Radio remote control for controlling vehicle functions of a motor vehicle

A radio remote control with a safety device and secret security information ensures secure activation and deactivation of functional safety functions, addressing cost and complexity issues in existing systems by applying functional safety standards selectively to the safety device components.

DE102012202934B4Active Publication Date: 2025-10-16BAYERISCHE MOTOREN WERKE AG
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
DE102012202934
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2012-02-27
Publication Date
2025-10-16
Estimated Expiration
2032-02-27

AI Technical Summary

Technical Problem

Existing radio remote controls for vehicles face challenges in efficiently controlling functions relevant to functional safety, such as autonomous parking, due to stringent requirements that lead to high development costs and complexity, especially concerning installation space and power consumption.

Method used

A radio remote control system with a safety device that includes a user-operable safety input means and a safety circuit, using a secret security information to generate transmission data only when the safety input means is actuated, ensuring that functions relevant to functional safety are activated and deactivated securely, thus reducing the need for comprehensive compliance with functional safety standards across the entire transmitter.

Benefits of technology

The system allows for cost-effective and reliable control of functional safety functions without imposing the full burden of functional safety standards on the entire remote control, enhancing robustness and reducing false activations, while maintaining compliance with ISO 26262 standards only for the safety device components.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Radio remote control (10, 20, 30, 40) - to control at least one first vehicle function relevant for functional safety and - for controlling one or more further second vehicle functions of a motor vehicle, comprising - user-operable input means (2) for activating vehicle functions by the user, including for activating the first vehicle function, and for obtaining a user input (E) corresponding to the vehicle function to be activated, wherein, in the event that the first vehicle function is to be activated, a user input (E) associated with the first vehicle function is present, and - a transmitter logic (3) for processing the user input (E), characterized in that the remote control additionally comprises: - a safety device (6) for safeguarding the first vehicle function with - a user-operable safety input means (Sw) which is to be operated to execute the first vehicle function, and - a safety circuit (6) coupled to the safety input means (Sw) and having safety information (G), wherein the remote control is configured such that, in the case of a user input (E) associated with the first vehicle function, the safety information (G) is used to generate transmission data (S; SH; W) which effect the execution of the first vehicle function only in the case when the safety input means has been actuated.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a radio remote control for controlling vehicle functions of a motor vehicle according to the preamble of claim 1.

[0002] In the following, due to the possible confusion in German between security in the sense of the English term "security" (access protection, protection against intruders, protection against data corruption, etc.) and security in the sense of the English term "safety" (protection against unacceptable risks to life and limb), the term "Sicherheit" is generally used in the first case and the term "Betriebssicherheit" or "funktional Sicherheit" (operational safety) in the second case.

[0003] It is common practice to control individual vehicle systems that are not directly related to driving a vehicle via remote control (e.g., integrated into the vehicle's remote key). Examples include the central locking access functions, opening a convertible top, or opening the windows. In many vehicles, the remote key also contains part of the immobilizer. In some cases, other convenience functions, such as an auxiliary air conditioning system or auxiliary heating, can also be controlled via remote control. Moving the vehicle, however, cannot be controlled remotely in most cases.

[0004] For theft protection, today's remote keys generally require cryptographic security. This is typically achieved using symmetric or asymmetric encryption / signature. Furthermore, the radio link of such remote controls is protected against tampering, for example, using a checksum procedure, particularly cyclic redundancy check (CRC), or signatures. This can serve both to increase robustness and further increase the security of the transmission.

[0005] Vehicles contain many functions that are relevant to operational safety / functional safety. Such functions are developed and validated in accordance with standards such as IEC 61508 (IEC - International Electrotechnical Commission) or, in the automotive sector, ISO 26262 (ISO - International Organization for Standardization).

[0006] When remotely controlling functions in the vehicle that are relevant for operational safety / functional safety, the entire remote control must meet requirements for operational safety / functional safety (in the sense of “safety”) in addition to the already known requirements for robustness and safety (in the sense of “security”).

[0007] For example, the incorrect activation of a remote-controlled function relevant to functional safety due to errors in the radio remote control (i.e. in the transmitter) must be sufficiently excluded or safeguarded against.

[0008] These functional safety requirements must be met, for example, by developing and safeguarding the entire remote control system (both transmitter and receiver) in accordance with the ISO 26262 standard used in the automotive sector.

[0009] However, this conventional approach to ensuring functional safety results in considerable effort and additional problems, particularly for the remote control (i.e., the transmitter). Compared to simple radio keys, for example, the software development process is very complex, and the quantitative failure rates are significantly higher. Furthermore, solutions typically used to ensure functional safety, such as redundant processing of input signals relevant to ensuring functional safety, are severely limited in radio key remote controls due to space constraints and power consumption alone.

[0010] Fig. 1 shows a conventional transmitter / receiver system used to remotely control a vehicle function: A remote control 1 comprises input means 2 for controlling the vehicle functions, for example various buttons for triggering different vehicle functions, for example a button for opening the vehicle and a button for closing the vehicle. A user input E is obtained by means of the input means 1. The user input E is converted by a transmitter logic 3 into the data S to be sent, which contains the user input E in coded form, i.e. S is a function of E: S = f(E). For example, f(E) can be a simple code (S=E) or S can contain - for example for security reasons - further information such as the identification of the transmitter (transmitter ID) or checksums (for example in the sense of a CRC) or sequence counter.The transmitter logic 3 is implemented, for example, using a microcontroller and, if necessary, other electronic components. The modulation of the data to be transmitted onto a corresponding radio-frequency carrier is described in . Fig. 1 is not shown for reasons of simplification. On the receiver side, after demodulation (not shown), the evaluation logic 4 determines the user input E from the received data S, ie E = f -1 (S), and the corresponding output signal A is output to perform the vehicle function assigned to the user input.

