Communication system and vehicle

By inserting a management unit into the vehicle communication line and utilizing its multi-mode and encryption protection mechanisms, the problem of insufficient protection in existing vehicle communication systems is solved, enabling fast and low-computational-load information flow management, and improving network security and the applicability of vehicle diagnostic protocols.

CN121220003APending Publication Date: 2025-12-26MERCEDES BENZ GRP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202480026883.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-15
Filing Date
2024-05-08
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing vehicle communication systems struggle to provide efficient and reliable protection without adjusting all control devices, especially for older models, particularly those lacking upgrade interfaces, to prevent malicious code intrusion and tampering.

Method used

A management unit is inserted into the communication lines inside the vehicle. This unit has at least two operating modes and selectively allows or blocks messages by using operating mode selection information attached to the message. The management unit can be implemented in dedicated hardware or software, supports the UDS protocol, and enhances security through encryption protection and decision tree logic.

Benefits of technology

It enables fast, low-computational-consumption information flow management, improves network security, reduces the number of accesses to control devices, lowers latency, simplifies decision-making processes, and is applicable to a wide range of vehicle diagnostic protocols.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121220003A_ABST
    Figure CN121220003A_ABST
Patent Text Reader

Abstract

The invention relates to a communication system comprising a vehicle-external response unit (1), at least one vehicle-internal control device (2), and a vehicle-internal management unit (4) inserted in a communication line (3) between the response unit (1) and the at least one control device (2), the management unit (4) providing a firewall function (5), in this way, messages (6) that can be exchanged between the response unit and the at least one control device can be selectively released or intercepted. The communication system according to the invention is characterized in that the management unit (4) has at least two operating modes, in which different sets of messages (6) to be released and intercepted are preset in each operating mode, and in which the messages (6) to be released and intercepted are stored in the management unit (4). The management unit (4) is designed to activate one of the operating modes on the basis of operating mode selection information (7) added to the message (6) by the response unit (1) or by the at least one control device (2).
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The invention relates to a communication system of the type defined more closely in the preamble of claim 1 and to a vehicle. BACKGROUND

[0002] Modern vehicles have a wide variety of computing units, such as control devices, central on-board computers, remote communication units, etc. These computing units both communicate with each other and with systems outside the vehicle. The communication can be realized by wired or wireless means. In particular, the connection of the computing units inside the vehicle with systems outside the vehicle offers an opportunity for attackers to intrude and tamper with components of the vehicle. In order to prevent malicious code from intruding into the on-board computing units, appropriate security measures must be taken.

[0003] For the exchange of information between two computing units, a verified and reliable control method is the use of a so-called firewall. A firewall is a security system that contains preset rules according to which it decides which information packets are allowed to be exchanged between the computing units and which are not. Thereby, unauthorized access can be prevented. The firewall can be realized as a software component running on a hardware component.

[0004] Due to the continuous improvement of the technology of attackers, as well as attack strategies and malicious code, the information security technology used also needs to be adjusted accordingly. If it is a newly produced vehicle, the current security requirements can be met directly during production. For vehicles already in use, their software can be updated, for example at a service visit, by means of a wireless upgrade or a wired connection. However, older vehicle models are more difficult to adapt to current security requirements, especially when these vehicles do not have a suitable upgrade interface. In particular, the adjustment of the on-board computing units should be kept within reasonable limits, i.e. the adjustment of the on-board computing units should be limited to as few computing units as possible. Here it must still be ensured that all computing units are reliably protected against attacks.

[0005] US 2020 / 0272735 A1 discloses a device for securing the transmission of diagnostic instructions to a control device of a vehicle and a corresponding vehicle. The patent document describes how a firewall is used to filter the exchanged information between the control device and a diagnostic tester. Here, the filtering of the information to be exchanged depends on the state of the hardware installed in the vehicle and the state of the software running on it. For example, diagnostic instructions can only be forwarded to specific control devices, only a completely specific series of diagnostic instructions is allowed to be forwarded, writing data to specific memory addresses of the control device is blocked, diagnostic instructions are suppressed when the frequency of sending diagnostic instructions exceeds a threshold value, or diagnostic instructions are only executed when the vehicle is in a specific state, for example when the vehicle is stationary.

