Verification method for fast secure boot
By dividing the memory region in the electric power steering system and using CMAC verification, the problems of excessively long safety guidance time and insufficient tamper detection are solved, and fast and secure memory verification is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NEXTEER AUTOMOTIVE SYST SUZHOU
- Filing Date
- 2025-03-24
- Publication Date
- 2026-06-05
Smart Images

Figure CN122153893A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to software verification techniques for electric power steering (EPS) systems. Background Technology
[0002] Vehicles (such as cars, trucks, sport utility vehicles, crossovers, minivans, boats, aircraft, all-terrain vehicles, recreational vehicles, or other suitable forms of transportation) typically include a steering system, such as an electric power steering (EPS) system, a steer-by-wire (SbW) system, a hydraulic steering system, or other suitable steering system. The steering system of such vehicles typically controls various aspects of the vehicle's steering, including providing steering assistance to the operator and controlling the steerable wheels. Summary of the Invention
[0003] This disclosure generally relates to software verification techniques for electric power steering (EPS) systems.
[0004] One aspect of the disclosed embodiments includes a method for performing partial memory checks during a secure boot process, comprising: defining N distinct regions of memory, wherein N is an integer greater than one; generating a verification sequence for the N distinct regions of memory; performing a partial memory check on a first selected region among the N distinct memory regions according to the verification sequence; and completing the secure boot process without performing partial memory checks on the remaining unselected regions among the N distinct memory regions.
[0005] In another aspect, a system is configured to perform one or more functions of the various methods described herein. In yet another aspect, a processor is configured to execute instructions stored in memory to perform one or more functions of the various methods described herein.
[0006] Other applicable areas of this disclosure will become apparent from the detailed description, claims, and drawings. The detailed description and specific examples are intended for illustrative purposes only and are not intended to limit the scope of this disclosure.
[0007] These and other aspects of this disclosure are disclosed in the following detailed description of embodiments, the appended claims and the accompanying drawings. Attached Figure Description
[0008] This disclosure is best understood in conjunction with the accompanying drawings and the following detailed description. It should be emphasized that, in accordance with conventional practice, the various features in the drawings are not drawn to scale. Instead, for clarity, the dimensions of the various features have been arbitrarily enlarged or reduced.
[0009] Figure 1A A vehicle based on the principles of this disclosure is shown in general.
[0010] Figure 1B An example domain controller and electronic control unit (ECU) based on the principles of this disclosure are shown in general.
[0011] Figure 2 An example implementation of a partial memory inspection technique based on the principles of this disclosure is shown.
[0012] Figure 3 This is a flowchart illustrating example steps of a method for performing partial memory checking techniques according to the principles of this disclosure. Detailed Implementation
[0013] The following discussion pertains to various embodiments of this disclosure. While one or more of these embodiments may be preferred, the disclosed embodiments should not be construed as or otherwise intended to limit the scope of this disclosure (including the claims). Furthermore, those skilled in the art will understand that the following description has broad application, and the discussion of any embodiment is merely illustrative and not intended to imply that the scope of this disclosure (including the claims) is limited to that embodiment.
[0014] As described, vehicles (such as cars, trucks, sport utility vehicles, crossovers, minivans, ships, aircraft, all-terrain vehicles, recreational vehicles, or other suitable forms of transport) typically include a steering system (such as an electric power steering (EPS) system, a steer-by-wire (SbW) steering system, a hydraulic steering system, or other suitable steering system). The steering system of such a vehicle typically controls various aspects of the vehicle's steering (including providing steering assistance to the vehicle's operator, controlling the vehicle's steerable wheels, etc.). Although this document describes vehicles, the principles of this disclosure can also be implemented in other types of transport or non-transport equipment that include a steering system.