[0011] For a vehicle function relevant to functional safety, such as a parking function that can be triggered from outside the vehicle for automated parking or reversing of a passenger car, the conventional approach requires that all parts of the remote control that come into contact with the remote control of such a vehicle function be designed in accordance with functional safety requirements. This results in considerable additional effort, which is difficult or impossible to reconcile with the given constraints of the available installation space and power consumption. This applies particularly to the microcontroller used in the remote control.

[0012] From US Pat. No. 6,034,617 A, a passive remote control system with a remote control for accessing a vehicle is known. The remote control transmits a command signal at regular intervals when the remote control is moving. As the driver approaches the vehicle, the remote control comes within the reception range of a control circuit in the vehicle, which then receives the command signal. Upon receipt of the command signal, the control circuit is activated to begin detecting a driver action, such as the operation of a door handle, which indicates the intention to enter the vehicle. If this action is detected within a certain period of time after receipt of the command signal, the vehicle doors are unlocked.

[0013] Furthermore, reference is made to documents EP 1 004 230 A2, DE 10 2008 051 982 A1, DE 10 2010 005 327 A1 and DE 10 2006 010 170 A1 as further prior art.

[0014] It is an object of the invention to provide a radio remote control which, in addition to controlling vehicle functions (e.g. opening and closing the central locking system) which are not relevant for functional safety, also allows control of vehicle functions (e.g. automatic parking) which are relevant for functional safety, without the requirements in connection with functional safety being transferred essentially completely to the entire transmitter-side microcontroller.

[0015] The problem is solved by the features of the independent patent claims. Advantageous embodiments are described in the dependent claims.

[0016] The radio remote control according to the invention serves to control at least one first vehicle function relevant to functional safety, for example, a function for carrying out an autonomous driving process of a vehicle, in particular a parking function for automatically parking or reversing a passenger car. This is preferably a parking function for (frontal and / or rearward) parking into a head-on parking space, in particular for parking into a head-on parking space (for example, a single-car garage). Such a remote-controllable parking function is described in German patent application 10 2011 084 366.3 entitled "Remote control for a parking assistance system and a remote-controllable parking assistance system" by the same applicant, which was filed on October 12, 2011.The description of the parking function and its operation given therein are hereby incorporated by reference into the disclosure content of this application.

[0017] In addition to one or more such functions, the remote control is also used to control other vehicle functions, such as opening and closing the central locking system.

[0018] The remote control according to the invention comprises user-operable input means for activating vehicle functions and for obtaining a user input corresponding to the selected vehicle function, as is the case in connection with Fig. 1 has already been described. The input means also serve to activate the first vehicle function, wherein, in the event that the first vehicle function is to be activated, a user input associated with the first vehicle function is present. For example, the input means are buttons, wherein either each button is associated with a specific vehicle function or, alternatively, one or more buttons are associated with more than one vehicle function. Furthermore, the remote control comprises a transmitter logic for processing the user input, as already described in connection with Fig. 1 was described.

[0019] In contrast to conventional remote controls, the remote control according to the invention additionally comprises a specific safety device to safeguard the first vehicle function.

[0020] The safety device itself comprises a user-operable safety input means, which is to be actuated to execute the first vehicle function. Preferably, the safety input means is transferred to a first state upon actuation and remains in this state during the execution of the first vehicle function. For example, it can be provided that the remote control is configured such that the safety input means is to be held in the first state by the user during the execution of the first vehicle function, in particular by applying force on the part of the user, for example by continuously actuating a button against a counterforce of the button or by continuously holding an extended operating element against a counterforce.It would also be conceivable to provide a (for example, mechanical) timer, wherein the timer, after a single activation, maintains the safety input means (for example, in the form of a button) in the first state and then resets it after a - preferably defined - period of time. In this example, continuous actuation of the safety input means by the user would be possible but not absolutely necessary. For example, an electrical or electronic timer integrated into the safety input means or connected downstream thereof could also be used, wherein the timer, after activation, maintains the button in the first state and then resets it after a - preferably defined - period of time has elapsed.

[0021] The safety input device may be a switch that is switched by a force applied by the user.

[0022] However, this is not mandatory. Preferably, the safety input means has at least two different states and is activated and transferred to another state by a user action (e.g., by pressing a button or touching a specific area on the remote control). For example, the safety input means is a switching element.

[0023] The safety device further comprises a safety circuit coupled to the safety input device containing safety information. When the safety input device is activated, for example, the safety information is released for processing.

[0024] The remote control is configured such that, in the case of a user input assigned to the first vehicle function, the security information is used to generate transmission data that trigger the execution of the first vehicle function only if the security input means has been actuated. Preferably, in the case of a user input assigned to the first vehicle function, the security information is used to generate transmission data that trigger the execution of the first vehicle function only if the first state of the security input means is present, and upon leaving the first state, the use of the security information for this purpose is excluded.Only if the first state is present can transmission data be generated using the security information (and preferably using the user input associated with the first vehicle function) that enables the execution of the first vehicle function. Actuating the security input means therefore represents a security input by the user. If the state of the security input means subsequently changes, the use of the security information is then canceled.

[0025] According to the invention, unwanted activation of the first vehicle function can be prevented by providing a secret in the form of the security information, which must be used when generating transmission data in order to obtain valid transmission data for triggering the first vehicle function. The secret, i.e. the security information, should preferably be so complex that it can be ruled out with sufficient probability that an element in the chain of transmitter, transmission path, receiver, and evaluation logic generates the secret randomly—even in the event of an error! The security information is preferably at least 16 bits long, in particular at least 32 bits long, for example 16, 32, 64, 128, or 256 bits long.

[0026] The use of the secret to generate the transmission data must be activated on the transmitter side by a security input from the user, namely by pressing the additional security input device. The receiver checks whether the secret was used to generate the transmission data, and only then is the first vehicle function activated.