[0006] Further, DE 10 2021 207 870 A1 discloses a method for managing diagnostic requests in a network and a computing unit. Here, a computing unit with firewall functionality is inserted into a vehicle internal communication network between a control device installed in the vehicle and an external communication interface. A diagnostic tester can establish a connection to the communication network via the external communication interface. The computing unit contains a configuration file which decides which diagnostic information is allowed to be exchanged between the diagnostic tester and the control device and which is not allowed to be exchanged depending on diagnostic requests received by the computing unit and on the active operating mode of the control device connected to the computing unit.

[0007] Further, US 2013 / 0081106 A1 discloses a security device for monitoring traffic in a data bus and a security system. The security device is connected in the data bus between an interface of a tool computing unit and a control device. The security device regulates data transmission between the tool computing unit and the control device. Here, the security device embeds an address of the control device into a response message fed back to the tool computing unit. SUMMARY

[0008] It is an object of the present application to provide an improved communication system.

[0009] According to the application, this object is achieved by a communication system having the features of claim 1. Advantageous design solutions and refinements as well as a vehicle comprising parts of the communication system are given in the dependent claims.

[0010] A generic communication system comprising an external response unit, at least one internal control device and an internal management unit inserted in a communication line between the response unit and the at least one control device, wherein the management unit provides a firewall functionality for selectively passing or blocking messages exchangeable between the response unit and the at least one control device, the improvement according to the application is that the management unit has at least two operating modes, wherein in each mode a different set of messages to be passed and messages to be blocked is preset, wherein the management unit is arranged to activate one of the operating modes depending on operating mode selection information appended in a message by the response unit or by the at least one control device.

[0011] Depending on the scenario, it is necessary to allow or prevent communication between the response unit and the control device. The response unit can be any vehicle-external computing unit. For example, it can be a laptop, tablet, desktop computer, etc. The response unit enables, for example, developers, workers during vehicle production, mechanics during vehicle maintenance, to respond to the control device of the vehicle. Accordingly, the right to access the control device should be granted. However, the response unit can also be used by an attacker, such as a hacker, to tamper with the control device of the vehicle. In this case, communication between the response unit and the control device should be limited.

[0012] The communication system according to the application provides a particularly efficient, thus fast and low-computing, method for preventing or permitting the flow of information between a response unit and a control device of a vehicle. The management unit thus has at least two operating modes, each of which describes a different total amount of messages that should be released or intercepted in the respective operating mode. Here, the messages transmitted via the communication line can be divided into different message types. The different message types are distinguished by specific content and / or specific target addresses. For example, this can be an instruction to the control device to perform or provide an operation or service. In response, the control device can provide information, for example. The message can also contain a software update, i.e. a code component of the software executable by the control device that needs to be added or modified. Here, each operating mode of the management unit defines which type of message is to be released or intercepted. This eliminates the need to exchange status information between the individual control devices and the management unit, which reduces the computing effort and shortens the latency time. This also improves network security, as the number of accesses to the control device is reduced. Because computing units are particularly vulnerable to attacks, such as voltage glitch attacks, when processing tasks.

[0013] Here, the operating mode selection information is transmitted together with the message itself. This further simplifies the decision-making process of which messages should be released and which should be intercepted. The response unit also does not need to establish a separate communication with the management unit and does not need to be individually configured for this purpose. Here, the operating mode selection information can constitute the entire message or only a part thereof. In particular, the message comprises a header part and a payload, also referred to as header and payload, wherein the header part contains information relevant to the processing of the message, such as the target address, the message type, the task type, etc., and the payload contains the relevant part of the data to be transmitted.

