CAN-Bus-System
Patent Information
- Application Number
- DE102024104159
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-02-14
- Publication Date
- 2025-09-11
- Estimated Expiration
- 2044-02-14
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a CAN bus system according to the preamble of claim 1.
[0002] Electronic attacks on vehicle CAN bus systems usually occur via their OBD interface or other sensitive and / or open CAN bus areas, man-in-middle attacks, changing data records and unlocking development levels via bootloader or JTAG.
[0003] The CAN bus in commercial vehicles (trucks) is not encrypted. If the CAN bus is encrypted, any control unit (e.g., a defective one) that falls into the wrong hands via a recycling cycle represents a potential security risk.
[0004] DE 10 2016 202 527 A1 describes a method for operating a computing unit for a motor vehicle, wherein the computing unit provides interfaces for accessing resources of the motor vehicle for a software application external to the vehicle, during a verification phase an authentication of the software application external to the vehicle is carried out and / or a functional scope of the software application external to the vehicle is determined, depending on the result of the verification phase carried out it is determined whether and to what extent the software application external to the vehicle may access the resources of the motor vehicle via the interfaces, and security functions that can be called by the software application external to the vehicle are provided in order to secure the execution of the software application external to the vehicle.
[0005] In addition, DE 10 2014 114 783 B4 shows an external device that functions as a watchdog and is connected to a monitoring controller of a CAN bus via a gateway, allowing faulty CAN connections or CAN controllers to be identified by analyzing error signatures.
[0006] Finally, DE 10 2018 128 183 A1 describes a method for updating a control unit in a vehicle, wherein, to check whether a control unit has been updated successfully, it is specified that a checksum of the updated software of the control unit is compared with a reference value and that a consistent control unit state is present.
[0007] The invention is based on the object of providing a novel CAN bus system.
[0008] The object is achieved according to the invention by a CAN bus system having the features of claim 1.
[0009] Advantageous embodiments of the invention are the subject of the subclaims.
[0010] A CAN bus system of a vehicle, in particular a commercial vehicle, is proposed, comprising a central gateway and a plurality of control units. According to the invention, a watchdog with a mirror memory is provided in the CAN bus system and connected to the central gateway. The watchdog is configured to store checksums of the control units and, upon an ignition change, to compare them with the checksums reported by the control units. The watchdog is configured to report a checksum that has changed since the last ignition change and the control unit in question as corrupted to the central gateway, which is configured to exclude the control unit in question from communication in the CAN bus system. According to the invention, the watchdog is configured to be enabled for write access via an OBD connection by a remote station during a diagnostic session using two-factor authentication.
[0011] In one embodiment, the watchdog is configured to accept the checksums after a diagnostic session is completed.
[0012] In one embodiment, the watchdog is configured to transfer the checksums to the mirror memory after two or three error-free vehicle cycles.
[0013] In one embodiment, the watchdog is configured to store the last two user IDs in the mirror memory.
[0014] In one embodiment, a CAN slave is arranged in one or more control units or their connectors, which is configured to cut off the control unit in question from the CAN bus in the event of an incorrect checksum or changed, conspicuous behavior.
[0015] In one embodiment, the CAN slave is configured to detect an individual voltage loss at the relevant control unit as a changed, conspicuous behavior.
[0016] The inventive solution provides protection against manipulation that is relatively difficult to overcome, can be implemented cost-effectively on the hardware side, and allows integration into vehicles. Retrofitting existing vehicles is also possible. Due to the low hardware specifications, the watchdog could operate at voltages down to 5V. The watchdog is also very small and could be installed in hard-to-reach locations to prevent potential attacks on the watchdog itself. Likewise, the Bluetooth® signal could operate covertly to further secure the already highly secure Bluetooth® standard 5.2 or 5.3. UN ECE R155 applies to all new developments from 2022 and new registrations from 2024. This provides an additional firewall in the vehicles.
[0017] Embodiments of the invention are explained in more detail below with reference to a drawing.
[0018] It shows: Fig. 1 a schematic view of a vehicle's CAN bus system.
[0019] The only Fig. 1 is a schematic view of a CAN bus system 1 of a vehicle, in particular a commercial vehicle, a bus or a passenger car, with a central gateway 3 (CGW), an OBD interface 4 and a plurality of control units located in an area 5 to be protected against manipulation and / or electronic attacks.