[0027] Preferably, it is provided that when the first state is exited, the use of the security information to generate valid transmission data that triggers the execution of the first vehicle function is excluded. This makes it possible for the first vehicle function to be safely deactivated as soon as the user withdraws the security input. When implementing the remote control, it should be ensured with sufficient probability - even in the event of an error - that the secret, i.e. the security information, is deactivated when the user withdraws the security input and the security input means leaves the first state. In this case, it is determined on the receiving side that the security information is no longer being used to generate the transmission data, in which case further execution of the first function is then prevented.For example, the transmitter repeatedly sends corresponding data to the receiver at a specific time interval, for example, every 10 ms, to execute the first vehicle function. If, after a specific period of time (for example, 100 ms) after receiving data valid for executing the first vehicle function, no more valid data is received that was generated by the transmitter using the safety information, further execution of the first vehicle function is stopped.

[0028] The threshold for the above-mentioned sufficient probabilities depends on the safety level of the first vehicle function. The threshold can be derived, for example, from specifications in functional safety standards; for example, ISO 26262 suggests a value less than or equal to 1 for ASIL C (Automotive Safety Integrity Level C). -7 per operating hour.

[0029] The proposed radio remote control allows the control (e.g., switching on and off) of sensitive vehicle functions with regard to functional safety, without the entire remote control having to comply with the corresponding requirements of the functional safety standard. Instead, only the safety device (i.e., the safety input device, the safety circuit, and any other components of the safety device) is preferably developed and secured according to the requirements of the functional safety standard. This reduces the effort required to develop and secure the remote control despite compliance with functional safety standards such as IEC 61508 or ISO 26262. Since only the safety circuit, not the entire transmitter-side component, is developed and secured according to the requirements of the respective standard, the approach proposed here leads to a significant cost reduction.At the same time, the functional safety of the system also tends to be increased compared to the classic approach of protecting the entire transmitter, as the remote control components that actually need to be protected according to the respective standard are less complex. In addition, independent of functional safety, the robustness of the function is also increased, as even false activations can be prevented that might not actually pose a hazard but still represent undesirable behavior from the user's perspective.

[0030] Preferably, the remote control comprises a first button, which in turn comprises the safety input means in the form of a safety switching element.

[0031] According to a first embodiment variant for the first button, the first button can comprise, in addition to the safety switching element, a further switching element, which serves to obtain a user input associated with the first vehicle function. The further switching element is thus assigned to the input means for user-side selection of a vehicle function, while the safety switching element is assigned to the safety device. The first button is then designed such that when the first button is actuated, both the safety switching element and the further switching element are actuated.

[0032] Alternatively, it can be provided that the remote control comprises at least one further button in addition to the first button and that the further button serves as an input means for selecting the first vehicle function.

[0033] As an alternative to using a button, wherein the security input means is actuated when the button is actuated, a completely different concept can also be used to actuate the security input means. For example, the remote control can comprise a base body and an operating part comprising at least one operating element. The at least one operating element is used to select the first vehicle function, for example for autonomous parking of a vehicle. When the operating part is in a concealed state, the at least one operating element of the operating part is concealed and cannot be operated. The operating part can be converted from the concealed state into an open state of the operating part, in which the at least one operating element is visible and operable, by moving the operating part relative to the base body, in particular by pushing, pulling out, or folding the operating part.Such an arrangement comprising a base body and control unit is described in the aforementioned German patent application 10 2011 084 366.3. The description of such an arrangement and its mode of operation given therein are hereby incorporated by reference into the disclosure of this application.

[0034] The present invention utilizes a safety input means, wherein in this case the safety input means is actuated by the movement of the operating part relative to the base body and placed in the first state, wherein it is then in the first state when open. For example, the safety input means could be designed as a microswitch, wherein the microswitch is actuated, i.e., transferred to the first state, by the movement of the operating part relative to the base body.

[0035] In a further implementation, the safety input means could be designed as a reed relay, for example, whereby the movement of the operating part relative to the base body brings a magnet to the reed relay and thus transfers the safety input means to the first state.

[0036] In this case, it is preferably provided that the safety input means must be actively held in the first state by the user in that the user must hold the operating part in the open state against a counterforce (for example caused by a spring mechanism), since otherwise, without sufficient force being applied by the user, the operating part will fall back into the closed state due to the counterforce and thus the safety input means will leave the first state again.

[0037] A second aspect of the invention relates to a receiver for a remote control as described above, which is integrated into a motor vehicle. The receiver is configured to check the received data to determine whether or not it was generated by the transmitter using the security information described above.

[0038] A third aspect of the invention relates to a motor vehicle with a receiver described above. The motor vehicle can be remotely controlled via a remote control described above in such a way that at least one first vehicle function relevant to functional safety (for example, a parking function for automated parking or exiting) and one or more second vehicle functions (for example, an opening and closing function for a central locking system) can be triggered by the remote control. However, the first vehicle function is only executed if the test in the receiver has confirmed that the received data was generated by the transmitter using the safety information.

[0039] The invention is described below with reference to several exemplary embodiments and with reference to the accompanying drawings. In these drawings: Fig. 1 a conventional transmitter / receiver system used to remotely control a vehicle function: Fig. 2 shows a first embodiment of a remote control according to the invention; Fig. 3 an alternative wiring of the safety circuit; Fig. 4 shows a second embodiment of a remote control according to the invention; Fig. 5 shows a third embodiment of a remote control according to the invention; Fig. 6 shows a fourth embodiment of a remote control according to the invention; and Fig. 7 an example of two buttons on the remote control.

[0040] The approach proposed here allows functional safety-relevant functionalities to be switched on and off via radio key remote control without the requirements of the relevant functional safety standards (e.g. ISO 26262) being transferred to the entire electronics or even just to the microcontroller.