[0014] The operating mode selection information can also be output by the control device, so that the control device of the vehicle can also switch the operating mode of the management unit.

[0015] The management unit is inserted into the communication line between the response unit and the vehicle interior control device. It is thus not necessary to adapt all control devices of the vehicle, so that the IT security can be improved. The centralized management of such communication traffic can be implemented in the vehicle accordingly simply and cost-effectively.

[0016] The management unit can be a dedicated hardware, for example a separate computing unit. The firewall function can be implemented by means of software running on the management unit. The management unit itself, however, can also be implemented by means of software and thus be embedded in a computer system, for example as a virtual machine.

[0017] An advantageous embodiment of the communication system is designed in such a way that the communication via the communication line is based on the UDS protocol defined by ISO 14229. UDS stands for Unified Diagnostic Services, also known as Universal Vehicle Diagnostics. In this context, the response unit is also often referred to as a tester or diagnostic tester. The communication taking place between the response unit and the control device is based on the so-called "request-response" principle, also known as the Request-Response principle. The communication system according to the invention is thus able to effectively and securely protect a protocol that is also widely used for vehicle diagnostics.

[0018] In this case, the messages exchanged between the response unit and the control device are diagnostic messages or diagnostic commands in accordance with the respective diagnostic protocol. The management unit can be a central gateway in the vehicle, which is connected to the control devices of the vehicle via a single bus system, in particular one or more CAN buses. The communication line branch connecting the response unit to the management unit is also referred to as a diagnostic bus. The message types can then be described by means of UDS services. A distinction can be made by means of so-called SIDs (service identifiers).

[0019] A further advantageous embodiment of the communication system according to the invention, the operating mode selection information is attached to the respective message in an encrypted manner. For this purpose, all conventional encryption methods can be used, for example the execution of a signature procedure, a certificate check, the execution of a so-called challenge-response authentication, etc. Such encryption security methods are usually based on a public and private key exchange and calculate the key by means of a hash function. The security of the communication between the components of the communication system is thus further improved. Only authorized computing units can thus generate the respective messages, which can actually trigger a switch of the operating mode. The management unit verifies the authenticity of the respective message and the operating mode selection information by means of the encryption methods mentioned above and only switches the operating mode if it is confirmed that the message indeed originates from an authorized source.

[0020] It is possible to design it such that, in order to activate certain specific non-safety-related operating modes, messages with unencrypted or non-cryptographically protected operating mode selection information are also accepted. This is the case, for example, when only information is to be read from the control device.

[0021] Further, a further advantageous embodiment of the communication system according to the application is designed such that the management unit is set up to automatically activate a first operating mode, to activate the operating mode specified by the operating mode selection information upon receipt of a message containing operating mode selection information, and to automatically reactivate the first operating mode after at least the message has been processed. In other words, the first operating mode corresponds to a standard operating mode, which is thus activated most of the time. Correspondingly, on the basis of the rules underlying the first operating mode, messages are either released or intercepted. Only when a completely specific message, for example a safety-related message, is to be released, these messages can switch the management unit by means of the attached operating mode selection information, so that a different operating mode is temporarily activated in order to release the respective message. Subsequently, the management unit switches back to the first operating mode. Here, the respective message can also specify to the management unit not only the release of the respective message itself, but for example also the release of the x messages following it. In this context, "message processing" means forwarding or intercepting by the management unit.

[0022] Here, in the first operating mode, forwarding of all messages is preferably prohibited. This enables further improvement of the network security of the communication system according to the application. Thus, the management unit generally prevents the exchange of messages between the response unit and the control device within the vehicle. Only messages that are authorized, i.e. messages containing appropriate operating mode selection information, preferably containing cryptographically protected operating mode selection information, are forwarded.