[0020] A watchdog 2 is connected to the CAN bus system 1, in particular to the central gateway 3 or to an interface between the OBD interface 4 and the central gateway 3.
[0021] Watchdog 2 can be implemented as a control unit and physically located on CAN bus cables, integrated at the hardware level in the central gateway 3, or integrated into a control unit as a virtual control unit (i.e., purely as software, if the hardware level allows it). (This should be considered when designing the control units, as additional hardware may be required. However, the CAN interface could be used to reduce production costs.) Watchdog 2 features a CAN monitor configured to check and / or compare the following, depending on the intended complexity and / or the intended cost and / or the intended use of resources: - 1: The checksum of all software and / or hardware part numbers, software version numbers, CVN (Calibration Verification Number), data set, mileage, operating hours, etc. of the vehicle (deviations would arise from unauthorized version changes, such as flashing (overwriting) with an unauthorized data set). This would also detect an (offline) replacement or removal and / or installation of a control unit (for example, removal and tampering outside the vehicle network and / or topography) during the first ignition run. This can be done by actively monitoring information collected or selected from a log file (for example, all messages and responses from control units, calculating a checksum, comparing, or with each short test request via diagnostics or telemetry online short test) and comparing it with the last data set stored in Watchdog 2. - 2: all parameters as binary, hexadecimal or decimal keys (SCN coding) which are legitimate for the respective vehicle (online comparison during each workshop visit via a vehicle documentation system, whereby illegal, offline coding which was used as a numerical key contrary to the individual coding valid for this vehicle can be compared. - 3: The entire CAN communication (especially purely read-only). This allows authorized authorities, such as TÜV, DEKRA, BAG, police, etc., to use their own readout adapters. In the case of a request frame (Arbitration Field CAN message), the CAN connection can be immediately short-circuited or grounded to prevent manipulation. Legitimate requests would only work if Watchdog 2 is inactive (special case: Watchdog 2 is put to sleep) (workshop mode).
[0022] As already mentioned, the Watchdog 2 can be configured as a standalone control unit (including a housing and a connector), integrated into another control unit as a virtual control unit, or implemented as pure software. Essentially, the Watchdog 2 is a mirror memory or has a mirror memory that stores and / or updates one or more of the above-mentioned information with each legitimate access and / or change. This information is compared with each ignition change and / or each short test request and / or cyclically via the CAN bus. A dedicated operating system (software) or a system-on-a-chip (SOC) can be used for this purpose. The Watchdog 2 is configured to listen to all messages on the CAN bus and process information.
[0023] Watchdog 2 does not appear in the short test as a separate control unit, or only appears via special functions (to prevent a possible attack). It can be located in a hard-to-reach location, for example, behind another control unit or a panel, for example, with a shear screw on a housing and / or connector, to provide physical protection against attacks and access. Watchdog 2 can be installed in its own housing. Furthermore, Watchdog 2 can have a molded circuit board.
[0024] In the event of legitimate (i.e., legal and / or intentional) programming and / or value changes in one of the control units, Watchdog 2 must also be updated so that it recognizes and accepts the new legitimate software, parameters, etc. To do this, Watchdog 2 can be put into workshop mode (or sleep mode with active defense). This can be done (since it is CAN-based) via OBD interface 4 to ensure speed for the user. To counteract this attack, protection can be provided according to one of the following options: - A: Securing a non-publicly visible, encrypted Bluetooth connection, which becomes active when a legitimate tester is connected, to a general end device (e.g. a smartphone) or, with stronger security, to a special end device (e.g. a special workshop tool, in particular a Bluetooth dongle with a hardware key on a USB port of the tester, or a special diagnostic cable with a Bluetooth chip, the power supply of which can come from the OBD interface 4, or to a similar end device with its own power supply or one provided by the vehicle (depending on the level of security also as an inductive and / or capacitive signal), whereby the Watchdog 2 can be put into a workshop mode or programming mode by means of a handshake (roll-on codes or SEED key procedure), which allows an automatic or manual update of the mirror memory at the end of the diagnostic session. - B: In addition to A (or, with lower security, also possible instead of A), a second factor would also be possible, which would require a networked diagnostic device and / or online diagnostic device. After a personalized login in the diagnostic device, an authorization request and / or PIN request could be sent to an app on a mobile device (e.g., a smartphone), which would have to be actively confirmed by the user. In this case, an access time and user identity could be stored online. - C: The stored information can also be encrypted using hardware and / or software to increase security and prevent possible extraction from the Watchdog 2 (during removal and opening). This could be done using an algorithm or a security chip (hardware encryption), or via blockchain. The blockchain would make the coding history available offline on the vehicle.
