Procedures for responding to tampering with the vehicle in order to reduce risks to the target vehicle and the fleet as a whole.
The method addresses vehicle tampering risks by implementing real-time anomaly detection and response strategies, ensuring safe and efficient operation of both individual and fleet vehicles by minimizing tampering effects.
Patent Information
- Application Number
- DE102024115449
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-04
- Publication Date
- 2025-12-04
AI Technical Summary
Modern vehicles face significant risks due to tampering, which can lead to costly recalls and prolonged vulnerabilities, especially in automated or autonomous fleets, necessitating immediate and cost-effective countermeasures to ensure safe operation.
A method involving real-time monitoring and detection of communication and vehicle function anomalies, followed by immediate and targeted responses, such as message blocking, application shutdowns, and interface deactivation, to mitigate tampering effects across affected and non-affected vehicles within a fleet.
Enables safe, reliable, and cost-effective operation of individual vehicles and entire fleets by minimizing damage from tampering through rapid, localized countermeasures, enhancing safety and reducing downtime.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for operating a vehicle, e.g., a fleet vehicle, such as an automated or autonomous vehicle, in a particularly safe manner, which has, e.g., internal and / or external communication and various vehicle functions. Furthermore, the invention relates to a corresponding computer program, a corresponding control unit, a corresponding vehicle, and a corresponding backend device for carrying out the corresponding method.
[0002] Modern vehicles increasingly use wireless communication via a network to provide various vehicle functions. Several systems exist for analyzing and detecting vehicle tampering. If tampering is detected, the affected vehicles are recalled to the workshop for repair, which is a very costly measure. Alternatively, the security vulnerabilities are closed via an update (for example, over-the-air), which often takes a very long time (preparation, development, homologation, etc.). In the meantime, the vehicles affected by the tampering, as well as the entire fleet, are at risk. In the worst-case scenario, several vehicles have to be taken out of service.
[0003] It is therefore an object of the present invention to overcome at least one of the disadvantages described above, at least partially. In particular, it is an object of the invention to provide an improved method for the safe operation of a vehicle, for example, a fleet vehicle, preferably an automated or autonomous vehicle, which has communication capabilities, particularly internal and / or external ones, and various vehicle functions, which preferably provides short-term countermeasures for both affected vehicles and the entire vehicle fleet, preferably at low cost, and which enables safe, reliable, and / or convenient operation of the vehicle and the entire vehicle fleet.Furthermore, it is an object of the invention to provide a corresponding computer program product, a corresponding control unit and a corresponding vehicle and a corresponding backend device for carrying out a corresponding method.
[0004] The preceding problem is solved by: A method comprising the features of the independent method claim, as well as a corresponding computer program product, a corresponding control unit, a corresponding vehicle, and a corresponding backend device for carrying out a corresponding method comprising the features of the dependent claims. Further features and details of the invention will become apparent from the dependent claims, the description, and the drawings. Features and details described in connection with the method according to the invention naturally also apply in connection with the computer program product according to the invention and / or in connection with the control unit according to the invention and / or in connection with the vehicle according to the invention, and vice versa, so that the disclosure of the individual aspects of the invention always includes, or allows for, reciprocal reference.
[0005] The invention provides for: A method for operating a vehicle, in particular a safe manner, e.g. a fleet vehicle, such as an automated or autonomous vehicle, which has communication capabilities, in particular internal and / or external communication capabilities, and various vehicle functions that can be provided, for example, by means of communication, comprising: - Monitoring communication and / or vehicle functions for manipulation (or attacks), e.g., anomalies, irregularities, manipulated data and / or messages, - Detection of manipulation depending on monitoring (detection can preferably be carried out in the vehicle; in principle, it is conceivable that detection can be carried out outside the vehicle, e.g. in another vehicle and / or in a backend device), - Initiating (or starting, triggering, instigating, etc.) at least one reaction in the event of detected manipulation, in order to reduce the potential for damage when operating the vehicle and / or at least one other vehicle, which may belong to a vehicle fleet, e.g., the same vehicle fleet as the (own) vehicle.
[0006] Communication can include internal communication and / or external communication.
[0007] Vehicle functions can include, for example, those vehicle functions that provide for the activation / deactivation / non-activation of actuators / sensors / control units / devices in the vehicle.
[0008] Vehicle functions can include, for example, those vehicle functions that provide for actions when operating actuators / sensors / control units / devices.