[0015] Steering systems can include various controller architectures to control various actuators used to engage and / or actuate components of the steering system. In some examples, a steering system can include one or more domain controllers configured to control the functionality of a specific area or domain of the vehicle. For example, a steering domain controller can be configured to control the functionality of the steering system (including controlling various actuators). In some examples, a vehicle can include various electronic control units (ECUs) or other controllers. As used herein, "ECU" can refer to a hardware module or component including one or more processors or microcontrollers, memory, sensors, one or more actuators, communication interfaces, etc., any part of which can be collectively referred to as "circuit". In examples implementing a domain controller architecture, various ECUs can respond to one or more domain controllers.
[0016] Various techniques can be used to protect vehicle controllers, software, and systems from intrusion (e.g., from security threats such as hackers or other attackers). As an example, a secure boot process can be performed when the vehicle starts. This secure boot process may include a full or partial memory check to verify the contents of memory (e.g., flash memory or other non-volatile memory) associated with the operation of system software performed using various controllers.
[0017] Vehicle manufacturers may require a secure boot process to be completed within a short timeframe (e.g., 200 ms or less). However, a full memory check (e.g., verification of all memory locations) may exceed the required timeframe. Therefore, in some examples, a partial memory check (e.g., verifying only a fixed flash memory region or location range) may be performed to shorten the duration of the secure boot process (“secure boot time”). However, a partial memory check may fail to detect whether content has been modified in one or more memory locations (e.g., tampered with by an attacker).
[0018] The verification system and method according to this disclosure are configured to implement partial memory checking techniques during the secure boot process, which maximize the verification of memory locations while reducing secure boot time.
[0019] Figure 1A A vehicle 10 based on the principles of this disclosure is generally shown. Vehicle 10 may include any suitable vehicle, such as a car, truck, SUV, minivan, crossover, any other passenger vehicle, any suitable commercial vehicle, or any other suitable vehicle. Although vehicle 10 is shown as a wheeled passenger vehicle intended for use on a road, the principles of this disclosure can be applied to other vehicles, such as airplanes, ships, trains, drones, or other suitable vehicles.
[0020] Vehicle 10 includes a vehicle body (fuselage) 12 and an engine hood 14. A passenger compartment 18 is defined at least partially by the vehicle body 12. Another portion of the vehicle body 12 defines an engine compartment 20. The engine hood 14 is movably attached to a portion of the vehicle body 12 such that when the engine hood 14 is in a first position or open position, the engine hood 14 provides access to the engine compartment 20, and when the engine hood 14 is in a second position or closed position, the engine hood 14 covers the engine compartment 20. In some embodiments, the engine compartment 20 may be located at the rear of the vehicle 10, rather than as generally shown.
[0021] The passenger compartment 18 may be located behind the engine compartment 20, but in embodiments where the engine compartment 20 is located at the rear of the vehicle 10, the passenger compartment may be located in front of the engine compartment 20. The vehicle 10 may include any suitable propulsion system, including: an internal combustion engine, one or more electric motors (e.g., for an electric vehicle), one or more fuel cells, a hybrid propulsion system including a combination of an internal combustion engine and one or more electric motors (e.g., for a hybrid vehicle), and / or any other suitable propulsion system.
[0022] In some embodiments, vehicle 10 may include an electric, hybrid, or petroleum or gasoline fuel engine, such as a spark-ignition engine. In some embodiments, vehicle 10 may include a diesel fuel engine, such as a compression-ignition engine. Engine compartment 20 houses and / or encloses at least some components of the propulsion system of vehicle 10. Alternatively or additionally, propulsion controls (such as accelerator actuators (e.g., accelerator pedal), brake actuators (e.g., brake pedal), steering wheel, and other such components) are disposed in passenger compartment 18 of vehicle 10. The propulsion controls may be actuated or controlled by the operator of vehicle 10 and may be directly connected to corresponding components of the propulsion system, such as throttle, brakes, vehicle axles, vehicle transmission, etc. In some embodiments, the propulsion controls may transmit signals to a vehicle computer (e.g., drive-by-wire), which may then control the corresponding propulsion components of the propulsion system. Thus, in some embodiments, vehicle 10 may be an autonomous vehicle.