[0025] Watchdog 2 is configured to establish a second, difficult-to-overcome security barrier in the vehicle's environment via Bluetooth®, for example, Bluetooth® standard 5.2 or 5.3. Watchdog 2 still permits the mere reading of data or the deletion of error logs, as this is legally required for authorities, TÜV (German Technical Inspection Association), emission control devices, free diagnostic devices, etc. Watchdog 2 can prohibit writing to the central gateway 3 (prevent the routing of CAN messages), abort diagnostic sessions, or ground the CAN bus, which leads to a communication interruption. Watchdog 2 knows all valid checksums of relevant control units (i.e., all control units to be protected, especially those specified in UN ECE R155).This can be divided according to CAN buses (driveline and chassis CAN) or according to control units (engine, transmission, ESP and / or brakes, central gateway 3, immobilizer, instrument cluster).) and compares these with the checksums provided by the control units when the ignition is changed (the ignition is switched on after it was previously off). For example, watchdog 2 has a mirror memory in which the checksums are stored. If a checksum has changed since the last ignition change (e.g. due to a hardware attack via a bootloader, JTAG, etc.), watchdog 2 reports this event to central gateway 3, and the control unit with the changed checksum is declared corrupted by central gateway 3 and excluded from communication in CAN bus system 1.
[0026] The Watchdog 2 can be configured to communicate via Bluetooth® with a suitable counterpart (for example, a USB Bluetooth® dongle in a diagnostic device, a Bluetooth® chip in an OBD cable that is powered by a multiplexer or the vehicle) and to be activated via a quasi two-factor authentication so that the Watchdog 2 allows write access via the OBD connection, for example, when the vehicle is in a workshop for parameterization, programming or similar.
[0027] This would allow ECU-sensitive parameterizations to continue as usual (e.g., XMC parameterization, MCM, etc.). Watchdog 2 can be configured to transfer the modified checksums to the mirror memory after the end of the diagnostic session and / or after two or three error-free driving cycles. Should an incorrect parameterization occur, the new checksums can be transferred to the mirror memory only after two or three error-free driving cycles. In the event of incorrect flashing or coding, this would prevent Watchdog 2 from being activated, which could potentially lead to a system that can no longer be flashed or coded, as Watchdog 2 could no longer be deactivated and / or addressed, permanently crippling the system.
[0028] Furthermore, it can be planned to store identity numbers (IDs) of the last two users and / or workshops in the mirror memory in order to identify and centrally deactivate potential insiders or theft of dongle IDs. The identity numbers are assigned, for example, by the vehicle manufacturer for each employee and for workshops, along with a password and an app for unlocking specific applications. During a flash in the workshop, each worker must log in to the diagnostic device. The Watchdog 2 can receive a signal via Bluetooth® (unhackable parallel connection to the Watchdog 2). This is difficult to emulate or scan because it is hidden, providing additional security. A dongle ID can be, for example, a USB hardware key (e.g., including a chip). Identification can also be biometric, using a fingerprint or other biometric method on a smartphone.), which is only issued to workshops and on which a unique key (for example a 256-bit key) is stored, with which an individual fingerprint is compared via a manufacturer's server and would be difficult or impossible to copy at the hardware level. An insider would have to steal the user identification number and password and, if necessary, the means of possible two-factor authentication (for example a smartphone with an app and a password) and / or the hardware dongle in order to encrypt it, which makes an insider job more difficult, as every access and every use would be traceable and the insider would therefore be identifiable. Should such access nevertheless occur, the corresponding identification numbers (of a person, an app and / or a hardware dongle) can be blocked and / or deleted centrally on the manufacturer's server, making them unusable.