[0023] Further, a further advantageous embodiment of the communication system according to the application is designed such that the management unit has a monitoring interface and is set up to be able to provide operating information via the monitoring interface, wherein the operating information describes the operating behavior of the management unit. Thereby, a user can trace the behavior of the management unit or of the respective firewall function. Thus, for example, a developer can trace the specific reason why a message was not forwarded, even though it was supposed to be forwarded. It is particularly advantageous if the operating information is read by a so-called "watchdog". A "watchdog" is a function for detecting malfunctions of a digital system. Correspondingly, the "watchdog" can take appropriate measures in order to maintain the normal operation of the communication system in the event of a functional failure. For example, individual components of the communication system can be reset or restarted.

[0024] According to a further advantageous embodiment of the communication system according to the application, the decision logic, which the management unit uses for deciding which messages should be intercepted or forwarded depending on the respective operating mode, is defined in the form of a decision tree. This makes it possible to quickly and easily trace the decision-making behavior of the management unit. Here, the different levels of the decision tree are divided according to message types. At the topmost level of the decision tree, it is detected, for example, which SIDs have the respective messages, messages with completely specific SIDs are then forwarded, messages with other SIDs are intercepted, and messages with further SIDs are transferred to a deeper level of the decision tree for detection. At the deeper levels of the decision tree, a plurality of SIDs can then be combined into groups, so that messages are intercepted or forwarded, for example, to completely specific target addresses.

[0025] Further, according to a further advantageous embodiment of the communication system according to the application, the management unit is designed to generate a response message to the response unit on behalf of the target control device when the management unit intercepts a message generated by the response unit to the target control device, wherein the management unit itself generates the response message to the response unit using the address of the target control device as the sending address. This makes it possible to maintain the operating flow in a particularly efficient manner when the response unit communicates with the control device. Depending on the message type, the response unit can need to wait for a response from the target control device. If the management unit, however, does not forward the respective message to the target control device, but rather intercepts it, the respective response message will not be sent, and the response unit will wait for too long. The management unit, however, can generate the response message itself on behalf of the target control device and send it to the response unit, so that this situation is avoided.

[0026] Here, the management unit is preferably designed to append error information to the response message, wherein the error information contains at least a hint to at least one operating mode of the management unit. Depending on the specific case, it is thus possible to adapt the operating behavior of the response unit. For example, if the response unit has been authorized to communicate with the control device, but uses a wrong operating mode, so that the management unit intercepts the relevant message, the response unit can subsequently activate the correct operating mode of the management unit, so that the message can be forwarded to the respective control device. This is the case, for example, when the response unit is designed to communicate with a general management unit that does not have a firewall function, and with a management unit according to the application. The response unit can thus query the management unit as to its implementation, and learn which operating modes are currently available. Here, depending on the specific embodiment of the management unit, it is also possible to design completely different combinations of a plurality of operating modes. Thus, a first management unit can have a first number of operating modes, and a second management unit can have a different number of operating modes than the first number of operating modes. The response unit can accordingly activate the operating mode that matches the forwarding of the respective message for each management unit.

[0027] A vehicle according to the application comprises at least one control device comprised in the above-mentioned communication system and a management unit comprised in the communication system. The vehicle can be any vehicle, such as a car, a truck, a van, a bus, etc. By comprising the respective components in the communication system according to the application, the network security of the vehicle according to the application is enhanced in a particularly simple, efficient and reliable manner. BRIEF DESCRIPTION OF DRAWINGS

[0028] Further advantageous design schemes of the communication system and the vehicle according to the application also result from the embodiments, which will be described in more detail below with reference to the drawings.

[0029] wherein:

[0030] Figure 1 A schematic diagram of a vehicle according to the application and of a communication system according to the application is shown; and

[0031] Figure 2 Two decision trees configured depending on different operating modes of the management unit of the communication system are shown. DETAILED DESCRIPTION

[0032] Figure 1 A vehicle 9 according to the application is shown. The vehicle 9 comprises a plurality of control devices 2, such as an engine control device, a gearbox control device, an ABS control device, a control device for controlling a combination instrument, a navigation system, an infotainment system or similar control devices. The control devices 2 can be connected to a management unit 4 via one or more bus lines 10, such as a high-speed bus and a low-speed bus. The management unit 4 can be a dedicated computing unit or a software component running on another computing unit. The management unit 4 can also be referred to as a so-called gateway.

