Provision of log data of a motor vehicle

DE102024101677A1Pending Publication Date: 2025-07-24BAYERISCHE MOTOREN WERKE AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102024101677
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-07-24

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method (300) for providing log data of a system (305, 310) on board a motor vehicle (110) comprises steps of detecting a request from a location (110) external to the motor vehicle (110) for providing the log data; encrypting the log data; and providing the encrypted log data.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the provision of log data of a motor vehicle. In particular, the invention relates to the provision of log data of a sensitive system on board a motor vehicle.

[0002] A motor vehicle comprises several systems that perform dedicated tasks on board. To monitor operation, measure performance, or predict maintenance intervals, a system can store information regarding its condition in log data. If an unforeseen condition occurs, such as an error or exception, information can be stored in the log data that allows the condition to be addressed. This allows the system to be improved or further developed.

[0003] Log data can contain sensitive information that should not be disseminated uncontrollably. For example, certain information can be used to reconstruct the system's operation, posing a risk of intellectual property theft. The log data can also contain personal information, such as a history of internet addresses visited by a person on board or an address book containing that person's contacts.

[0004] One object underlying the present invention is to provide an improved technology for providing log data on board a motor vehicle. The invention achieves this object by means of the subject matter of the independent claims. Subclaims specify preferred embodiments.

[0005] According to a first aspect of the present invention, a method for providing log data of a system on board a motor vehicle comprises steps of detecting a request from a location external to the motor vehicle for providing the log data; encrypting the log data; and providing the encrypted log data.

[0006] According to the invention, sensitive log data is not provided in plain text, but only in encrypted form to a location outside the motor vehicle. Prior to exporting the log data, no encryption is required, thus reducing the effort required to handle the log data. Particularly when log data is generated because an error has occurred, the log data can be stored internally more effectively by omitting encryption, without the risk of another error occurring during encryption. Processing of the log data on board the motor vehicle, for example, by another system, can proceed unhindered.

[0007] Only when the request for provision arrives from the external party can the requested log data be determined and encrypted. Transmitting log data externally is usually not time-critical, so a certain delay caused by encryption can be tolerated.

[0008] The log data may be confidential. In one embodiment, a distinction can be made between confidential and non-confidential log data. Confidential log data can only be provided in encrypted form. Non-confidential log data, on the other hand, can also be provided in plain text. Different types of log data can be labeled with regard to their confidentiality.

[0009] In another embodiment, log data from a first system can be classified as confidential, and log data from a second system can be classified as non-confidential. The first system can also provide non-confidential log data, which is then nevertheless provided in encrypted form. The second system, on the other hand, should only provide log data marked "non-confidential" according to the classification applied.

[0010] In a further embodiment, a degree of encryption can depend on a degree of confidentiality of the log data. This allows different security requirements to be met. For example, log data that only contains information that could also be obtained by other means can only be obfuscated or scrambled. Log data that includes, for example, personal information, can, however, be encrypted using a first encryption method. Log data that includes critical information that could, for example, potentially give an attacker access to a function of the motor vehicle can be encrypted using a second encryption method, which can be more secure than the first method. For example, the methods can differ in the length of a digital key or in the choice of encryption algorithm.In general, increased encryption security is accompanied by increased effort in encryption and / or decryption.

[0011] The system can control a security function on board the motor vehicle. In particular, the security function can control access to the motor vehicle. For example, a first security function can include unlocking a door or hatch. A second security function can relate to the use of the motor vehicle, for example, starting a drive engine or starting the motor vehicle. If the security function is compromised, the motor vehicle can be stolen or used without authorization.

[0012] In a particularly preferred embodiment, the security function is secured using a digital car key (DCK). A specification for the DCK has been published by the Car Connectivity Consortium and is currently available as Digital Key Release 3 in version 1.0.11. The DCK proposes the cryptographic security of a motor vehicle, whereby a user can store a digital key on a personal, assigned mobile device. To use the key, the user must authenticate themselves to the mobile device, for example, by presenting a biometric feature or entering a secret.

[0013] Cryptographic functions in the vehicle-side implementation of the DCK can provoke errors or other special conditions, the resolution of which requires information that could, for example, reveal a private processing method or a key or other cryptographic secret. For example, a function in which a special condition occurs can log predetermined information summarized in a "freeze frame." The information included in this information may depend on the function. Under certain circumstances, a freeze frame can be used to construct an attack vector against the function, which could ultimately undermine the vehicle's security.