[0009] In this way, at least one or more responses can be provided in a vehicle, preferably in several vehicles (e.g., within a relevant radius), or even in every vehicle in a fleet. In the event of detected tampering, at least one or more responses are initiated to reduce the potential for damage. Initiating a response (multiple responses triggered simultaneously are also possible) can occur both internally within the vehicle (i.e., directly in the affected vehicle) and externally (i.e., remotely, e.g., from a central backend system). If the response(s) are triggered from a central system, this can be done manually (e.g., by an analysis team) or automatically.
[0010] Using this method, reactions can be triggered in the affected vehicle in the event of a detected attack, in order to minimize the damage.
[0011] Using this method, if an attack is detected, reactions can be triggered in several other vehicles to close the potential vulnerability and prevent future attacks. For example, if one vehicle is hacked via Bluetooth, the Bluetooth interface can then be blocked in other vehicles in the fleet.
[0012] Using this method, preferably short-term countermeasures can be provided for both affected vehicles and the entire vehicle fleet, preferably at low cost, and enable safe, reliable and / or comfortable operation of the vehicle and the entire vehicle fleet.
[0013] Furthermore, the at least one response may include at least one of the following measures: 1.1. Non-forwarding of messages, especially manipulated messages, preferably defined (or already identified as manipulated).
[0014] Advantageously, this measure can prevent the manipulated messages from being forwarded.
[0015] The decision as to whether a message is not forwarded can be made based on the following criteria, for example: - News content, - Protocol characteristics (such as message identifiers, IP addresses, MAC addresses, ports), etc., and / or - other characteristics (such as an unusual frequency of receiving messages).
[0016] This measure can preferably be implemented directly at a communication interface with the outside world (using a so-called gateway control unit). If the manipulated messages are detected later, this measure can be implemented at a specific control unit within the vehicle that detects the manipulated messages. Advantageously, this measure can further stipulate that the data of the manipulated messages is replaced with previous data, default data, standard values, or similar. Detection can generally take place at various locations inside and / or outside the vehicle. Advantageously, at least one reaction can be triggered (preferably immediately) after detection.
[0017] Example of an incident: As part of an attack path, an attacker was able to manipulate certain messages forwarded by the gateway control unit to cause further damage. This measure can ensure that certain messages are not forwarded to prevent further damage.
[0018] Furthermore, at least one of the following measures may be taken: 1.2. Blocking of incoming messages, especially manipulated, preferably defined (or already identified as manipulated).
[0019] Advantageously, this measure can lead to attacked control units securely blocking defined incoming messages.
[0020] Example of an incident: As part of an attack path, an attacker was able to take over certain functions of a specific control unit, send erroneous messages, and / or flood an internal network / bus. This measure can ensure that unauthorized control commands are not executed, that erroneous messages are not received, and / or that the internal network / bus is relieved of congestion.
[0021] Furthermore, the at least one response may include at least one of the following measures: 1.3. Shutdown of applications, especially those affected.
[0022] Advantageously, this measure can lead to the attacked control units terminating specific processes.
[0023] Example of an incident: As part of an attack path, an attacker was able to take over and / or exploit certain applications. Running these applications could cause further damage. This measure can ensure that certain applications are not executed to prevent further damage.
[0024] Furthermore, the at least one response may include at least one of the following measures: 1.4. Shutdown of containers, especially those affected.
[0025] This reaction can lead to the shutdown of containers such as NorthStar, Docker, etc.
[0026] Example of an incident: As part of an attack path, an attacker was able to hijack and / or exploit certain applications of containers. Running these applications could cause further damage. This measure can ensure that certain applications are not executed to prevent further damage.
[0027] Furthermore, at least one of the following measures may be taken: 1.5. Creating driver warnings.
[0028] This measure can advantageously result in driver warnings being displayed in the relevant HMI. These driver warnings can be triggered from the backend and displayed in the target vehicle and / or across the entire fleet.
[0029] Example of an incident: A tampering has been detected that cannot be addressed with other measures (e.g., for safety reasons), and / or requires an ongoing response that prohibits the driver from continuing their journey. This measure can ensure that the driver is warned.
[0030] Furthermore, the at least one response may include at least one of the following measures: 1.6. Deactivating data extraction, especially unauthorized data extraction.
[0031] This reaction can disable the uploading of data, e.g. for certain applications and / or services, via communication links.
[0032] Example of an incident: An attacker uses online services to, for example, extract personal data. This measure can ensure that personal data is not extracted without authorization.