[0023] In some embodiments, vehicle 10 includes a transmission communicated with a crankshaft via a flywheel, clutch, or hydraulic coupler. In some embodiments, the transmission includes a manual transmission. In some embodiments, the transmission includes an automatic transmission. In the case of an internal combustion engine or hybrid vehicle, vehicle 10 may include one or more pistons that operate in cooperation with the crankshaft to generate force, which is transmitted through the transmission to one or more shafts that rotate wheel 22. When vehicle 10 includes one or more electric motors, a vehicle battery and / or fuel cell provide energy to these electric motors to rotate wheel 22.
[0024] Vehicle 10 may include an autonomous vehicle propulsion system, such as cruise control, adaptive cruise control, automatic braking control, other autonomous vehicle propulsion systems, or combinations thereof. Vehicle 10 may be an autonomous or semi-autonomous vehicle, or other suitable type of vehicle. Vehicle 10 may include more or fewer features than those generally shown and / or disclosed herein.
[0025] In some embodiments, vehicle 10 may include an Ethernet component 24, a controller area network (CAN) bus 26, a media-oriented system transport component (MOST) 28, a FlexRay component 30 (e.g., a brake-by-wire system), and a local interconnect network component (LIN) 32. Vehicle 10 may use the CAN bus 26, MOST 28, FlexRay component 30, LIN 32, other suitable network or communication systems, or combinations thereof, to transmit various information from sensors, such as those inside or outside the vehicle, to various processors or controllers, such as those inside or outside the vehicle. Vehicle 10 may include more or fewer features than those generally shown and / or disclosed herein.
[0026] In some embodiments, the vehicle 10 may include a steering system, such as an EPS system, a steer-by-wire system (e.g., which may include or communicate with one or more controllers that control components of the steering system without using a mechanical connection between the steering wheel and the wheel 22 of the vehicle 10), a hydraulic steering system (e.g., which may include a magnetic actuator incorporated into a valve assembly of the hydraulic steering system), or other suitable steering systems.
[0027] The steering system may include an open-loop feedback control system or mechanism, a closed-loop feedback control system or mechanism, or a combination thereof. The steering system may be configured to receive various inputs, including but not limited to steering wheel position, input torque, one or more wheel positions, other suitable inputs or information, or a combination thereof.
[0028] Alternatively or concurrently, the inputs may include steering wheel torque, steering wheel angle, motor speed, vehicle speed, estimated motor torque command, other suitable inputs, or combinations thereof. The steering system may be configured to provide steering functionality and / or control to the vehicle 10. For example, the steering system may generate auxiliary torque based on various inputs. The steering system may be configured to use the auxiliary torque to selectively control the motor of the steering system to provide steering assistance to the operator of the vehicle 10. The steering system of this disclosure is configured to implement a steering wheel estimation system and method, as described in more detail below.
[0029] Vehicle 10 includes one or more controllers, such as Figure 1BThe controller 100 is generally shown in the diagram. Controller 100 may correspond to a steering system controller. Controller 100 may include or be implemented as any suitable controller, such as an electronic control unit or other suitable controller or control circuit. In some examples, controller 100 may correspond to a domain controller of domain 102 (e.g., a steering system domain) that includes multiple ECUs 104. For example, controller 100 and ECUs 104 may correspond to the controller and actuator of the steering system of vehicle 10. Each ECU in ECU 104 may include a corresponding actuator 108 or other control mechanisms configured to actuate, control components of the steering system, provide torque to components of the steering system, etc., and / or be associated with a corresponding actuator or other control mechanism.
[0030] Controller 100 and ECU 104 can be configured to control various functions, such as those of the steering system and / or various functions of the vehicle 10. As described below, ECU 104 may have the same or different configuration as controller 100. For example, controller 100 may include processor 112 and memory 116. Processor 112 may include any suitable processor, such as those described herein. Alternatively or additionally, controller 100 may include any suitable number of processors other than or different from processor 102.
