Method for authenticating a diagnostic fault code generated by a vehicle's automotive system
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
- Filing Date
- 2018-05-17
- Publication Date
- 2026-07-23
AI Technical Summary
The existing method for storing diagnostic trouble codes (DTCs) in automotive systems loses consistency between volatile and non-volatile memory when the ECU is shut down, making it vulnerable to hacker attacks that manipulate error information, which cannot be detected.
A method involving generating a diagnostic error code with an error detection algorithm, storing it with an identity marker in non-volatile memory, and authenticating it upon ignition using the same algorithm to detect any manipulation.
Prevents malicious manipulation of DTCs by external sources and ensures data integrity by verifying the authenticity of stored error codes.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for authenticating at least one diagnostic fault code generated by a vehicle's automotive system ( DTC ) in the event of at least one defined fault event in the vehicle system.
[0002] Modern vehicles incorporate one or more computer systems that, as electronic control units (ECUs), control and monitor the operation of numerous vehicle systems, such as the engine, steering, transmission, braking system, climate control system, safety system, and driver assistance system. Furthermore, numerous sensors are installed in such vehicles, sending measurement data to the control units for the control of these vehicle systems. Such vehicle systems, including their associated algorithms and sensors, are susceptible to errors, failures, and malfunctions. Therefore, these electronic control units have diagnostic units that monitor the corresponding vehicle systems and detect fault conditions. If such a fault condition is detected in a vehicle system, an error code, e.g., a diagnostic fault code ( DTC The diagnostic trouble code (DTC) is generated, which is initially stored in volatile memory (RAM) and, after the vehicle's ignition is switched off, in non-volatile memory (EEPROM) during a run-on phase. After the write phase to the non-volatile memory is complete, the ECU is disconnected from the terminal. 30 separated and simultaneously the volatile memory with the DTCs deleted.
[0003] The disadvantage of this method is that shutting down the ECU results in a loss of consistency between the current fault information in the volatile memory and the fault information stored in the non-volatile memory. This creates the risk that a hacker attack could be carried out on the vehicle bus via a wireless communication device or an OBD port, for example, with the aim of altering or manipulating the data contents of the non-volatile memory.
[0004] After the ignition is switched back on or a "wake-up" via a vehicle bus (e.g., CAN bus), the fault information stored in the non-volatile memory is loaded back into the volatile memory as input for the vehicle system. This input serves as information for the vehicle system about existing fault conditions, which must be retained until this fault condition is confirmed again by a diagnostic function in the current ignition cycle.
[0005] Therefore, manipulation of this error information cannot be detected.
[0006] The object of the invention is to provide a method by which the consistency of the DTCs stored in a non-volatile memory can be verified.
[0007] This problem is solved by a method having the features of claim 1.
[0008] According to the invention, such a method for authenticating at least one diagnostic fault code generated by a vehicle system in the event of at least one defined fault event in the vehicle system is characterized by the following method steps: a) Generating a diagnostic fault code using a fault detection algorithm when the fault event occurs in the vehicle system, b) Storing the diagnostic fault code in a volatile fault memory, c) Generating an identity marker using the freeze-frame data that characterizes the fault detection algorithm at the time the diagnostic fault code is generated, d) Storing the identity marker in a non-volatile error memory, e) Storing the diagnostic fault code in the non-volatile fault memory when an ignition-off request signal is present, which together with the identity marker forms an authentication data record, f) Loading the diagnostic fault code from the non-volatile fault memory to the volatile fault memory when an ignition-on request signal is present and g) Authenticating the diagnostic fault code using the authentication record, by g1) first, the fault detection algorithm is determined with which the fault event indicated by the diagnostic fault code can be detected, g2) this error detection algorithm is then compared with the error detection algorithm indicated by the identity marker, and g3) if there is no match, a manipulation of the diagnostic error code is indicated.
[0009] In this method according to the invention, a diagnostic error code is stored together with an identity marker as an authentication data record, wherein this identity marker is based on freeze-frame data that indicate the conditions under which this diagnostic error code was generated, i.e., the error detection algorithm with which the displayed error event can be detected is specified.
[0010] A diagnostic fault code that is generated by an external source, e.g., fraudulently by a customer service tester, and stored in a fault memory, is not based on an internal vehicle monitoring process, which is why the storage of this diagnostic fault code is fraudulent.
[0011] The method according to the invention prevents malicious manipulation of the vehicle system's behavior via an external source. Furthermore, it prevents the storage of incorrect data that does not correspond to the relevant freeze-frame data at the time the diagnostic fault code is generated.
[0012] According to an advantageous further development of the invention, the identity marker is generated as a token using a cryptographic algorithm. For example, a hash value (fingerprint) can be calculated using the code of the error detection algorithm, which is compared with a stored hash value (fingerprint) at another memory location, thus ensuring that the error detection algorithm itself has not been changed.
[0013] A further advantageous embodiment of the invention provides that a source marker is generated which indicates whether the diagnostic fault code is generated by means of a source external to the vehicle, wherein the authentication data set is generated from the diagnostic fault code, the identity marker and the source marker.
[0014] Using such a source marker offers the advantage of explicitly logging both the diagnostic fault code storage and the method used to store the diagnostic fault code. This allows them to be logged independently, enabling the detection of any subsequent external manipulation of the diagnostic fault code or the detection method.
[0015] A final advantageous embodiment of the method according to the invention provides that c1) for the fault event indicated by the diagnostic fault code, an error response is provided, and c2) to generate the identity marker, additionally the data characterizing the error response are used.
[0016] The method according to the invention is described below using exemplary embodiments with reference to a single accompanying document. Fig. 1 describe which shows a block diagram to explain the method according to the invention.