[0041] For the following remote control examples, the following functional safety requirements are assumed: Analogous to the driver in the vehicle, who has ultimate responsibility for the entire operation of the vehicle, the operator operating the remote control (i.e., user) should retain ultimate responsibility for the remotely controlled functions. The first requirement is therefore: The system must prevent the activation of a function relevant to functional safety without the operator's consent.

[0042] It is assumed that disabling this function is a safe state. Therefore, the second requirement is: The system must detect the operator's request to disable the remotely controlled function and implement it by entering the safe state.

[0043] Since the operator no longer has mechanical override in certain situations requiring protection, the system should also be designed to prevent uncontrolled entry or entry into a non-safe state in all situations, especially in the event of operator error. In case of doubt, the safe state must be assumed. This is the third requirement.

[0044] The following examples provide the following to meet the first functional safety requirement: The remote control transmitter contains a secret in the form of security information, which the receiver is expected to activate in order to activate the function relevant for functional safety. This secret should be complex enough to exclude with sufficient probability the possibility of any element in the chain from the transmitter to the

[0045] The transmission path, receiver, and evaluation logic randomly generate the secret—even in the event of a fault. The secret is hidden in a safety circuit as part of a safety device. The strict requirements of the relevant functional safety standard (e.g., ISO 26262) are implemented only for the safety device and not for the entire transmitter. This is a key advantage of the invention. The use of the secret to generate a valid transmission signal to trigger the function to be protected is activated on the transmitter side by a security input from the user, namely by actuating the additional security input device. The receiver checks whether the secret was used to generate the transmission data, and only in this case is the first vehicle function activated.

[0046] The following examples provide the following to meet the second functional safety requirement: The remote control transmitter includes a mechanism that reliably deactivates the protected function as soon as the operator withdraws the security input. It must be ensured with sufficient probability – even in the event of an error – that the secret is deactivated when the operator withdraws the security input. The withdrawal of the security input can occur, for example, by withdrawing a continuous actuation of the security input device (if the security input device is implemented using a button, for example). In this case, the receiving end determines that the security information is no longer being used to generate the transmitted data, and further execution of the protected function is then prevented.

[0047] The following examples provide the following to meet the third functional safety requirement: The security input on the transmitter side is designed so that in typical misoperation situations—for example, dropping the remote control—the protected function is deactivated if it was previously activated. Furthermore, the security input on the transmitter side should be designed so that in typical misoperation situations—for example, a transmitter in a trouser pocket with an unintentional input—it can be ruled out with sufficient probability that the secret (i.e., the security information) will be inadvertently activated.

[0048] In Fig. 2 shows a first embodiment of a safety device according to the invention. The remote control 10 comprises, in addition to the remote control 1 in Fig. 1 a safety device, which comprises a safety input means in the form of a safety switching element Sw, a reset circuit 5 for the transmitter logic 5 and a safety circuit 6. If the user makes an input that is not to be secured (for example, to open or close the central locking system), the remote control 10 behaves in the same way as the remote control 1 in Fig. 1, because the safety switching element Sw is not actuated and the safety switching element Sw is in switching state Z1. In this state Z1, the safety circuit 6 is not active. “Not active” means that the safety circuit 6 cannot provide any safety information G, for example because the safety circuit 6 is switched off, in particular by switching off the operating voltage supply. If the switching state Z1 is present and the safety circuit 6 is not active, the transmitter logic 3 can only send the transmission data S without G, i.e. S = f(E). This is detectable on the receiver side, and the receiver can only activate those functions (e.g. opening the central locking system) that are addressed via user inputs that do not require protection.

[0049] The task of the safety circuit 6 is to communicate initially unknown and sufficiently complex safety information G to the transmitter logic 3, which is used to secure safety-relevant user inputs. The safety circuit can be a memory. The safety circuit can also be a more complex circuit, for example, a microcontroller or an ASIC (Application Specific Integrated Circuit). Preferably, the transmitter logic 3 and the safety circuit 6 are two different semiconductor components, with the safety circuit 6 being secured according to ISO 26262, but not the transmitter logic 3.

[0050] The safety circuit 6 is only active (i.e., can only provide the safety information 6) when the safety switching element Sw is in the switching state Z2. For this purpose, for example, the operating voltage supply V of the safety circuit 6 can be routed via the safety switching element Sw, whereby the safety circuit 6 is only supplied with operating voltage V in the switching state Z2 and only in this case can the safety circuit 6 provide the safety information G at the output. Alternatively, by switching the safety switching element Sw to the switching state Z2, an enable signal En (here an enable signal with the voltage value of the operating voltage V) could be sent to a corresponding enable input of the safety circuit 6, whereby in the case En = V the safety circuit 6 provides the safety information G at its output. An example of this is shown in Fig. 3. Alternatively, a reset signal Rs could be used, which is triggered when the safety switching element Sw is switched back to the switching state Z1, in which case the data output of the safety circuit 6 is reset to a predefined state for a certain period of time and during this period no safety information G is present at the output of the safety circuit. These two variants can also be used in the case of the embodiments in Fig. 4 to Fig. 6 can be used.

[0051] When the safety switching element Sw is actuated, the safety switching element Sw is switched to the switching state Z2, so that the safety circuit 6 becomes active and the security information G is activated for processing in the transmitter logic 3. The transmitter logic 3 then receives and knows the security information G, for example, because the activated safety circuit 6 sends the security information G to the transmitter logic 3 or because the transmitter logic 3 requests the secret G from the safety circuit 6. If the safety circuit 6 is not active, the transmitter logic 6 does not know the secret G.

[0052] In the case of a user input that needs to be secured (for example, to execute an autonomous parking function), the user must make the corresponding input via input device 2, so that a corresponding user input E is present, and actuate the safety switching element Sw, so that the switching state Z2 is assumed. This activates the safety circuit 6, and the transmitter logic 3 can access the safety information G.