[0029] In one embodiment of the invention, CAN slaves can be arranged in critical control units (or in their connectors). These slaves are configured to natively disconnect the respective control units from the CAN bus in the event of an incorrect checksum or a change in behavior, such as an individual voltage loss. A critical control unit is, for example, a control unit that is essential for the operation of the vehicle (engine control units, brakes, etc.). For example, the CAN slave can limit the number of engine starts via software or shut down the vehicle.For other control units, such as a radio (e.g., when TV is enabled while driving), if the test buzzer is incorrect, the central gateway 3 can exclude the control unit from communication, or a power supply output for the affected control unit in a central electrical system can be shut off, thus removing the power supply to the affected control unit and preventing all communication from the corrupted control unit on the CAN bus. Watchdog 2 can be integrated into a control unit with a CAN slave, such as the radio or a tachograph.
[0030] Since a Bluetooth® key could be copied and reverse-calculated by an "inside job," and a seed key can also be cracked, each vehicle can have its own blockchain as its key, which increments once each time it is accessed. This could also make it easier to defend against or trace offline attacks (removal of control units, JTAG attacks, simulated Bluetooth connections, or a fake Wi-Fi network posing as the manufacturer's server). The participants in the blockchain, in which a distributed register is stored, can be the watchdog 2, the manufacturer's server, and the central gateway 3. Any legitimate access can influence the blockchain, in addition to the user, the parameters, and / or a flash version.Unauthorized but detected access (for complete monitoring, see point 3 above) and / or offline coding could be detected using the blockchain, which would further increase the security of Watchdog 2.
[0031] The present invention can be used on all vehicles with a CAN bus (in particular with a central gateway 3 (CGW)). In response to manipulation and / or an attack, a "silent alarm" (vehicle stores an error code, which is recognized during the next workshop visit), an electrical reaction (watchdog 2 and / or central gateway 3 paralyze the CAN bus or individual systems or control units, for example, by pulling the CAN bus to a ground potential via a transistor), an acoustic and / or visual alarm via a CAN message, a warning message in an instrument cluster and / or via a wireless system (e.g., GPS and 4G), and / or a power limitation (inducement) can be provided. A combination of several of these reactions or further reactions would also be conceivable, up to and including activation of the immobilizer.
[0032] The Watchdog 2 can be used during vehicle manufacturing or as a retrofit solution for a vehicle. List of reference symbols 1 CAN bus system 2 Watchdog 3 central gateway 4 OBD interface 5 Area
Claims
[1] CAN bus system (1) of a vehicle, in particular a commercial vehicle, with a central gateway (3) and a plurality of control units, wherein a watchdog (2) with a mirror memory is connected to the central gateway (3), which is configured to store checksums of the control units and, in the event of an ignition change, to compare them with the checksums reported by the control units, and to report a checksum changed since the last ignition change and the control unit in question as corrupted to the central gateway (3), which is configured to exclude the control unit in question from communication in the CAN bus system (1), characterized by that the watchdog (2) is configured to be enabled for write access via an OBD connection in a diagnostic session by a remote station via two-factor authentication. [2] CAN bus system (1) according to claim 1, characterized bythat the watchdog (2) is configured to transfer the checksums to the mirror memory after the end of a diagnostic session. [3] CAN bus system (1) according to claim 1 or 2, characterized by that the watchdog (2) is configured to transfer the checksums to the mirror memory after two or three error-free vehicle cycles. [4] CAN bus system (1) according to one of the preceding claims, characterized by that the watchdog (2) is configured to store the last two user IDs in the mirror memory. [5] CAN bus system (1) according to one of the preceding claims, characterized by that a CAN slave is arranged in one or more control units or their connectors, which is configured to cut off the control unit in question from the CAN bus in the event of an incorrect checksum or changed, conspicuous behavior. [6] CAN bus system (1) according to one of the preceding claims, characterized bythat the CAN slave is configured to detect an individual voltage loss at the relevant control unit as a changed, conspicuous behavior.
Citation Information
Patent Citations
METHOD FOR MONITORING A CONTROLLER AREA NETWORK
DE102014114783B4
Electronic control unit for a motor vehicle
DE102016202527A1
Control unit for a vehicle component, kit comprising a control unit and a test device, vehicle, method for updating a control unit and computer-readable storage medium
DE102018128183A1