[0031] Memory 116 may include a single disk or multiple disks (e.g., a hard disk drive) and includes a storage management module that manages one or more partitions within memory 116. In some embodiments, memory 116 may include flash memory, semiconductor (solid-state) memory, etc. Memory 116 may include random access memory (RAM), read-only memory (ROM), or a combination thereof. Memory 116 may include instructions that, when executed by processor 112, cause processor 112 to control at least various aspects of vehicle 10. Alternatively or additionally, memory 116 may include instructions that, when executed by processor 112, cause processor 112 to perform functions associated with the systems and methods described herein.
[0032] The controller 100 may receive one or more signals from various measuring devices or sensors 120 that indicate sensed or measured characteristics of the vehicle 10. Sensors 120 may include any suitable sensors, measuring devices, and / or other suitable mechanisms. For example, sensors 120 may include one or more torque sensors or devices, one or more steering wheel position sensors or devices, one or more motor position sensors or devices, one or more position sensors or devices, other suitable sensors or devices, or combinations thereof. One or more signals may indicate steering wheel torque, steering wheel angle, motor speed, vehicle speed, other suitable information, or combinations thereof. As used herein, “sensor” may correspond to a physical sensor or derived signal (e.g., a signal derived from an algorithm or calculation based on one or more sensor inputs directly into the controller or using data transmitted to the controller from a source outside the direct controller area).
[0033] As used herein, "controller" can refer to a hardware module or component including one or more processors or microcontrollers, memory, sensors, one or more actuators, communication interfaces, etc., any part of which can be collectively referred to as "circuit". As described herein, the corresponding functions and steps performed by a given controller, control circuit, etc., can be performed jointly by multiple controllers, processors, etc. For example, "configured to perform" can mean that a single processor, processing device, controller, etc., is configured to perform both A and B, or it can mean that a first processor, first processing device, first controller, etc., is configured to perform A and a second processor, second processing device, second controller, etc., is configured to perform B. For simplicity, "control circuit configured to perform A and B" can mean that one or more processors, processing devices, controllers, etc., are jointly configured to perform A and B. In some examples, one or more functions can be performed remotely (e.g., relative to a vehicle), such as at the controller, processor, circuit, etc., of a remote server, cloud computing system, and / or other remote processing system.
[0034] One or more of the controller 100, ECU 104, and / or other controllers of vehicle 10 may be configured to implement the verification system and methods of this disclosure (including partial memory checking techniques). For example, one or more processors (such as processor 112) are configured to perform partial memory checking techniques (e.g., performing partial memory checking techniques on memory locations of non-volatile memory (such as memory 116)) during a secure boot process, as described in more detail below.
[0035] Partial memory inspection techniques according to this disclosure may be described with respect to one or more processors (e.g., processor 112) and memories (e.g., memory 116). For example, memory 116 may correspond to flash memory storing software executed by processor 112 and / or other components of vehicle 10. In one example, processor 112 is configured to execute instructions stored in memory 116 and / or other memories to perform a secure boot process when vehicle 10 is started. Processor 112 may correspond to a controller or other processing device of an EPS system.
[0036] In an example of performing a full memory check during the secure boot process, a full memory check is performed on memory 116 to verify all memory locations of memory 116. Verification of memory locations may include (but is not limited to): verifying that software components are stored in the correct corresponding memory locations (e.g., desired memory areas) within memory 116, verifying that one or more memory areas are properly protected, and / or verifying that memory locations or areas have not suffered damage (e.g., due to corruption, tampering, etc.).
[0037] In the example of performing a partial memory check, only a fixed flash memory region or location range of memory 116 is verified. For example, the same predetermined flash memory region or location range of memory 116 can be verified during each secure boot process.
[0038] Conversely, the partial memory checking technique according to this disclosure is configured to perform partial memory checks on different portions (i.e., different flash memory regions or location ranges) of memory 116 at each boot. For example, memory 116 may be divided into N separate flash memory regions or location ranges (where N is an integer greater than one). At each boot, a partial memory check is performed on one of the N regions in a pre-designed order. Therefore, after N boots and corresponding secure boot processes, each of the N flash memory regions will be verified. The N flash memory regions may be verified in the same (e.g., predetermined) or different (e.g., randomized) order in each boot.