[0033] Furthermore, the at least one response may include at least one of the following measures: 1.7. Deactivating hardware ports, especially those that are affected.
[0034] This response can be used to disable hardware ports, such as USB ports, etc., that have been affected by tampering.
[0035] Example of an incident: USB ports are used by an attacker in their attack path (e.g., KIA USB hack) and / or to mitigate the extraction of personal data. In this way, affected hardware ports can be blocked, which represent a security vulnerability for manipulation.
[0036] Furthermore, at least one of the following measures may be taken: 1.8. Blocking of, in particular defined, e.g. internal and / or external, IP addresses.
[0037] This response may disable routing and / or network visibility for specific IP addresses or IP address ranges.
[0038] Example of an incident: The vehicle currently has a large number of different IP addresses, some of which belong to unconfigured applications / services. If these are targeted by an attacker, communication with these addresses can be disabled.
[0039] Furthermore, the at least one response may include at least one of the following measures: 1.9. Deactivation, especially of affected interfaces
[0040] This reaction can disable interfaces such as WLAN, Bluetooth, BT, keyless access, digital key, etc.
[0041] Example of an incident: The WLAN interface is used by an attacker on their attack path. This interface can then be deactivated for security reasons in the affected vehicle or in the entire vehicle fleet.
[0042] Furthermore, at least one response may include at least one of the following measures: 1.10 Disabling an Internet and / or network connection for specific applications
[0043] This response can, for example, disconnect and / or interrupt the network connection for certain applications to prevent attacks by, among other things, online services.
[0044] Furthermore, it can be stipulated that initiating at least one reaction only occurs under certain vehicle conditions, for example, when the vehicle is stopped, stationary, or traveling below a certain speed threshold, e.g., 3 km / h. This ensures safe operation of the vehicle, which might not be possible at high speeds.
[0045] Advantageously, at least one reaction can be configured to execute only specific reactions, particularly those that have been checked for safety. This ensures that only verified reactions are used.
[0046] Furthermore, it can be provided that at least one reaction is configured in such a way that only defined, and in particular permitted, vehicle functions, targets, messages, applications, etc., are affected. In this way, only permitted vehicle functions, targets, messages, applications, etc., can be influenced.
[0047] For safety reasons, vehicle states can be defined, e.g., above a certain speed threshold, such as 3 km / h, in which initiating at least one reaction is prevented. This prevents unexpected interventions in the vehicle's operation at high speeds.
[0048] Advantageously, the duration of at least one reaction can be determined either on the vehicle side, e.g., by a vehicle control unit, or externally, e.g., by a backend control unit. In this way, reactions, such as safety measures, can be initiated only for a specific period of time to avoid continuously affecting vehicle operation.
[0049] As a safety precaution, it can be provided that the execution of at least one reaction can be aborted either on the vehicle side, e.g., by a vehicle control unit, or externally, e.g., by a backend control unit. In this way, any continuous interference with vehicle operation can be interrupted.
[0050] Furthermore, it can be stipulated that at least one of the following actions is carried out upon detection of manipulation: - Judging a detected manipulation as an unjustified attack, - Assessing a detected manipulation as an event and / or as a possible attack and conducting additional analysis, in particular to determine whether the event is an unauthorized attack, what type of attack the event is and / or how many vehicles are affected, e.g. whether only a few vehicles or the entire fleet is affected.
[0051] This allows for the creation of gradations between clearly and / or recognizably unauthorized attacks and potentially unauthorized attacks, with the latter not immediately triggering countermeasures and allowing for initial review. At the same time, this ensures that potentially unauthorized attacks are not overlooked and are investigated.
[0052] Furthermore, the procedure may include at least one of the following actions, which are carried out in particular on the vehicle side, e.g. by a control unit of the vehicle: - Evaluating at least one response with regard to the safe operation of the vehicle or its suitability to reduce the potential for damage when operating the vehicle and / or at least one other vehicle, and / or - Providing feedback on at least one response from the vehicle to an external backend device, to at least one other vehicle and / or to a user of the vehicle, indicating whether the at least one response was successful, in order to reduce the potential for damage when operating the vehicle and / or at least one other vehicle.
[0053] Providing feedback to an external backend system enables documentation, further analysis, and the development of new responses. Providing feedback to at least one other vehicle allows for the initiation of beneficial responses on another vehicle, even proactively. Providing feedback to the vehicle's user enhances clarity and increases user confidence.