[0053] In this case, the user input E is converted into data S to be transmitted with the aid of the security information G. In other words, the transmitted data S is generated using the security information G and the user input E, i.e., S = f(E,G), where the data S contains, for example, the user input E and G in coded form. Any function f(E,G) is suitable, in particular, provided the following coding properties are met: - the complexity of G is preserved by the coding; - a check on the receiver side for the use of the correct security information G when generating the transmission data S is possible; and - the information about the user input E is retained or can be reconstructed on the receiver side.

[0054] For example, to form the transmission data S, the security information G could simply be appended to the user input E, ie S = f(E,G) = E ◯ G. If the user input E consists, for example, of the binary word 1010 and the security information G of the binary word 10011001, the transmission data S would be S = 101010011001.

[0055] A more complex encoding can also be used to generate the transmitted data S. For example, the user input E in the sender logic 3 can be assigned a checksum or a hash, such as a CRC checksum. To determine the CRC checksum, the security information G can represent the starting value (seed) of the CRC: S = f(E,G) = E ◯ CRC(Seed=G, Date=E). Another more complex encoding approach involves using the security information G as a cryptographic key, either in symmetric or asymmetric encryption. For example, if the AES (Advanced Encryption Standard) encryption method is used, the transmitted data S could be determined in the following form: S = f(E,G) = AES (key = G, data = E).

[0056] On the receiver side, the received data S is checked in the evaluation logic 4 to determine whether it was generated on the transmitter side using the security information G. To do this, depending on the function f(E,G) used, it is either checked for security information G that is also known to the receiver (symmetric coding) or, in the case of asymmetric coding, using security information G' that matches the security information G. With symmetric coding, the receiver knows the security information G and knows how the transmitted signal S = f(E,G) is structured. The evaluation logic 4 can then check whether the received data S contains the correct G or, for example, when using the CRC, was calculated and reconstructed based on the correct security information G. With asymmetric coding, the receiver knows the security information G' that matches the security information G and knows how S = f(E,G) is structured.This allows the evaluation logic 4 to check the correctness of the received data S using a further function g(S,G') (which may differ from f(E,G)) and thus reconstruct the user input E (similar to PGP encryption).

[0057] If the received data S has been checked in the evaluation logic 4 to determine whether it was generated on the transmitter side using the security information G, then the reconstructed user input E is to be understood as a user input to be secured and output as A in the receiver. Otherwise, an error is detected on the receiver side, for example, or another meaningful reaction occurs, such as executing only one such action that corresponds to a user input that does not require security. For example, an input button on the remote control 10 can be assigned two functions, namely a function that does not require security (opening or closing the central locking system) and a function that does require security (performing an autonomous parking maneuver).If this input key is pressed and the switching element S is also pressed, the function to be protected is triggered on the receiver side, whereas if the input key is pressed without the switching element S being additionally pressed, the function not to be protected is triggered.

[0058] Preferably, the remote control 10 repeatedly transmits corresponding data to the receiver at a specific time interval, for example, every 10 ms. If, after a specific period of time (for example, 100 ms) following the receipt of data valid for executing the vehicle function to be protected, no more valid data is received that was generated on the transmitter side using the safety information G, further execution of the function to be protected is stopped, for example. This also applies accordingly to the following exemplary embodiments.

[0059] The remote control 10 is configured such that the transmitter logic 3 loses the safety information G again when the safety switching element Sw leaves the switching state Z2. Preferably, a reset circuit 5 is used for this purpose, which ensures that the transmitter logic 3 reliably forgets the safety information G as soon as the safety information G has been deactivated (switching from state Z2 to state Z1). The task of the reset circuit is, for example, to generate a reset pulse R for the transmitter logic 3 from the edge change of the signal R' when switching from state Z2 to state Z1. In the steady state (switching state Z1), the reset pulse has expired, i.e. the transmitter logic is not in the reset state, but ready for operation. This does not change when the state changes from Z1 to Z2.When the state changes back from Z2 to Z1, an edge change occurs at R' and the reset circuit 5 generates the reset pulse R, which causes the transmitter logic 3 to switch to a reset state and lose the safety information G. As soon as the reset pulse R has expired, the steady state is reached again. The reset circuit should therefore preferably be designed so that the transmitter logic 3 reliably forgets the previously explicitly or at least theoretically (also in the event of a fault) known safety information G with sufficient probability as soon as the safety information G has been deactivated by switching the safety switching element Sw from Z2 to Z1. The reset, ieThe resetting of the transmitter logic 3 can, for example, be carried out via an existing reset input of the transmitter logic 3 if a reset triggered in this way reliably deletes or resets an internal memory of the transmitter logic 3 that could contain the safety information G with sufficient probability. The resetting of the transmitter logic 3 can alternatively be carried out, for example, by (temporarily) removing the operating voltage of the transmitter logic 3 if, for example, the transmitter logic 3 is equipped with one or more volatile memories that can contain the safety information G.

[0060] In Fig. 4 shows a second embodiment of the remote control 20. In the Fig. In the example shown in Figure 4, when the safety switching element Sw is actuated, the safety circuit 6 generates the data H using the safety information G and the transmitter logic 3 generates the data S using the user input E. The data SH to be sent result from H and S, for example as a concatenation of H and S or as a more complex function of H and S.

[0061] In Fig. 4 the processes are similar to those in Fig. 2, in particular the functioning of the safety switching element Sw. For the Fig. 4 aspects not described are referred to the description of Fig. 2. However, in Fig. 4 in contrast to Fig. 2 not the sender logic 3 the security information G to generate the data S to be sent from G and the user input E. Instead, in Fig. 4 the safety circuit 6 makes the data H in addition to S of the transmitter logic 3 ready for transmission if the safety circuit 6 was activated upon actuation of the safety switching element Sw, for example by switching on the supply voltage V (alternatively, activation / deactivation could also be controlled via the enable input or the reset input of the safety circuit 6). In the simplest case, H = G and S = E. Preferably, one or both data values ​​H and S are coded, ie H = f1(G) and S = f2(E). H or S can also contain further information such as the identification of the transmitter (also referred to as transmitter ID) or a checksum (for example CRC) or a sequence counter.