[0039] Figure 2An example implementation of a partial memory checking technique performed on a memory (such as flash memory 200) according to this disclosure is shown. For example, flash memory 200 may correspond to or be a component of memory 116. Flash memory 200 may store various software and / or data components in corresponding memory areas, including but not limited to bootloader 204, application data 206 (e.g., one or more applications or application software), and calibration data (e.g., CAL1, CAL2, CAL3, etc.) 208. In one example, bootloader 204 is executed when a system including memory 200 starts (e.g., when a vehicle, EPS system, etc., starts) and is configured to initialize hardware components (e.g., processor 112, memory 116, etc.). Bootloader 204 may be configured to load an operating system and / or perform one or more other boot tasks.
[0040] In some examples, flash memory 200 may include a hardware security module (HSM) 212. Although HSM 212 is shown within flash memory 200, it may also be located externally. HSM 212 is configured to perform authentication processes / functions (e.g., functions of a secure boot process) and stores and manages keys (e.g., encryption keys) used to perform various authentication functions, such as keys for digital signatures, encryption, and / or other security mechanisms associated with performing the secure boot process. As an example, HSM 212 stores cryptographic message authentication codes (CMACs) generated for corresponding areas of flash memory 200. As used herein, the term "authentication data" can broadly refer to cryptographic keys, authentication codes (e.g., CMACs), etc.
[0041] For example, a unique CMAC can be generated for each software component (e.g., bootloader 204, application 206, etc.) using a cryptographic key and corresponding content for each software component, and this unique CMAC can be stored in a secure memory location (e.g., within HSM 212). As an example, the CMAC can be initially calculated when data, software, firmware, etc., are first stored / downloaded to memory 200 (e.g., during initial programming of memory 200). The CMAC generated during the initial programming of memory 200 can be referred to as the "pre-CMAC".
[0042] During the subsequent secure boot process, the corresponding CMAC can be recalculated for each software component and compared with the corresponding stored pre-CMAC. If the recalculated CMAC of a particular software component matches its corresponding pre-CMAC, the software component is considered verified or certified (e.g., it is determined that the software component has not been tampered with, modified, or otherwise corrupted since the initial burning of memory 200). Conversely, if the recalculated CMAC does not match the corresponding pre-CMAC, the software component can be identified as corrupted, and the secure boot process can be stopped. In some examples, memory 200 can then be re-burned to its previous state.
[0043] The partial memory checking technique according to this disclosure is configured to perform partial memory checks on different portions or regions of flash memory 200 at each boot. For example, memory 200 can be divided into N separate flash memory regions or location ranges (e.g., by defining N different memory regions or location ranges, where N is an integer greater than one). As an example, 2MB of flash memory can be divided into 16 regions. As shown, memory 200 is divided into region 1, region 2, region 3, ... and region N, which can be collectively referred to as region 216. Region 216 can be of the same or different sizes (e.g., including the same or different numbers of memory locations). As shown, region 216 does not necessarily have to be aligned with components of flash memory 200. In other words, each region in region 216 can include portions or locations of different components stored in memory 200, and each of these components can include portions corresponding to two or more regions in region 216. As an example, the corresponding location (e.g., memory / address / location range) of each region in region 216 can be defined and stored in HSM 212 or another secure location (e.g., memory outside of memory 200).
[0044] As an example, after the initial programming of memory 200, a trust anchor (e.g., trusted platform module 220, processor, etc.) calculates a corresponding pre-CMAC (pre-CMAC 2, pre-CMAC 3, pre-CMAC 4, ..., and pre-CMAC N) 222 for each region in region 216. The pre-CMAC 222 can be stored in HSM 212.
[0045] During each subsequent secure boot process, partial memory checks are performed on different regions within region 216. For example, the Trusted Platform Module 220 recalculates the CMAC for a selected region within region 216 and compares the recalculated CMAC with the corresponding pre-CMAC. Thus, after N boots and corresponding secure boot processes, each region within region 216 is verified.