[0054] Firstly, it is conceivable that if at least one reaction was successful, at least one action will be carried out: - Assessing the operation of the vehicle as safe.
[0055] On the other hand, it is conceivable that if at least one reaction has been unsuccessful, at least one of the following actions will be carried out: - Repeat at least one reaction, - Providing other known responses, - Conducting an additional analysis, - Developing new reactions, - Stopping the vehicle, performing an update and / or visiting a repair shop, or accepting the risk of operating the vehicle.
[0056] In this way, the safety during vehicle operation can be increased even further.
[0057] Furthermore, the process can include at least one of the following actions, which are performed particularly externally to the vehicle, e.g. by a control unit of a backend device: - Analyzing feedback about at least one response from the vehicle to an external backend device, - Creating a database of successful responses to different manipulations.
[0058] In this way, documentation, further analysis, and the development of new responses can be made possible.
[0059] It is conceivable that if at least one reaction has been unsuccessful, at least one of the following actions will be carried out: - Initiating a repeat of at least one response if the at least one response was unsuccessful, in order to reduce the potential for damage to the vehicle and / or at least one other vehicle, - Triggering other known reactions, - Conducting an additional analysis, - Developing new reactions, - Initiating a recall of the vehicle and / or the vehicle fleet or accepting the risk in the operation of the vehicle and / or the vehicle fleet if at least one of the responses has been unsuccessful.
[0060] In this way, the safety during vehicle operation can be increased even further.
[0061] In principle, it is conceivable that the initiation of at least one reaction in the (own) vehicle is triggered either on the vehicle side, e.g. by a control unit of the vehicle, or externally on the vehicle, e.g. by a control unit of a backend device.
[0062] Additionally or alternatively, it is conceivable that the initiation of at least one reaction in the (own) vehicle is carried out automatically and / or manually by a control unit of a backend device, e.g. by an analysis team.
[0063] Advantageously, it is conceivable that initiating the at least one reaction when operating at least one other vehicle in a vehicle fleet is carried out using the vehicle, in particular by providing direct feedback about the at least one reaction from the vehicle to the at least one other vehicle, e.g. through V2V communication.
[0064] The above problem is further solved by: A computer program product comprising instructions which, when executed by a computer, cause the computer to perform the method, which can proceed as described above. The same advantages can be achieved as described above in connection with the method according to the invention.
[0065] The above task will continue to be solved by: A control unit comprising a processing unit and a storage unit in which instructions are stored which, when at least partially executed by the processing unit, carry out a process that can proceed as described above. The control unit can be provided as a central control unit of the vehicle. The same advantages can be achieved that have been described above in connection with the method according to the invention.
[0066] The above problem is further solved by: A vehicle, preferably an automated or autonomous vehicle, with a corresponding control unit. The vehicle can form part of a vehicle fleet. The same advantages can be achieved as described above in connection with the method according to the invention.
[0067] The above task will continue to be solved by: A control unit comprising a processing unit and a storage unit in which instructions are stored which, when at least partially executed by the processing unit, perform a process that can proceed as described above. The control unit can be provided in an external backend device. The same advantages described above in connection with the method according to the invention can be achieved in this case.
[0068] The above problem is further solved by: A back-end device with a corresponding control unit. The same advantages can be achieved as described above in connection with the method according to the invention.
[0069] Further advantages and features of the invention will become apparent from the following description, in which several embodiments of the invention are described in detail with reference to the drawings. The drawings schematically illustrate: Fig. 1. An exemplary sequence of a proposed procedure, Fig. 2 further possible procedural steps, Fig. 3 further possible procedural steps, and Fig. 4 further possible procedural steps.
[0070] In the following figures, identical reference numerals are used for the same technical features, even for different embodiments.
[0071] The Fig. References 1 to 4 serve to describe a method in accordance with the invention, which was developed for the, in particular safe, operation of a vehicle 100.
[0072] The vehicle 100 within the meaning of the invention can be a fleet vehicle and form part of a vehicle fleet.
[0073] Consequently, the procedure can be used comprehensively for the operation of a vehicle fleet, particularly for its safety.
[0074] The vehicle 100 within the meaning of the invention can, for example, be an automated or autonomously driving vehicle.