[0062] The Fig. The reset circuit 5 shown in Figure 2 is located in the safety device in Fig. 4 is not necessary, since the sender logic 3 never knows the security information G and it is therefore not necessary for the sender logic 3 to reliably forget the security information G.

[0063] In Fig. 4, SH is sent, which results from S and H, i.e. SH = f(S,H). For example, H and S can be sent in a time-correlated manner (e.g., as a concatenation SH = SoH or SH = HoS). For example, sender logic 3 first sends S and then safety circuit 6 sends H. It is also conceivable that, when the data is repeatedly transmitted, either H or S is sent less frequently than S or H, respectively. For example, H can be sent less frequently than S in order to reduce the amount of data. H can be sent periodically and independently of S. Furthermore, it is possible for SH to result from a concatenation of alternating sub-segments of S and H, i.e., for example, first a sub-segment of S, then a sub-segment of H, then again a sub-segment of S, etc.

[0064] On the receiver side, SH is checked for correctness (ie whether SH was generated using the security information) and, if successful, a corresponding output signal A is issued to execute the function to be protected. The procedure is analogous to that to Fig. 2. In this embodiment, too, a reliable deactivation of the safety circuit 6 occurs when the safety switching element switches from the switching state Z2 to the switching state Z1 analogously to the Fig. 2. When the safety circuit 6 is deactivated, no valid H is generated or at least no longer output by the safety circuit 6, and thus only S and no SH is sent.

[0065] In Fig. 5 shows a third embodiment of the remote control 30. In Fig. 5, the safety circuit 6 generates the data H when the safety switching element Sw is actuated using the safety information G and the data S generated from E by the transmitter logic 3. Alternatively, it would also be conceivable for E to be used directly instead of S. The transmission data SH results from H and optionally S. It is possible for SH to be equal to H.

[0066] In Fig. 5 the processes are similar to those in Fig. 4. For the Fig. 5 aspects not described are referred to the description of Fig. 2 and Fig. 4. In the example in Fig. 5, when the safety switching element Sw is actuated, the safety circuit 6 generates the data H using the safety information G. In contrast to the example from Fig. 4, the safety circuit 6 also uses the data S generated by the transmitter logic 3 for this purpose. It would also be conceivable to use the user input E instead. The transmission data SH to be transmitted results from H and optionally S; in particular, the transmission data SH can also correspond to H.

[0067] In the Fig. In the example shown in Figure 5, the safety circuit 6 considers both the safety information G and the data S coming from the transmitter logic 3 when calculating H and then makes H available for transmission when the safety circuit 6 was activated upon actuation of the safety switching means Sw. Thus, H = f3(G,S).

[0068] For example, the function f3 can be a checksum or encryption function, analogous to the examples given in connection with Fig. 2. The generation of the transmission data SH as well as the checking and evaluation of the data SH on the receiver side work in the same way as in connection with Fig. 4. Likewise, in this embodiment, as already described in connection with Fig. 4 - optionally a reset circuit 5 can be used (see dashed outline in Fig. 5). In this embodiment, too, a reliable deactivation of the safety circuit 6 occurs when switching from the switching state Z2 to the switching state Z1, as already described in connection with Fig. 2. If safety circuit 6 is deactivated, no H can be generated and thus only S and no SH can be sent.

[0069] The Fig. The variant shown in Figure 5 offers, in contrast to the variant shown in Fig. The variant shown in Figure 4 has the advantage that H typically changes depending on the signal S and thus depending on the user input E. This can offer advantages in terms of transmission protocol technology. For example, it might be useful to provide different safeguards H for different user inputs E. For example, the "size" (e.g., number of bits) of H could be reduced for less functional safety-relevant user inputs E that occur more frequently, compared to more functional safety-relevant user inputs E that occur less frequently, for example to save bandwidth of a radio transmission.

[0070] In Fig. Figure 6 shows a fifth embodiment of the remote control 40. Here, the security circuit 6 comprises means 7 for releasing the security information G such that the security information is processed within the security circuit 6.

[0071] The means 7 for releasing the safety information G are coupled to the safety switching element Sw via the input GEn such that, upon actuation of the safety switching element Sw, the safety information G is released for processing within the safety circuit 6. The safety circuit 6 is configured to generate the transmission data W to be transmitted using the safety information G and the data S generated by the transmitter logic 3 when the safety information G is released.

[0072] A significant difference from the other embodiments is that the safety circuit is not completely activated or deactivated by means of the safety switching element Sw. In the case of a user input E to be protected (i.e. in switching state Z1), the safety information G is enabled within the safety circuit 6 if a corresponding signal is present at the input GEn in switching state Z1. If the safety information G is enabled, the safety circuit 6 can calculate transmission data W from S using G, so that W = f(S,G). Without enabled safety information G, the safety information cannot use the safety information G for this purpose, so that transmission data W is calculated according to W = f(S). The transmission data W is then transmitted and evaluated at the receiver end (analogous to the Fig. 4). When the safety switching element Sw leaves the switching state Z2 again, the safety circuit 6 loses the enable for using the safety information G; the input GEn is then no longer at the potential of the operating voltage V. In order to achieve a reliable reset of the safety circuit G, Fig. 6 preferably analogous to Fig. In the case described in Figure 2 (via reset circuit 5), a reset is triggered when switching from switching state Z2 to switching state Z1. However, this reset affects the part of safety circuit 6 that is activated independently of the safety switching element Sw.