[0014] The external party can be protected using an asymmetric encryption method. To do this, the external party can have a public and a private key that match each other in such a way that encryption with the public key can be overridden by decryption with the private key. The public key can be stored at a public location. In particular, the public key can be used to asymmetrically encrypt log data during readout, so that it can only be decrypted by the owner of the private key.

[0015] The external party can be authenticated using a challenge-response procedure, in which it proves possession of a secret key that matches a public key, thus proving the external party's identity. The asymmetric authentication procedure can be designed as a two-way process, with the vehicle also being assigned a pair of private and public keys, so that the vehicle can also prove its identity.

[0016] The asymmetric authentication method ensures that only a request from a predetermined external party results in the provision of log data. This prevents log data from being leaked to an unauthorized party.

[0017] The log data can be signed using an asymmetric signature method. For this purpose, a cryptographic hash can be created for a message and, signed with the private key, attached to the message. The signed hash is preferably determined based on a private key of the motor vehicle and a device (200) providing the log data. By signing the log data, authorship of the data can be verified.

[0018] Encryption can be performed dedicated to the external party. This ensures that only the requesting external party can decrypt the provided encrypted log data. Since an attacker does not know the private key of the authorized external party, it can be ensured that an attacker who intercepts provided encrypted log data cannot decrypt the data. Using an asymmetric encryption method can also prevent a Janus attack (man in the middle).

[0019] More preferably, encryption is performed hybridly. A session key can be negotiated with the external party based on an asymmetric encryption method. Encryption can then be performed using a symmetric encryption method based on the session key. The symmetric encryption method is easier to apply and, in particular, allows for the encryption of large amounts of data. With the symmetric encryption method, the same cryptographic key is used for both encryption and decryption. Very efficient algorithms are known for symmetric methods, and a processing device on which the method runs can be equipped to significantly accelerate symmetric encryption.

[0020] Random data can be deliberately added to the log data, and the log data and random data can be encrypted and provided together. An attacker analyzing encrypted log data cannot initially distinguish whether they are working on encrypted data or encrypted random data. This can increase the attacker's security against analysis and rekeying. The random data can be formatted like log data and contain meaningless information. Alternatively, the random data can be inserted between actual log data and have no fixed structure.

[0021] The system can provide a stream of log data. Random data can be mixed into the log data in such a way that a predetermined data rate is maintained. This allows real-time analysis of a system function without the fluctuation in the data rate being used to analyze system behavior. The data rate can be kept above a first threshold and / or below a second threshold. If the system provides only a small amount of log data, a proportion of the random data can be increased, and vice versa. The data rate can also follow a predetermined pattern, which in one embodiment is itself determined to be random.

[0022] According to a further aspect of the present invention, a device (200) on board a motor vehicle comprises a communication device for communicating with a location external to the motor vehicle; an interface to a source of log data; and a processing device. The processing device is configured to receive a request for providing log data from the external location; encrypt log data from the source; and provide the encrypted log data to the location.

[0023] The processing device is preferably configured to partially or completely execute a method described herein. For this purpose, the processing device can be implemented electronically and, for example, comprise an integrated circuit, a programmable logic module, or a programmable microcomputer. The method can be implemented in the form of a configuration or as a computer program product with program code means for the processing device. The configuration or the computer program product can be stored on a computer-readable data carrier. Features or advantages of the method can be transferred to the device (200), or vice versa.

[0024] The device (200) can manage log data from multiple systems on board the motor vehicle. In one embodiment, the actual encryption of log data can be performed by the on-board system that originally generated the log data. This allows different systems to support appropriate encryption for their log data. Furthermore, a system can handle different log data differently and may encrypt some of its log data and not others.

[0025] The device (200) can comprise a wired and a wireless communication device. Whether or how log data is encrypted can depend on which of the interfaces the log data is to be provided via. In one embodiment, requested log data is provided unencrypted on the wired communication device and encrypted on the wireless communication device. The wired communication device can be physically secured, for example by being located in a lockable interior of the motor vehicle. This allows an external location that already has physical access to the wired communication device to obtain and evaluate log data unencrypted. For example, a workshop or service center can thus obtain certain technical information on-site directly and without encryption.

[0026] The device (200) can comprise a secure memory for storing a private cryptographic key. The secure memory can, for example, comprise a hardware module similar to a TPM (trusted platform module), which is resistant to various attacks aimed at obtaining stored information. A certificate from a public authority, where public keys of participants in an asymmetric encryption method are stored, can also be stored in the secure memory. Furthermore, information can be stored here that indicates which external entities are trusted and which are not.