[0075] The vehicle 100 according to the invention can have internal communication K1, e.g., via a bus system, and / or external communication K2, the latter being wireless and implemented using various technologies such as the internet, mobile communications, WLAN, etc. Information, data, and control commands can be transmitted via internal communication K1. Data can be sent to and / or received from outside the vehicle 100 via external communication K2. For example, the vehicle 100 can exchange sensor data, traffic jam information, evaluated traffic signs, etc., with other vehicles. Furthermore, the vehicle 100 can subscribe to and receive certain topics from external providers. Finally, the vehicle 100 can communicate with user-side devices, e.g., for access control purposes.
[0076] The vehicle 100 according to the invention can furthermore have different vehicle functions F1, F2, which in turn can be provided by means of internal and / or external communication K1, K2.
[0077] The vehicle functions F1, F2 can, for example, include such vehicle functions F1 that provide for the activation / deactivation / non-activation of actuators / sensors / control units / devices in the vehicle 100.
[0078] The vehicle functions F1, F2 can, for example, include vehicle functions F2 that provide actions when operating actuators / sensors / control units / devices.
[0079] As it is Fig. As shown in Figure 1, the procedure has the following steps: 110 Monitoring of communication K1, K2 and / or vehicle functions F1, F2 for manipulations Mi (or attacks), e.g., for anomalies, irregularities, manipulated data and / or messages, 120 Detecting manipulation Mi depending on the monitoring, if, for example, anomalies, irregularities (e.g., a message is sent more often than usual), manipulated data and / or messages have been detected, 130 Initiating (or starting, triggering, instigating, etc.) at least one reaction Rn in the event of detected manipulation Mi, in order to reduce the potential for damage when operating the vehicle 100 and / or at least one other vehicle 101.
[0080] Using this method, at least one or more responses Rn can be provided in the vehicle 100, preferably in several or even in every vehicle 100, 101 of a vehicle fleet. In the event of a detected manipulation Mi, at least one or more responses Rn are initiated (immediately, without the need to wait for an update or repair the vehicle) to reduce the potential for damage.
[0081] In principle, it is conceivable that the initiation of at least one reaction Rn in the vehicle 100 is initiated either on the vehicle side, e.g. by a control unit ECU of the vehicle 100, or externally on the vehicle, e.g. by a control unit ECU of a backend device 200.
[0082] Additionally or alternatively, it is conceivable that the initiation of at least one reaction Rn in the company's own vehicle 100 and / or in at least one other vehicle 101 of the fleet is carried out automatically and / or manually, e.g., by an analysis team, by a control unit ECU of a backend device 200. If at least one or more reactions Rn are triggered from a (central) backend device 200, this can be done both manually (e.g., by an analysis team) and automatically.
[0083] Advantageously, it is conceivable that the initiation of the at least one reaction Rn when operating at least one other vehicle 101 of a vehicle fleet is carried out using the (own) vehicle 100, in particular by providing direct feedback about the at least one reaction Rn from the own vehicle 100 to the at least one other vehicle 101, e.g. by V2V communication.
[0084] Using this method, in the event of detected manipulation Mi in the affected vehicle, 100, 101 reactions Rn can be triggered to minimize or even avoid the damage.
[0085] Using this method, in the event of detected manipulation Mi (on the user's own vehicle 100), reactions Rn can be triggered in at least one or several other vehicles 101 (which, for example, are not (yet) affected) to close the potential security gap and effectively or even proactively prevent manipulation Mi. For example, if a vehicle 100 is hacked via Bluetooth, the Bluetooth interface can then be blocked in other fleet vehicles. Similarly, if an access system (keyword "man-in-the-middle attack") to a vehicle 100 is hacked, keyless access, for example via proximity sensors and / or wireless ID verification, can be blocked (preferably proactively) in other nearby vehicles 100.
[0086] Using this method, countermeasures, preferably short-term, can be provided at low cost for both affected vehicles 100 and 101, as well as for the entire vehicle fleet. This will ensure the safe, reliable, and / or convenient operation of vehicle 100 and the entire vehicle fleet.
[0087] The at least one reaction Rn can, for example, include the following measure: 1.1. Non-forwarding of messages, especially manipulated messages, preferably defined (or already identified as manipulated).
[0088] This measure can prevent the manipulated messages from being forwarded. This measure can preferably be implemented at a communication interface with the outside world, for example, using a so-called gateway control unit. Should the manipulated messages only be detected later, this measure can be implemented at the respective control unit (CPU) of the vehicle 100 that detects the manipulated messages. This measure can further stipulate that the data of the manipulated messages is replaced by previous data, such as default data, standard values, or similar.