[0073] The functional safety of the approaches described above can optionally be increased by designing the safety switching element Sw as a dead man's switch. This ensures that in the event of incorrect operation, such as dropping the remote control or slipping, the system switches to a safe state. To achieve this, the switching element must be designed in such a way that the operator must keep the switching element active in switching state Z2 throughout the entire control process of a user input to be protected, in particular by applying force. For example, this can be achieved by continuously pressing a button encompassing the safety switching element Sw against a counterforce of the button or by continuously holding an extended operating element against a counterforce.

[0074] In Fig. Figure 7 shows two exemplary buttons 8 and 9 of a remote control. Button 8 is a button for activating a non-protected function, for example, opening the central locking system. Button 9 is a button for activating a protected function, for example, an autonomous parking or exit function.

[0075] The button 8 comprises an operating surface 11 and the switching element Sw_E1. The switching element Sw_E1 serves as an input means for obtaining a user input E. When the switch 8 is actuated by pressing the operating surface 11 with a force F1 that is greater than the counterforce F3 of the button 8, the switching element Sw_E1 is set to the switching state Z2 and a corresponding user input E is generated, which indicates the user's selection of the function not to be protected and is converted into a corresponding transmission signal S by the transmitter logic 3. Upon receipt of the transmission signal S, the function not to be protected is triggered in the vehicle.

[0076] The button 9 comprises an operating surface 12 and the switching element Sw_E2. Similar to the switching element Sw_E1, the switching element Sw_E2 serves as an input means for obtaining user input. When the switch 9 is actuated by a force F2 that is greater than the counterforce F4 of the button 9, the switching element Sw_E2 is actuated and placed in the switching state Z2, and a corresponding user input E is generated, which indicates the user's selection of the function to be protected. The button 9 also comprises the safety switching element Sw. When the button 9 is actuated, not only is the switching element Sw_E2 actuated and placed in the switching state Z2, but the safety switching element Sw is also actuated and placed in the switching state Z2.Only when the safety switching element Sw is in the switching state Z2, the safety information G is used to generate transmission data S, which, when received, can actually cause the execution of the vehicle function to be protected.

[0077] In contrast to Fig.7 In addition to a single safety switching element Sw, several safety switching elements can also be used which must be actuated together to ensure the use of the safety information and to trigger the desired vehicle function. Alternatively, several switching elements can be used which must be actuated in a sequence, whereby, for example, the last switching element to be actuated corresponds to the safety switching element described above. In order to trigger the function to be protected using the safety information, the other switching elements must then also be actuated in the specified sequence. In this case, at least the last switching element actuated remains in state Z2 when executing the function to be protected, whereby the execution of the function to be protected is aborted when state Z2 is exited.Theoretically, it can also be provided that all or a subset of the switching elements to be switched in sequence must remain switched during the execution of the vehicle function to be protected, for example an operating unit coupled to a switching element which must be pulled out and in doing so switches the switching element and must remain pulled out during the execution of the function, and a side button which is to be actuated after the operating unit has been pulled out and which must be pressed and must remain pressed during the execution of the function.

[0078] In addition to or in combination with the safety switching element Sw, a distinction can also be made in the user input E between inputs relevant to functional safety and inputs not relevant to functional safety. For example, simultaneous actuation of various buttons (or other operating elements) of the input means for E may be necessary to generate an input E relevant to functional safety. Alternatively, sequential actuation of several buttons (or several operating elements) for E may be necessary to generate an input E relevant to functional safety.