[0046] Figure 3 This is a flowchart generally illustrating a method 300 for performing partial memory checking techniques according to the principles of this disclosure. For example, one or more computing devices, processors, or processing devices are configured to execute instructions to implement method 300, such as one or more processors in a system described herein (e.g., a computing device or processor of a vehicle configured to implement controller 100, processor 112, and memory 116, memory 200, etc.). In some examples, one or more steps of method 300 as described below may be skipped or omitted, and / or one or more of these steps may be performed in a different order than described.
[0047] Method 300 begins at 302. For example, method 300 corresponds to a secure boot process that begins upon startup (e.g., power-on) of a vehicle and associated systems (such as an EPS system). In this example, memory is downloaded / burned (e.g., with software / firmware) before method 300 begins. For example, the memory has been divided into N regions, and a pre-CMAC value is calculated and stored for each of the N regions as described above.
[0048] At 304, method 304 includes: initializing the HSM (e.g., HSM 212), and may include initializing the bootloader 204. The HSM 212 and / or bootloader 204 can be used to perform the initial steps of the secure boot process.
[0049] At 308, method 300 includes: determining whether the current boot is the first boot since the memory was downloaded / burned (e.g., since the memory was last burned / updated with verified software or firmware). If it is the first boot, method 300 proceeds to 312. If it is not the first boot, method 300 proceeds to 316.
[0050] At 312, method 300 includes: generating a check or verification sequence and storing an indication that the memory is valid or verified (e.g., by setting a "memory valid" flag to true). For example, the memory valid flag may be set in a secure location (such as an HSM). The verification sequence indicates a sequence that, starting from the current boot, will be used to verify N regions of memory during the corresponding secure boot process. In one example, the verification sequence is randomized, but other sequence generation techniques may be used. The verification sequence may be stored in a secure location (e.g., in an HSM).
[0051] At 320, method 300 includes: verifying the CMAC of the selected region. For example, the selected region corresponds to a region selected from N regions according to the current verification sequence. For the first boot, the selected region corresponds to the first region in the verification sequence. For subsequent boots, the selected region corresponds to the next region in the verification sequence immediately following the region verified in the previous boot. The date indicating the current position or region in the sequence (including indications of previously checked regions, unchecked regions, etc.) can be stored in a secure location (e.g., in the HSM). For example, for N regions, indicators of positions from 1 to N in the verification sequence can be stored, and these indicators can be incremented after each secure boot process is completed. As described above, verifying the CMAC of the selected region may include: recalculating the CMAC of the selected region and comparing the recalculated CMAC with the corresponding pre-CMAC.
[0052] At 324, method 300 includes: determining whether the selected memory region is valid (i.e., based on the result of the CMAC verification performed at 320). If the selected memory region is valid, method 300 continues the secure boot process at 328. If the selected memory region is invalid, method 300 continues to 332. At 332, method 300 includes: setting a memory valid flag to false. Then, method 300 proceeds to 336 to exit the secure boot process.
[0053] At 316, method 300 includes determining whether a memory valid flag is set to true. If the memory valid flag is set to true, method 300 continues to 340. If the memory valid flag is set to false, method 300 exits the secure boot process at 336. In this way, if the memory was previously determined to be invalid (e.g., during a previous secure boot process) and the memory was not reprogrammed, method 300 stops the secure boot process.
[0054] At 340, method 300 includes: determining whether the current verification sequence has ended / completed (e.g., each of the N regions in the previously generated verification sequence has been verified during the corresponding secure boot process). If the current verification sequence has ended / completed, method 300 continues to 344. If the current verification sequence has not ended / completed, method 300 continues to 320 based on the current verification sequence. At 344, method 300 includes: generating a new verification sequence, and then proceeding to 320 based on the new verification sequence.
[0055] The foregoing discussion is intended to illustrate the principles and various embodiments of the invention. Once the foregoing disclosure is fully understood, many variations and modifications will become apparent to those skilled in the art. The appended claims are intended to be construed as covering all such variations and modifications.