[0089] Example of an incident: As part of an attack path, an attacker was able to manipulate certain messages forwarded by the gateway control unit to cause further damage. This measure can ensure that certain messages are not forwarded to prevent further damage.
[0090] The at least one reaction Rn can, for example, include the following measure: 1.2. Blocking of incoming messages, especially manipulated, preferably defined (or already identified as manipulated).
[0091] This measure can ensure that attacked control units securely block defined incoming messages.
[0092] Example of an incident: As part of an attack path, an attacker was able to take over certain functions of a specific control unit, send erroneous messages, and / or flood an internal network / bus. This measure can ensure that erroneous messages are not received, that unauthorized control commands are not executed, and / or that the internal network / bus is relieved of congestion.
[0093] The at least one reaction Rn can, for example, include the following measure: 1.3. Shutdown of applications, especially those affected.
[0094] This measure can lead to the attacked control units being able to selectively terminate processes.
[0095] Example of an incident: As part of an attack path, an attacker was able to take over and / or exploit certain applications. Running these applications could cause further damage. This measure can ensure that certain applications are not executed to prevent further damage.
[0096] The at least one reaction Rn can, for example, include the following measure: 1.4. Shutdown of containers, especially those affected.
[0097] This reaction can lead to the shutdown of containers such as NorthStar, Docker, etc.
[0098] Example of an incident: As part of an attack path, an attacker was able to hijack and / or exploit certain applications of containers. Running these applications could cause further damage. This measure can ensure that certain applications are not executed to prevent further damage.
[0099] The at least one reaction Rn can, for example, include the following measure: 1.5. Creating driver warnings.
[0100] This measure can cause driver warnings to be displayed in the relevant HMI. These driver warnings can be triggered from the backend and displayed in the target vehicle and / or across the entire fleet.
[0101] Examples of an incident: A manipulation Mi was detected that cannot be addressed with other reactions Rn, e.g., for safety reasons. An ongoing reaction Rn stipulates that the vehicle 100 must not continue its journey. This measure can ensure that the driver is warned.
[0102] The at least one reaction Rn can, for example, include the following measure: 1.6. Deactivating data extraction, especially unauthorized data extraction.
[0103] This reaction can disable the uploading of data, e.g. for certain applications and / or services, via communication links.
[0104] Example of an incident: An attacker uses online services to, for example, extract personal data. This measure can ensure that personal data is not extracted without authorization.
[0105] The at least one reaction Rn can, for example, include the following measure: 1.7. Deactivating hardware ports, especially those that are affected.
[0106] This reaction can be used to deactivate hardware ports, e.g. USB ports, etc., that have been affected by manipulations.
[0107] Example of an incident: USB ports are used by an attacker in their attack path, e.g., in the KIA USB hack, and / or to mitigate the extraction of personal data. In this way, affected hardware ports can be blocked, which represent a security vulnerability for manipulation.
[0108] The at least one reaction Rn can, for example, include the following measure: 1.8. Blocking of, in particular defined, e.g. internal and / or external, IP addresses.
[0109] This response Rn can disable routing and / or network visibility for specific IP addresses or IP address ranges.
[0110] Example of an incident: Vehicle 100 currently has a large number of different IP addresses, some of which belong to unconfigured or unsecured applications / services. If these are targeted by an attacker, communication with K1 and K2 to these addresses can be disabled.
[0111] The at least one reaction Rn can, for example, include the following measure: 1.9. Deactivation of interfaces, especially those affected.
[0112] This reaction can disable interfaces such as WLAN, Bluetooth, keyless access, digital key, etc.
[0113] Example of an incident: The WLAN interface is used by an attacker on their attack path. This interface can then be deactivated for security reasons in the affected vehicle 100, in at least one other vehicle 101, or in the entire vehicle fleet.
[0114] The at least one reaction Rn can, for example, include the following measure: 1.10 Disabling an Internet and / or network connection for specific applications
[0115] This response can, for example, disconnect and / or interrupt the network connection for certain applications to prevent attacks by, among other things, online services.
[0116] The initiation of at least one reaction Rn can advantageously be carried out only in certain vehicle states, e.g., when the vehicle 100 is stopped, stationary, or traveling below a speed threshold, e.g., 3 km / h. In this way, the safety of the vehicle 100's operation can be maintained, which might not be possible at high speeds.
[0117] Advantageously, at least one reaction Rn can be configured such that only certain reactions Rn, particularly those verified for safety, are performed. This ensures that only verified reactions Rn are used.