Claims

[1] Radio remote control (10, 20, 30, 40) - to control at least one primary vehicle function relevant to functional safety and - for controlling one or more additional secondary vehicle functions of a motor vehicle, including - user-operated input means (2) for user-activated vehicle functions, including for activating the first vehicle function, and for obtaining a user input (E) corresponding to the vehicle function to be activated, wherein, in the case that the first vehicle function is to be activated, a user input (E) associated with the first vehicle function is available, and - a sender logic (3) for processing the user input (E), characterized by , that the remote control also includes: - a safety device (6) to safeguard the first vehicle function with - a user-operated safety input device (Sw) which is required to perform the first vehicle function, and - a safety circuit (6) coupled to the safety input device (Sw) with safety information (G), wherein the remote control is configured such that in the case of a user input (E) assigned to the first vehicle function, the safety information (G) is used to generate transmission data (S; SH; W) that cause the execution of the first vehicle function only if the safety input device has been activated. [2] Radio remote control (10) according to claim 1, wherein - the safety input device (Sw) is moved into a first state (Z2) upon activation and remains in this first state (Z2) during the execution of the first vehicle function, - the remote control is set up in such a way that when leaving the first state (Z2), the use of the security information (G) to generate such transmission data is excluded. [3] Radio remote control (10) according to one of claims 1 or 2, wherein the remote control (10) is configured such that when the safety input means (Sw) is activated, the transmitter logic (3) - receives the security information (G) and - the transmission data (S) is generated using the safety information (G) and the user input (E) assigned to the first vehicle function. [4] Radio remote control (10) according to claim 3, wherein - the safety input device (Sw) is moved into a first state (Z2) upon activation and remains in this first state (Z2) during the execution of the first vehicle function, - the remote control is configured in such a way that, upon exiting the first state (Z2), the use of the security information (G) for generating such transmission data is excluded, and - the remote control is set up such that the transmitter logic (3) loses the security information when the security input device (Sw) leaves the first state (Z2). [5] Radio remote control (10) according to claim 4, wherein the safety device further comprises: - a reset circuit (5) coupled with the safety input device (Sw) for generating a reset pulse, wherein when the reset pulse is triggered the transmitter logic (3) loses the safety information (G). [6] Radio remote control (20) according to one of claims 1 or 2, wherein the remote control (20) is configured such that - when the safety input device (Sw) is activated, the safety circuit (6) generates first data (H) using the safety information (G) or provides the safety information (G) as first data (H), - the transmitter logic (3) generates second data (S) using the user input (E) assigned to the first vehicle function, or the user input (E) assigned to the first vehicle function corresponds to the second data (S) and - the transmission data (SH) is derived from the first data (H) and the second data (S). [7] Radio remote control (30) according to one of claims 1 or 2, wherein the remote control (30) is configured such that - when the safety input device (Sw) is activated, the safety circuit generates first data (H) using the safety information (G) and using second data (S), - the transmitter logic (3) generates the second data (S) using the user input (E) assigned to the first vehicle function, or the user input (E) assigned to the first vehicle function corresponds to the second data (S) and - the data to be sent (SH) is derived from the first data (H) and optionally the second data (S), or the data to be sent (SH) corresponds to the first data (H). [8] Radio remote control (20, 30) according to one of claims 6 or 7, wherein - the safety input device (Sw) is moved into a first state (Z2) upon activation and remains in this first state (Z2) during the execution of the first vehicle function, - the remote control is configured in such a way that, upon exiting the first state (Z2), the use of the security information (G) for generating such transmission data is excluded, and - the remote control (20, 30) is configured such that the safety circuit (6) no longer generates or outputs any initial data (H) using the safety information (G) when the safety input device (Sw) leaves the initial state (Z2). [9] Radio remote control (40) according to one of claims 1 or 2, wherein - the transmitter logic (3) generates second data (S) using the user input (E) assigned to the first vehicle function, - the safety circuit (6) comprises means (7) for releasing the safety information (G) for processing within the safety circuit (6), wherein the means (7) for releasing the safety information (G) are coupled to the safety input means (Sw) such that when the safety input means (Sw) is actuated, the safety information (G) is released for processing within the safety circuit (6), and - the safety circuit (6) is set up to generate the transmit data (W) to be sent, using the safety information (G) and the second data (S), when the safety information (G) is released. [10] Radio remote control (40) according to claim 9, wherein - the safety input device (Sw) is moved into a first state (Z2) upon activation and remains in this first state (Z2) during the execution of the first vehicle function, - the remote control is configured in such a way that, upon exiting the first state (Z2), the use of the security information (G) for generating such transmission data is excluded, and - the remote control (40) is configured such that the safety circuit (6) loses the authorization to use the safety information (G) when the safety input device (Sw) leaves the first state (Z2). [11] Radio remote control (10, 20, 30, 40) according to one of the preceding claims, wherein the safety input means is a safety switching element, and the remote control (40) comprises a first button (9) which includes the safety switching element (Sw). [12] Radio remote control (10, 20, 30, 40) according to claim 11, wherein the first button (9) - in addition to the safety switching element (Sw), it includes another switching element (Sw_E2) which serves to obtain one of the user inputs (E) assigned to the first vehicle function, and - is designed in such a way that when the first button (9) is pressed, both the safety switching element (Sw) and the further switching element (Sw_E2) are activated. [13] Radio remote control (10, 20, 30, 40) according to claim 11, wherein - the remote control includes at least one additional button besides the first button and - the additional button serves as an input device to activate the first vehicle function. [14] Radio remote control (10, 20, 30, 40) according to any one of the preceding claims 1-10, wherein the remote control (10, 20, 30, 40) comprises: - a basic body and - a control unit comprising at least one control element, wherein the remote control is designed such that - in a concealed state of the control unit, at least one control element of the control unit is concealed and cannot be operated, - the control unit can be moved from a concealed state to an open state by moving the control unit relative to the base body, in particular by pushing out, pulling out or folding the control unit, in which the at least one control element is visible and operable, and - the safety input device (Sw) is activated by the movement of the control unit relative to the base body. [15] Radio remote control (10, 20, 30, 40) according to one of the preceding claims, wherein - the safety input device (Sw) is moved into a first state (Z2) upon activation and remains in this first state (Z2) during the execution of the first vehicle function, - the remote control is set up in such a way that when leaving the first state (Z2), the use of the security information (G) to generate such transmission data is excluded and - the remote control (10, 20, 30, 40) is set up in such a way that the safety input device (Sw) is to be kept in the first state (S2) during the execution of the first vehicle function by the user, in particular by exerting force on the part of the user. [16] Radio remote control (10, 20, 30, 40) according to one of the preceding claims, wherein the first vehicle function is a parking function for automating the parking or unparking of the passenger car. [17] Receiver for the radio remote control (10, 20, 30, 40) according to one of the preceding claims, wherein the receiver is configured, - to check received data (S, SH, W) to see if it was generated by the sender using the security information (G). [18] Motor vehicle comprising and equipped with a receiver according to claim 17, - remotely controllable to perform at least one first vehicle function relevant to functional safety and one or more further second vehicle functions and - to execute the first vehicle function only if the check in the receiver has confirmed that the received data (S, SH, W) were generated on the sender side using the safety information (G).

Citation Information

Patent Citations

  • Lift e.g. stair lift, or crane starting and operation method, involves providing remote control with separate current supply and automatically carrying out starting of lift or crane by learning program in self-learning manner

    DE102005039531A1

  • key transmitter with a device for automatically releasing a cover

    DE102006010170A1

  • Vehicle e.g. hybrid vehicle, maneuvering method, involves releasing parking brake, transferring forward- or backward driving position in automatic transmission, and regulating speed of vehicle by parking brake

    DE102008051982A1

  • Driver assistance device for a motor vehicle and method for assisting a driver in monitoring an autonomous parking maneuver of a motor vehicle

    DE102009041587A1

  • Method for securing of parking process of motor car using remote control, involves producing evaluation signal based on checked state of barrier, and producing output signals for release of driving process based on evaluation signal

    DE102010005327A1