[0033] The management unit 4 has access to the control devices 2 in order to read information, trigger the control devices 2 to provide services and / or modify or add software components of the control devices 2. For this purpose, the vehicle-external response unit 1 is connected to the respective control devices 2 via a communication line 3. The part of the communication line 3 between the response unit 1 and the management unit 4 is also referred to as a diagnostic bus 3.1 and the part between the management unit 4 and the control devices 2 is referred to as a type bus 3.2, wherein “type” here represents the category of the control devices 2 connected to the type bus 3.2, respectively, such as an infotainment bus. Further, sensors 11 can be connected to the control devices 2 via a sub-bus 3.3.

[0034] To enhance network security, management unit 4 includes or provides firewall functionality 5. Firewall functionality 5 can be implemented via software components running on management unit 4. Response unit 1 is used to respond to various control devices 2. Here, management unit 4 manages communication conducted via communication line 3. According to a preferred embodiment of the communication system of the present invention, this communication is based on the Unified Diagnostic Service (UDS) protocol defined in ISO 14229. Here, the corresponding diagnostic message serves as... Figure 2 The message 6 shown is exchanged. The management unit 4 then determines which messages in message 6 should be allowed / transmitted to each control device 2, and which messages in message 6 should be intercepted. Similarly, the management unit 4 can further allow or intercept messages 6 output by the control device 2 to be sent to the response unit 1.

[0035] According to the present invention, the management unit 4 has at least two operating modes, wherein different sets of different messages 6 are allowed and / or blocked in each operating mode. Here, activation of each operating mode is achieved by operating mode selection information 7 attached to each message 6 (see [link to relevant documentation]). Figure 2 The operating mode selection information 7 can be attached to the corresponding message 6 by either the response unit 1 or the control device 2, so that both the response unit 1 and the control device 2 can change the operating mode of the management unit 4.

[0036] For the two different configuration operating modes Figure 2 The decision logic underlying each operating mode is illustrated in the form of a decision tree (Figure 8). Figure 2 a) shows the configuration according to the first operating mode. Figure 2 b) shows the configuration according to the second operating mode. Here, a circled checkmark indicates that message 6 is allowed, and a circled cross indicates that message 6 is blocked or prevented from being forwarded.

[0037] In a first step 201, the management unit 4 analyzes the received messages 6. Therein, the messages 6 consist of a header 6.1 and of valid data 6.2. Herein, the operating mode selection information 7, preferably cryptographically protected, is a constituent of the valid data 6.2. The management unit 4 activates the operating mode specified by the operating mode selection information 7. Subsequently, different messages 6 are forwarded or blocked, depending on the currently valid operating mode. For this purpose, the messages 6 can be grouped according to an address part 12 and a service part 13, as shown in steps 202 and 203, for example. The service part 13 describes, for example, a specific message type, i.e. which service should be provided or used by the respective control device 2 by means of the respective message 6, for example. If the communication system according to the application is based on the UDS protocol defined by ISO 14229, the service part 13 can be a so-called SID, for example. Correspondingly, a plurality of different SIDs can be preset, which are released by the management unit 4. A corresponding filtering can be based on the address part 12, which corresponds to a source address or a target address of a respective hardware component in the communication system. In the embodiment shown in Figure 2 In the embodiment shown in

[0038] The filtering of the messages 6 can be realized by means of an arbitrary number of subsequent stages. Messages 6 which are not directly released in step 203 can be further checked in a subsequent step 204. A first subset of the messages 6 can then be intercepted and a further subset, referred to as TYP1 here, can be further checked in step 205. This subset contains messages which provide a completely specific service for a completely specific target address, for example. From the TYP1 subset, further subsets TYP1.1 and TYP1.2 can be formed in steps 206 and 207, respectively. From these subsets, further subsets can be formed in step 208, which are referred to as TYP1.1.1 here.

