2 has a detection device 2.1, which is designed to detect raw measurement data 3. Detection device 2.1 can be designed, in particular, to detect acceleration, rotational speed, pressure, force, or oil level. If a corresponding counterpart 2.2 is present, which can, for example, perform a relative movement (rotational or translational) relative to detection device 2.1, detection device 2.1 can be designed to detect rotational movements or angles or displacements, such as in the case of level changes or, for example, in the case of detecting the position of a movable element.

[0077] Figure 2 A sensor 1 according to a second embodiment is shown.

[0078] A sensor 1 is shown, which is used, in particular, to detect the steering angle of a vehicle. The sensor 1 has the following elements:

[0079] - housing 11;

[0080] a measuring interface 2 , which is designed to detect a rotational movement of a rotatably arranged element 10 of a vehicle and is designed to generate raw measurement data 3 describing this rotational movement;

[0081] A processing device 4 is designed to process the raw measurement data 3 into measurement data 5 .

[0082] The rotatable element 10 is designed as a steering column of a vehicle and is rotatable about a vertical imaginary axis.

[0083] Measuring interface 2 comprises a detection device 2.1 and a mating element 2.2, wherein mating element 2.2 is connected to element 10 and together performs a rotational movement. This is detected by detection device 2.1 and transmitted to processing device 4 as raw measurement data 3. Measuring interface 2 is shown here merely as an example. Other configurations are also possible. For example, measuring interface 2 may comprise an annular element that is coaxially and rotationally fixedly arranged relative to the axis of element 10, wherein its rotational movement is detected by detection device 2.1.

[0084] Furthermore, the sensor 1 has the following elements:

[0085] a data interface 6 , which is designed for exchanging data between the sensor 1 and other transmitters or receivers and is connected to the processing device 4 for this data exchange;

[0086] a memory section 7 which is designed to store at least one encryption key and to make this encryption key available only to the processing device 4 , wherein

[0087] The processing device 4 is designed to encrypt, decrypt or authenticate data transmitted or received via the data interface 6 using at least one key, wherein

[0088] The memory section 7 is designed as a hardware security module or is designed in a hardware security module.

[0089] The following description applies not only to Figure 1 The embodiment shown in Figure 2 The embodiment shown in .

[0090] In this case, the storage section 7 is arranged separately from the processing device 4 in a sub-area 9 which has the aforementioned shielding against wireless access (not shown).

[0091] The data interface 6 has a receiving section 6 . 1 , via which application data or program code can be sent to the sensor 1 , so that in particular the processing device 4 can be updated and maintained.

[0092] The data interface 6 has a measurement data section 6 . 2 , via which measurement data 5 and status information of the sensor 1 can be transmitted.

[0093] The storage section 7 enables safe and secure storage of at least one encryption key, wherein the at least one encryption key is additionally shielded against wireless access from the outside in a subregion 9 of the housing 11. This subregion can comprise a correspondingly structured alloy in or on the wall of the housing 11.

[0094] According to another embodiment (not shown), processing means 4 is arranged partially, preferably completely, in subregion 9 of housing 11 in order to protect important functions of sensor 1 that are implemented by processing means 4 .

[0095] exist Figure 1 and Figure 2 As a safeguard against unauthorized access, the sensor shown in FIG can be designed so that if housing 11 is opened without authorization, it is deactivated in the manner described above. This can be achieved in a non-destructive manner, so that when the sensor is reactivated, for example, using one or more encryption keys provided for this purpose, sensor 1 can be used again. However, it is also possible to permanently deactivate sensor 1 due to damage. This can be achieved, for example, by deliberately overloading the circuit of sensor 1.

[0096] Reference Signs List

[0097] 1 sensor

[0098] 2 measurement interfaces

[0099] 2.1 Detection Device

[0100] 2.2 Mating parts

[0101] 3 Original measurement data

[0102] 4 processing devices

[0103] 5 Measurement data

[0104] 6 data interface

[0105] 6.1 Receiving Section

[0106] 6.2 Measurement Data Section

[0107] 7 Storage Segments

[0108] 8 data connections

[0109] 9 sub-areas

[0110] 10 Elements arranged in a rotatable manner

[0111] 11 Shell

Claims

1. A sensor (1) for a vehicle, in particular a commercial vehicle, comprising: - housing (11), a measuring interface (2) which is designed to detect a measured variable of the vehicle and which is designed to generate raw measurement data (3) describing the measured variable; - a processing device (4) designed to process the raw measurement data (3) into measurement data (5); a data interface (6) which is designed for exchanging data between the sensor (1) and other transmitters or receivers and is connected to the processing device (4) for the data exchange; a memory section (7) which is designed to store at least one encryption key (8) and to make the at least one encryption key available only to the processing device (4), wherein The processing device (4) is designed to encrypt, decrypt or authenticate data sent or received via the data interface (6) using the at least one key (8), wherein: The memory section (7) is designed as a hardware security module or is designed in a hardware security module.

2. The sensor (1) according to claim 1, wherein The storage section (7) is designed as a memory structurally separate from the processing device (4).

3. The sensor (1) according to claim 1, wherein The storage section (7) and the processing device (4) are designed as a structural unit.