[0056] The word “example” is used herein to indicate that something is used as an example, instance, or illustration. Any aspect or design described herein as an “example” is not necessarily to be construed as preferred or advantageous over other aspects or designs. Rather, the use of the word “example” is intended to present the concept in a specific manner. As used herein, the term “or” is intended to mean an inclusive “or” rather than an exclusive “or.” That is, unless otherwise specified or clearly understood from the context, “X comprises A or B” is intended to mean any of the natural inclusive permutations and combinations. That is, if X comprises A; X comprises B; or X comprises both A and B, then “X comprises A or B” is satisfied in any of the foregoing examples. Additionally, the articles “a” and “an” as used herein and in the appended claims should be generally interpreted as meaning “one or more” unless otherwise specified or clearly understood from the context to refer to the singular form. Furthermore, the use of the terms “one embodiment” or “an embodiment” throughout is not intended to refer to the same embodiment or implementation unless specifically described as such. As used herein, the term “approximate” may correspond to “…within + / - 5.0%”.
[0057] The systems, algorithms, methods, instructions, etc., described herein can be implemented in hardware, software, or any combination thereof. Hardware may include, for example, computers, intellectual property (IP) cores, application-specific integrated circuits (ASICs), programmable logic arrays, optical processors, programmable logic controllers, microcode, microcontrollers, servers, microprocessors, digital signal processors, or any other suitable circuitry. In the claims, the term "processor" should be understood to cover any of the aforementioned hardware, individually or in combination. The terms "signal" and "data" are used interchangeably.
[0058] As used herein, the term "module" can include packaged functional hardware units designed for use with other components, instruction sets executable by a controller (e.g., a processor executing software or firmware), processing circuitry configured to perform specific functions, and stand-alone hardware or software components interfacing with a larger system. For example, a module can include application-specific integrated circuits (ASICs); field-programmable gate arrays (FPGAs); circuits; digital logic circuits; analog circuits; combinations of discrete circuits; gates; and other types of hardware; or combinations thereof. In other embodiments, a module can include memory storing instructions executable by a controller to implement the features of the module.
[0059] Furthermore, in one aspect, for example, the systems described herein can be implemented using a general-purpose computer or general-purpose processor with a computer program that, when executed, implements any of the various methods, algorithms, and / or instructions described herein. Alternatively or alternatively, for example, a special-purpose computer / processor may be utilized, which may include additional hardware for implementing any of the methods, algorithms, or instructions described herein.
[0060] Furthermore, all or part of the embodiments of this disclosure may take the form of a computer program product accessible from, for example, a computer-usable medium or a computer-readable medium. A computer-usable medium or a computer-readable medium may be any means capable of, for example, tangibly containing, storing, transmitting, or transporting a program for use by or in conjunction with any processor. Such a medium may be, for example, an electronic, magnetic, optical, electromagnetic, or semiconductor device. Other suitable media are also available.
[0061] The above embodiments, implementations, and aspects have been described to allow for an easy understanding of the invention and are not intended to limit it. Rather, the invention is intended to cover various modifications and equivalent arrangements included within the scope of the appended claims, which should be given the broadest interpretation to cover all such modifications and equivalent structures permitted under the law.
Claims
1. A method for performing a partial memory check during a secure boot process, the method comprising: Define N distinct regions of memory, where N is an integer greater than one; Generate verification sequences for the N different regions of the memory; Based on the verification sequence, perform the partial memory check on a first selected region among N different memory regions; and The secure boot process is completed without performing the partial memory check on the remaining unselected regions of the N different memory regions.
2. The method according to claim 1, further comprising: Prior to the secure boot process, corresponding authentication codes for the N different regions of the memory are calculated, and the corresponding authentication codes are stored as pre-authentication codes. The partial memory check includes: recalculating the authentication code for the first selected region, and comparing the recalculated authentication code with the pre-authentication code for the first selected region.
3. The method according to claim 2, wherein, The corresponding authentication code is a password-based message authentication code.
4. The method according to claim 2, wherein, Storing the corresponding authentication code includes storing the corresponding authentication code in a hardware security module.