[0039] According to Figure 2 b), another operating mode of the management unit 4 is valid, which releases and blocks different messages 6, respectively.

[0040] The communication system according to the application is particularly simple and can therefore be integrated into existing vehicles at low cost. Only a single component, the management unit 4 described, has to be adapted. The communication system therefore enables the reuse of prior art. By managing and filtering the communication on the communication line 3, the network security is improved. Herein, it is ensured that authorized users can reliably access the control devices 2 in a simple manner. In this way, an authorized user can configure the management unit 4 accordingly quickly and simply by transmitting a message 6 containing the respective operating mode selection information 7, so that the necessary access to the control devices 2 is enabled.

Claims

1. A communication system comprising a vehicle exterior response unit (1), at least one vehicle interior control device (2), and a vehicle interior management unit (4) inserted in a communication line (3) between the response unit (1) and the at least one control device (2), wherein, The management unit (4) provides a firewall function (5) for selectively passing or blocking messages (6) exchangeable between the response unit and the at least one control device, characterized in that the management unit (4) has at least two operating modes, wherein in each operating mode a different set of messages (6) to be passed and to be blocked is predefined, and wherein the management unit (4) is set up to activate one of the operating modes depending on an operating mode selection information (7) attached to the messages (6) by the response unit (1) or by the at least one control device (2).

2. Communication system according to claim 1, characterized in that the communication via the communication line (3) is based on the UDS protocol defined by ISO 14229.

3. Communication system according to claim 1 or 2, characterized in that the operating mode selection information (7) is attached to the respective message (6) in an encrypted manner.

4. Communication system according to one of claims 1 to 3, characterized in that the management unit (4) is set up to automatically activate a first operating mode, to activate the operating mode specified by the operating mode selection information (7) upon receipt of the message (6) containing the operating mode selection information (7), and to automatically reactivate the first operating mode upon completion of the processing of at least the message (6).

5. Communication system according to claim 4, characterized in that in the first operating mode, forwarding of all messages (6) is prohibited.

6. Communication system according to one of claims 1 to 5, characterized in that the management unit (4) is provided with a monitoring interface and is set up to be able to provide operating information via the monitoring interface, wherein the operating information describes the operating behavior of the management unit (4).

7. Communication system according to one of claims 1 to 6, characterized in that the decision logic of the management unit (4) depending on the respective operating mode for deciding which messages (6) shall be blocked or passed is defined in the form of a decision tree (8).

8. Communication system according to one of claims 1 to 7, characterized in that the management unit (4) is set up to respond on behalf of a target control device when the management unit (4) blocks the message (6) generated by the response unit (1) to the target control device, wherein the management unit (4) itself generates a response message to the response unit (1) and uses the address of the target control device as the sending address in the process.

9. Communication system according to claim 8, characterized in that the management unit (4) is set up to attach error information to the response message, wherein the error information contains at least a hint to at least one operating mode of the management unit (4).

10. Vehicle (9), characterized in that the management unit (4) is set up to automatically activate a first operating mode, to activate the operating mode specified by the operating mode selection information (7) upon receipt of the message (6) containing the operating mode selection information (7), and to automatically reactivate the first operating mode upon completion of the processing of at least the message (6). At least one control device (2) comprised in a communication system according to any one of claims 1 to 9, and a management unit (4) comprised in the communication system.

Citation Information

Patent Citations

  • Firewall of vehicle-mounted information system of automobile

    CN105871830A

  • Method and corresponding device for protecting vehicle against cyber attacks

    CN111385286A

  • Vehicle diagnosis method and system and related device

    CN113282071A

  • Vehicle-mounted communication system and vehicle-mounted communication method

    CN115834121A

  • Method and computing unit for managing diagnostic requests in a network

    DE102021207870A1