[0027] According to yet another aspect of the present invention, a motor vehicle comprises a device (200) described herein. The motor vehicle preferably comprises a passenger car or a motorcycle.

[0028] According to yet another aspect of the present invention, a system comprises a motor vehicle as described herein and a location external to the motor vehicle as described herein. The external location can function as a central collection point for log data from a plurality of motor vehicles. Collected log data can be correlated with each other and evaluated jointly. Alternatively, selected log data can be forwarded to another location for evaluation.

[0029] The invention will now be described in more detail with reference to the accompanying drawings, in which: Fig. 1 a system; Fig. 2 a motor vehicle; and Fig. 3 a flow chart of a procedure illustrated.

[0030] Fig. 1 shows a system 100 comprising a motor vehicle 105 and an external location 110. A first external location 110 is depicted in the form of a diagnostic device, which is preferably connected to the motor vehicle 105 via a wired communication device. A second external location 110 is depicted in the form of a central location, which communicates with the motor vehicle 105 via a wireless communication device.

[0031] Log data is generated on board motor vehicle 105, at least some of which may be sensitive or confidential. To verify, monitor, or analyze a technical function of motor vehicle 105 or one of its components, an external entity 110 may request log data created in connection with the function.

[0032] It is proposed that requested log data be encrypted on board the motor vehicle 105 before it leaves the vehicle. The external location 110 can decrypt received data and evaluate its technical functionality. Decrypted information that is no longer required can be discarded or overwritten by the external location 110.

[0033] The wirelessly connected, central external location 110 can collect encrypted log data from a motor vehicle 105. Preferably, received data is associated with identification data that points to the respective motor vehicle 105. Optionally, additional data associated with the motor vehicle 105 can be merged with the received log data.

[0034] Collected data can be transmitted from the external location 110 to a data storage 115 and stored there. The transmission is preferably also encrypted, as in Fig. 1 is symbolically indicated by the closed padlock. In one embodiment, the received log data is first decrypted by the external location 110 after receipt and then encrypted again using a different method or a different key before being transmitted to the data storage 115.

[0035] It is preferred that the log data be transmitted only in encrypted form between the external location 110 and the data storage 115. It is further preferred that the log data be stored in encrypted form in the data storage 115. Received data can be decrypted and re-encrypted with a different key or encryption method before being stored.

[0036] The data storage unit 115 can store a large number of log data from one or more motor vehicles 105. To evaluate a technical function of a motor vehicle 105, suitable log data can be determined and requested from the data storage unit 115. The log data can be generated on board one or more motor vehicles 105. The requested data can be provided in unencrypted form, for example, to an analyzer 120. Alternatively, the data can be transmitted in encrypted form to the analyzer 120 and decrypted there.

[0037] Fig. 2 shows a motor vehicle 105 with a device (200) 200 for managing log data. At least one system 205 is mounted on board the motor vehicle 105, which generates log data. In the illustration of Fig. 2 shows, by way of example, a first system 205 and a second system 210, each generating log data. Log data from the first system 205 may include confidential information, while log data from the second system 210 may consistently include non-confidential information. Multiple first and / or multiple second systems 205, 210 may also be provided.

[0038] The device (200) 200 comprises a processing device 215 connected to a wireless communication device 220 and a wired communication device 225. A plurality of first and / or a plurality of second communication devices 220, 225 may also be provided. One of the communication devices 220, 225 may also be omitted.

[0039] A secure memory 230 is configured to store information required for cryptographic processing of log data, authentication of an external entity 110, or authentication to an external entity 110. The secure memory 230 can, in particular, be formed as a hardware module.

[0040] The systems 205, 210 can create log data as part of the functions they perform. A storage for log data is provided in Fig. 2 not explicitly shown; in different embodiments, a central storage for log data may be used by multiple systems 205, 210 or a system 205, 210 may have a dedicated storage.

[0041] The device (200) 200 is configured to receive a request for the provision of log data from an external party 110 via a communication device 220, 225. The request is preferably signed and / or encrypted by the external party 110. If the authenticity of the external party 110 cannot be confirmed or if the external party 110 is not assigned access rights to the requested log data, the request can be rejected.

[0042] Requested log data may be obtained and encrypted onboard motor vehicle 105 before the log data is provided to external location 110. In one embodiment, log data of the first system 205 is encrypted, while log data of the second system is not encrypted. In another compatible embodiment, log data provided via wireless communication device 220 may be encrypted, while log data provided via wired communication device 225 may remain unencrypted.

[0043] An optional random source 235 is configured to provide random data. True randomness or pseudorandomness can be used for this purpose. In one embodiment, random data can be mixed into the log data before both are encrypted.