5. The method according to claim 2, wherein, Performing the partial memory check on the first selected region includes: Determine whether the recalculated authentication code matches the pre-authentication code; In response to the determination that the recalculated authentication code matches the pre-authentication code, the secure boot process is completed without performing the partial memory check on the remaining unselected regions of the N different memory regions; and In response to the determination that the recalculated authentication code does not match the pre-authentication code, the secure boot process is exited without completing the secure boot process.
6. The method according to claim 5, further comprising: In response to the determination that the recalculated authentication code matches the pre-authentication code, an indication that the memory is valid is stored.
7. The method according to claim 5, further comprising: In response to the determination that the recalculated authentication code does not match the pre-authentication code, an indication that the memory is invalid is stored.
8. The method according to claim 1, further comprising: After the secure boot process is completed, a second memory check is performed during the second secure boot process, wherein performing the second memory check includes: Based on the verification sequence, perform the second partial memory check on a second selected region among the N different memory regions; and The second secure boot process is completed without performing the second partial memory check on the first selected region and the remaining unselected regions of the N different memory regions.
9. The method according to claim 1, further comprising: Based on the verification sequence, it is determined whether a corresponding partial memory check has been performed on each of the N regions of the memory, and in response to the determination that the corresponding memory check has been performed on each of the N regions of the memory based on the verification sequence, a second verification sequence for the N regions of the memory is generated.
10. The method according to claim 1, wherein, The verification sequence is a random sequence.
11. The method according to claim 1, wherein, The memory is flash memory.
12. The method according to claim 11, wherein, The flash memory corresponds to a flash memory that stores data associated with the control of the vehicle's steering system.
13. A system for performing a partial memory check during a safety guidance process of a vehicle's steering system, the system comprising: A processor is configured to execute instructions stored in memory, wherein executing the instructions causes the processor to: Define N distinct regions of memory, where N is an integer greater than one. Generate verification sequences for the N different regions of the memory. According to the verification sequence, the partial memory check is performed on a first selected region among N different memory regions, and The secure boot process is completed without performing the partial memory check on the remaining unselected regions of the N different memory regions.
14. The system according to claim 13, wherein, Executing the instructions also causes the processor to: calculate corresponding authentication codes for the N different regions of the memory before the secure boot process, and store the corresponding authentication codes as pre-authentication codes, wherein performing the partial memory check includes: recalculating the authentication code for the first selected region, and comparing the recalculated authentication code with the pre-authentication code for the first selected region.
15. The system according to claim 14, wherein, The corresponding authentication code is a password-based message authentication code.
16. The system according to claim 14, wherein, Storing the corresponding authentication code includes storing the corresponding authentication code in a hardware security module.
17. The system according to claim 14, wherein, Performing the partial memory check on the first selected region includes: Determine whether the recalculated authentication code matches the pre-authentication code; In response to the determination that the recalculated authentication code matches the pre-authentication code, the secure boot process is completed without performing the partial memory check on the remaining unselected regions of the N different memory regions; and In response to the determination that the recalculated authentication code does not match the pre-authentication code, the secure boot process is exited without completing the secure boot process.
18. The system according to claim 17, wherein, Executing the instructions also causes the processor to: In response to the determination that the recalculated authentication code matches the pre-authentication code, an indication that the memory is valid is stored; as well as In response to the determination that the recalculated authentication code does not match the pre-authentication code, an indication that the memory is invalid is stored.
19. The system according to claim 13, wherein, Executing the instructions also causes the processor to: perform a second part of a memory check during a second secure boot process after the secure boot process has been completed, wherein performing the second part of the memory check includes: Based on the verification sequence, perform the second partial memory check on a second selected region among the N different memory regions; and The second secure boot process is completed without performing the second partial memory check on the first selected region and the remaining unselected regions of the N different memory regions.
20. The system according to claim 13, wherein, Executing the instructions also causes the processor to: determine, based on the verification sequence, whether a corresponding partial memory check has been performed on each of the N regions of the memory, and in response to the determination that the corresponding memory check has been performed on each of the N regions of the memory based on the verification sequence, generate a second verification sequence for the N regions of the memory.