4. The sensor (1) according to any one of the preceding claims, wherein The data received via the data interface (6) is or contains application data or program code.

5. The sensor (1) according to any one of the preceding claims, wherein The data sent via the data interface (6) are either measurement data (5) or status information of the sensor (1).

6. The sensor (1) according to any one of the preceding claims, wherein The at least one key (8) is associated with an identification of the sensor (1) and / or with a manufacturer-specific identification and / or with a customer-specific identification, wherein: The identification of the sensor (1) is preferably a part number and / or a serial number and / or a vehicle identification number and / or an ECU ID and / or a manufacturer's name.

7. The sensor (1) according to any one of the preceding claims, wherein The memory section (7) is designed to store a program part of the processing device (4) and / or the raw measurement data (3) and / or the measurement data (5) in the memory section, wherein the program part and / or the raw measurement data and / or the measurement data are authorized by means of the at least one key (8).

8. The sensor (1) according to any one of the preceding claims, wherein The sensor (1), in particular the processing device (4), is designed to check the plausibility of the data or the communication sent by the transmitter of the data or the communication directed to the sensor (1), wherein the data is provided with an encryption key and the data is received via the interface (6), and the communication is received via the interface (6), wherein: The sensor (1) is further preferably designed to output a notification via the interface (6) or to deactivate the sensor itself or the system in which the sensor (1) is located or to place the sensor in a safe and reliable state when the sending origin or the received data or the communication directed to the sensor (1) is classified as untrustworthy.

9. The sensor (1) according to any one of the preceding claims, wherein At least one sub-region (9) or the entire sensor (1) has a shield against wireless access as a structural protective measure.

10. The sensor (1) according to claim 9, wherein The shielding of the sub-region (9) is achieved by a shielding element which is arranged in the housing of the sensor (1) or in or on one or more walls of the housing (11), or wherein The housing of the sensor (1) consists of a shielding element.

11. The sensor (1) according to claim 9 or 10, wherein: The shielding of the sub-region (9) is achieved by a multi-layer construction of the sensor (1), and the sub-region (9) to be shielded is shielded by a layer of another component of the sensor (1) arranged above the sub-region or by a correspondingly arranged shielding element.

12. The sensor (1) according to any one of the preceding claims, in, The sensor (1) is configured to be deactivated when the housing (11) is opened without authorization.

13. The sensor (1) according to any one of the preceding claims, wherein The sensor (1) is designed as a protective measure to detect whether an unauthorized data connection to the sensor (1) is or has been established.

14. The sensor (1) according to any one of the preceding claims, wherein The sensor (1) is an angle sensor, and the measured variable detected via the measuring interface (2) is a measured variable describing the rotational movement of a rotatably arranged element (10), wherein the rotatably arranged element (10) is in particular a steering column or an element of a vehicle steering system from which the steering angle can be determined, or wherein: The sensor (1) is a rotational speed sensor, wherein the measured variable detected via the measurement interface (2) is in particular the yaw rate, pitch rate and / or roll rate of the vehicle in which the sensor (1) is located, or wherein The sensor (1) is an acceleration sensor, wherein the measured variable detected via the measurement interface (2) is acceleration, or wherein: The sensor (1) is a pressure sensor, wherein the measured variable detected via the measuring interface (2) is pressure, or wherein: The sensor (1) is a force sensor, wherein the measured variable detected via the measuring interface (2) is force, or wherein: The sensor (1) is a rotational speed sensor, wherein the measured variable detected via the measuring interface (2) is the rotational speed, or wherein: The sensor (1) is a position sensor, wherein the measured variable detected via the measuring interface (2) is in particular the position of a movable element, or wherein The sensor (1) is a level sensor, wherein the measured variable detected via the measuring interface (2) is the level of the body of the vehicle in which the sensor (1) is located, or wherein The sensor (1) is an oil level sensor, wherein the measured variable detected via the measuring interface (2) is the oil level.

15. A system, in particular a control system, a regulating system or a monitoring system for a vehicle, in particular a commercial vehicle, having a sensor (1) according to any one of claims 1 to 14, wherein: The system is designed to determine, by comparing at least one encryption key (8) of the sensor (1) with at least one encryption key of the system, whether the sensor (1) is authorized for use in the system, and wherein: The system is preferably designed to, if an impermissible sensor is detected by the system, deactivate the sensor, output a message, or deactivate the system or transfer the system to a safe and reliable state.

16. A vehicle, in particular a commercial vehicle, comprising a sensor (1) according to any one of claims 1 to 14 or a system according to claim 15.

17. Method for checking the admissibility of a combination of a system, in particular a control system, a regulating system or a monitoring system, for a vehicle with a sensor (1) according to any one of claims 1 to 14, wherein: The method comprises the following steps: - providing the system, in particular the system according to claim 15, wherein the system has an encryption key; - providing a sensor (1) according to any one of claims 1 to 14; - comparing at least one encryption key (8) of the sensor (1) with at least one encryption key of the system; - enabling the system with the aid of the sensor (1) when it is determined via the comparison that the sensor (1) is permissible for the system.