[0118] The at least one reaction Rn can further be configured such that only defined, in particular permitted, vehicle functions F1, F2, targets, messages, applications, etc. are affected. In this way, only permitted vehicle functions F1, F2, targets, messages, applications, etc. can be affected.
[0119] For safety reasons, vehicle states can be defined, e.g., above a certain speed threshold, such as 3 km / h, in which the initiation of at least one reaction Rn is prevented. This prevents unexpected interventions in the operation of the vehicle 100 at high speeds.
[0120] Advantageously, the duration of at least one reaction Rn can be determined either on the vehicle side, e.g., by a vehicle control unit (ECU) 100, or externally, e.g., by a backend device control unit (ECU) 200. In this way, reactions Rn, e.g., safety measures, can be initiated only for a specific period of time to avoid continuously affecting vehicle operation.
[0121] As a safety precaution, it can be provided that the execution of at least one reaction Rn can be aborted either on the vehicle side, e.g., by a control unit ECU of the vehicle 100, or externally, e.g., by a control unit ECU of a backend device 200. In this way, a continuous influence on vehicle operation can be interrupted and reactions Rn that are no longer required can be deactivated.
[0122] As it is Fig. As illustrated in section 2, the following procedural steps can be carried out when a manipulation is detected: 121 Assessing a detected manipulation as an unjustified attack, 122 Assessing a detected manipulation Mi as an event or as a possible attack and carrying out an additional analysis, in particular to be able to determine whether the event is an unauthorized attack, what type of attack the event is and / or how many vehicles 100, 101 are affected, e.g. whether only a few vehicles 100, 101 or the entire vehicle fleet is affected.
[0123] As it is Fig. As indicated in point 3, the following procedural steps can be carried out on the vehicle side: 140 Evaluate the at least one reaction Rn with regard to the safe operation of the vehicle 100 or its suitability to reduce the potential for damage when operating the vehicle 100 and / or at least one other vehicle 101, and / or 150 Providing feedback on the at least one response Rn from the vehicle 100 to an external backend device 200, to at least one other vehicle 201 and / or to a user of the vehicle 100, as to whether the at least one response Rn was successful in order to reduce a potential for damage when operating the vehicle 100 and / or at least one other vehicle 101.
[0124] By providing feedback to an external backend device 200, documentation and further analysis as well as the development of new reactions Rn* can be enabled.
[0125] By providing feedback to at least one other vehicle 201, advantageous reactions can be initiated on another vehicle 201, even proactively.
[0126] Providing feedback to a user of the vehicle can create clarity for the user and strengthen trust in the vehicle.
[0127] As it is Fig. As illustrated in paragraph 3, if at least one reaction Rn was successful, at least one action can be carried out: 160 rated the operation of the vehicle as safe.
[0128] As it is Fig. 3 clarifies that if at least one reaction Rn has not been successful, at least one of the following actions (170) can be carried out: - Repeat at least one reaction Rn, - Providing other known reactions Rn, - Conducting an additional analysis, - Developing new reactions Rn*, - Stopping the vehicle 100, performing an update and / or visiting a workshop or accepting the risk in operating the vehicle 100.
[0129] As it is Fig. As illustrated in section 4, the following process steps can be carried out by the backend device 200: 210 Analyzing feedback about the at least one response Rn from the vehicle 100 to an external backend device 200, 220 Creating a database of successful responses Rn for different manipulations Mi, 230 Initiating a repeat of at least one reaction Rn if the at least one reaction Rn was unsuccessful in order to reduce the potential for damage in the operation of the vehicle 100 and / or at least one other vehicle 101, 240 Causing other known reactions Rn, 250 Performing an additional analysis, 260 Developing new reactions Rn*, 270 Initiating a recall of vehicle 100 and / or the vehicle fleet or accepting the risk in the operation of vehicle 100 and / or the vehicle fleet if at least one response Rn has not been successful.
[0130] A corresponding computer program product, a corresponding control unit ECU, a corresponding vehicle 100, preferably an automated or autonomously driving vehicle, and a corresponding backend device 200, preferably a central backend device 200 for a fleet of vehicles, also represent aspects of the invention.