[0017] The Fig. Figure 1 shows a schematically indicated vehicle system 1 (e.g., a braking system) of a vehicle, showing only the components relevant to the process. Furthermore, this shows Fig. 1 a workshop tester 10 , which includes a diagnostic module 1.2 is connected, which enables communication with the connected workshop tester. 10 and the execution of commands from the workshop tester 10 , such as reading an error memory in a RAM memory 1.4 (cf.) Fig. 1) takes over an ECU.
[0018] Using an error detection algorithm implemented as a software component 1.1 The functions of the vehicle system will be 1 monitored and, in the event of a defined fault event in the vehicle system, a diagnostic fault code indicating this fault event is generated. DTC This diagnostic error code was issued. DTC is done, on the one hand, by means of the diagnostic module 1.2 in a volatile error memory (RAM) 1.4 stored and on the other hand a memory (RAM) 1.3 supplied to the storage 1.3 Furthermore, at the time the diagnostic error code is generated DTC which the error detection algorithm 1.1 Characteristic freeze frame data stored. From the diagnostic error code DTC and an identity marker is assigned to the still image data. IDM generated, which is stored in a non-volatile error memory (EEPROM) 1.5 is saved.
[0019] The identity marker IDM It is generated as a token using a cryptographic algorithm. This means that a hash value (fingerprint) is calculated using the code of the error detection algorithm, which is then compared to a stored hash value (fingerprint) in another memory location, thus ensuring that the error detection algorithm itself has not been changed.
[0020] It is also possible to use the diagnostic error code for the DTC to provide an error response to the displayed error event and to additionally use the data characterizing the error response to generate the identity marker.
[0021] If an ignition-off request signal is present, e.g., when the ignition is switched off using the vehicle's ignition lock, the diagnostic fault code will be displayed. DTC from the volatile error memory 1.4 into the non-volatile error memory 1.5stored and from the diagnostic error code DTC and the identity marker IDM an authentication record ATD educated.
[0022] It is also possible to use this authentication record. ATD with another one as a source marker QM to form the designated dataset. This source marker QM indicates whether the diagnostic error code DTC via an external source, e.g., with the customer service tester 10 was generated. This information is generated by the diagnostic module. 1.2 directly to the non-volatile error memory 1.5 It is fed in and stored there. In this case, the authentication data record consists of... ATD from three data sections, namely the diagnostic error code DTC , the identity marker IDM or the corresponding token and the source marker QM .
[0023] With such an authentication data set ATD (with or without source markers) QM ) the consistency of the diagnostic error code DTC with the identity marker IDM or with the identity marker IDM and the source marker QM checked, i.e., the authentication of the diagnostic error code DTC carried out.
[0024] Authentication of the diagnostic fault code DTC When an ignition-on request signal is present, i.e., when the ignition is switched on via the ignition lock, an authentication unit is used. 1.6 This is carried out by first determining the error detection algorithm with which the diagnostic error code is determined. DTC The displayed error event can be detected, which is stored in volatile memory. 1.4 is loaded. This error detection algorithm is then used with the identity marker. IDM displayed error detection algorithm 1.1compared and, in case of a lack of match, manipulation of the diagnostic error code DTC by means of manipulation information MI a manipulation treatment unit 1.7 supplied.
[0025] The manipulation treatment unit 1.7 It is used to detect a manipulated diagnostic error code DTC , i.e., an impermissible entry of such a diagnostic error code DTC The recorded error is compared to the stored detection method for plausibility. If the corresponding information is not plausible, manipulation of the diagnostic error code in the non-volatile error memory is suspected. 1.5 vicinity.
Claims
[1] Method for authenticating at least one diagnostic trouble code (DTC) generated by a vehicle system in the event of at least one defined fault event in the vehicle system (1), wherein the method comprises: a) Generating a diagnostic trouble code (DTC) using a fault detection algorithm (1.1) when the fault event occurs in the vehicle system (1), b) Storing the diagnostic trouble code (DTC) in a volatile fault memory (1.4), c) Generating an identity marker (IDM) with the freeze frame data identifying the fault detection algorithm (1.1) at the time the diagnostic trouble code (DTC) is generated, d) Storing the identity marker (IDM) in a non-volatile error memory (1.5), e) Storing the diagnostic trouble code (DTC) in the non-volatile fault memory (1.5) when an ignition off request signal is present, which together with the identity marker (IDM) forms an authentication data record (ATD), f) Loading the diagnostic trouble code (DTC) from the non-volatile fault memory (1.5) to the volatile fault memory (1.4) when an ignition-on request signal is present and g) Authenticating the diagnostic trouble code (DTC) using the authentication data set (ATD) by first determining the fault detection algorithm with which the fault event indicated by the diagnostic trouble code (DTC) can be detected, g2) this error detection algorithm is then compared with the error detection algorithm (1.1) indicated by the identity marker (IDM), and g3) if there is no match, a manipulation of the diagnostic trouble code (DTC) is indicated. [2] Method according to claim 1, wherein the identity marker (IDM) is generated as a token using a cryptographic algorithm. [3] Method according to claim 1 or 2, wherein a source marker (QM) is generated which indicates whether the diagnostic trouble code (DTC) is generated by means of a source external to the vehicle, wherein the authentication data set (ATD) is generated from the diagnostic trouble code (DTC), the identity marker (IDM) and the source marker (QM). [4] Method according to any one of the preceding claims, wherein c1) a fault response is provided for the fault event indicated by the diagnostic trouble code (DTC), and c2) the data characterizing the fault response is additionally used to generate the identity marker (IDM).