[0044] Fig.Figure 3 shows a flowchart of a method 300 for providing log data from a system 305, 310 on board a motor vehicle 105. In a step 305, an event can be determined for which log data is to be stored. The event is typically recorded by a system 305, 310, which preferably also determines the log data.

[0045] In a step 310, system data is collected. The system data can relate to the system 305, 310 or additionally to another system 305, 310. The determined system data can be stored in a step 315.

[0046] In a step 320, a request from an external entity 110 to provide log data can be recorded. The external entity 110 can authenticate itself upon the request. If the authenticity of the external entity 110 cannot be confirmed or the external entity 110 is not assigned access rights to the requested log data, the request can be rejected.

[0047] In a step 325, the requested log data can be captured. Stored log data can be retrieved from a memory. In a real-time application, provided log data can also be retrieved directly from a system 305, 310.

[0048] Optionally, random data can be generated in a step 330. Generated random data can be formatted as log data in a step 335 to create the impression of real log data without containing any usable information. Furthermore, in a step 340, random data can be mixed with the determined log data. The random data can be placed between data records that have at least one log data format.

[0049] In a step 345, the generated log data, including the random data, can be signed. In a step 350, the data can also be encrypted. Alternatively, the order of steps 345 and 350 can be reversed, i.e., the encryption can be performed before the signature. Encryption is preferably performed for the requesting external party 110, so that only the external party 110 that requested the log data can decrypt the encrypted log data. In a step 355, the encrypted log data can be provided. Typically, the log data is provided via the same communication device 220, 225 via which a corresponding request was received. Reference symbol 100 systems 105 Motor vehicle 110 external positions 115 data storage 120 Analyzer 200 Device (200) 205 first system 210 second system 215 Processing facility 220 wireless communication device 225 wired communication device 230 secured storage 235 Random source 300 procedures 305 Record event 310 Collect system data 315 Store log data 320 Request received 325 Collect log data 330 Generate random data 335 Random data as log data 340 Add random data 345 Sign log data 350 Encrypt log data 355 Provide log data

Claims

[1] Method (300) for providing log data of a system (305, 310) on board a motor vehicle (110), the method (300) comprising the following steps: - detecting (320) a request from a location (110) external to the motor vehicle (110) to provide the log data; - Encrypting (350) the log data; and - Providing (355) the encrypted log data. [2] The method (300) of claim 1, wherein the log data is confidential. [3] Method (300) according to claim 1 or 2, wherein the system (305, 310) controls a safety function on board the motor vehicle (110). [4] Method (300) according to one of the preceding claims, wherein the external entity (110) is authenticated (320) on the basis of an asymmetric authentication method. [5] Method (300) according to one of the preceding claims, wherein the log data are signed (345) on the basis of an asymmetric signature method. [6] Method (300) according to one of the preceding claims, wherein the encryption (350) is performed for the external location (110). [7] Method (300) according to claim 6, wherein a session key is negotiated with the external location (110) on the basis of an asymmetric encryption method; and the encryption (350) is carried out by means of a symmetric encryption method with respect to the session key. [8] Method (300) according to one of the preceding claims, wherein random data is added (335, 340) to the log data; and the log data and the random data are encrypted (350) and provided (355) together. [9] The method (300) of claim 8, wherein the system (305, 310) provides a stream of log data; wherein random data is mixed (335, 340) into the log data such that a predetermined data rate is maintained. [10] Device (200) on board a motor vehicle (110); the device (200) comprising: - a communication device (220, 225) for communication with a location (110) external to the motor vehicle (110); - an interface to a source (305, 310) of log data; - a processing device (215) configured to receive a request for providing log data from the external location (110); to encrypt log data from the source; and to provide the encrypted log data to the location (110). [11] The device (200) of claim 10, wherein a wired and a wireless communication device (220, 225) are provided; wherein requested log data is provided unencrypted on the wired communication device (225) and encrypted on the wireless communication device (220). [12] The device (200) of claim 10 or 11, further comprising a secure memory (230) for storing a private cryptographic key. [13] Motor vehicle (110) comprising a device (200) according to one of claims 10 to 12. [14] System (305, 310) comprising a motor vehicle (110) according to claim 13 and a location (110) external to the motor vehicle (110).

Citation Information

Patent Citations

  • Methods for data transmission and vehicle

    DE102010029929A1

  • Performing cryptographic operations in a vehicle's control unit

    DE102018130177A1

  • Securely providing diagnostic data from a vehicle to a remote server using a diagnostic tool

    US20160035148A1