[0131] The preceding explanation of the embodiments describes the present invention solely by way of examples. Naturally, individual features of the embodiments can be freely combined with one another, provided this is technically feasible, without departing from the scope of the present invention. Reference symbol list 100 vehicles 101 vehicles 200 Back end device F1 vehicle function F2 Vehicle Function K1 Communication K2 Communication Mi Manipulation Rn reaction Rn+1 reaction Rn* reaction ECU control unit
Claims
[1] Method for operating a vehicle (100), e.g. a fleet vehicle, such as an automated or autonomous vehicle, which has, in particular, internal and / or external communication (K1, K2) and different vehicle functions (F1, F2), comprising: - Monitoring of communication (K1, K2) and / or vehicle functions (F1, F2) for manipulations (Mi), e.g. anomalies, manipulated data and / or messages, - Detecting manipulation (Mi) depending on the monitoring, - Initiating at least one reaction (Rn) in the event of detected manipulation (Mi) in order to reduce the potential for damage when operating the vehicle (100) and / or at least one other vehicle (101). [2] The method of claim 1, wherein the at least one reaction (Rn) may comprise at least one of the following measures: - Non-forwarding of messages, especially manipulated messages, preferably defined (or already identified as manipulated), - Blocking of incoming messages, especially manipulated ones, preferably defined (or already identified as manipulated), - Shutdown of applications, especially those affected, - Shutting down of containers, especially those affected, - Creating driver warnings, - Disabling data extraction, especially unauthorized data extraction, - Disabling hardware ports, especially those that are affected, - Blocking of, in particular defined, IP addresses, - Deactivation of interfaces, especially those affected, and / or - Disabling an internet and / or network connection for specific applications. [3] Method according to one of the preceding claims, wherein the initiation of the at least one reaction (Rn) is carried out only in certain vehicle states, e.g. when the vehicle (100) is stopped, stationary or traveling below a speed threshold, e.g. 3 km / h. [4] Method according to any one of the preceding claims, wherein the at least one reaction (Rn) is configured such that only certain reactions, in particular those checked for safety, are carried out, and / or wherein the at least one reaction (Rn) is configured such that only defined, in particular permitted, vehicle functions (F1, F2), targets, messages, applications, etc. are affected, and / or where vehicle states are defined, e.g. above a certain speed threshold, e.g. 3 km / h, in which the initiation of at least one reaction (Rn) is prevented. [5] Method according to any one of the preceding claims, wherein the duration of the at least one reaction (Rn) is determined on the vehicle side, e.g. by a control unit (ECU) of the vehicle (100), or externally on the vehicle, e.g. by a control unit (ECU) of a backend device (200), and / or wherein an execution of the at least one reaction (Rn) is aborted on the vehicle side, e.g. by a control unit (ECU) of the vehicle (100), or externally on the vehicle, e.g. by a control unit (ECU) of a backend device (200). [6] A method according to any of the preceding claims, wherein, upon detection of manipulation (Mi), at least one of the following actions is performed: - Assessing a detected manipulation (Mi) as an unjustified attack, - Assessing a detected manipulation (Mi) as an event and / or as a possible attack and conducting additional analysis, in particular to determine whether the event is an unauthorized attack, what type of attack the event is and / or how many vehicles are affected, e.g. whether only a few vehicles or the entire fleet is affected. [7] Method according to any one of the preceding claims, furthermore, comprising at least one of the following actions, which is carried out in particular on the vehicle side, e.g. by a control unit (ECU) of the vehicle (100): - Evaluating at least one reaction (Rn) with regard to the safe operation of the vehicle (100), - Providing feedback on the at least one response (Rn) from the vehicle (100) to an external backend device (200), to at least one other vehicle (101) in the vehicle fleet and / or a user of the vehicle (100), indicating whether the at least one response (Rn) was successful in reducing the potential for damage when operating the vehicle (100) and / or at least one other vehicle (101), where, for example, the following action is performed if at least one reaction (Rn) was successful: - Assessing the operation of the vehicle (100) as safe, where, for example, at least one of the following actions is carried out if at least one reaction (Rn) was unsuccessful: - Repeat at least one reaction (Rn), - Providing other known reactions (Rn), - Conducting an additional analysis, - Developing new reactions (Rn*), - Stopping the vehicle (100), performing an update and / or visiting a repair shop or accepting the risk of operating the vehicle (100). [8] Method according to any one of the preceding claims, furthermore comprising at least one of the following actions, which is carried out in particular externally to the vehicle, e.g. by a control unit (ECU) of a backend device (200): - Analyzing feedback about at least one response (Rn) from the vehicle (100) to an external backend device (200), - Creating a database of successful responses (Rn) for different manipulations (Mi), where, for example, at least one of the following actions will be taken if at least one reaction (Rn) was unsuccessful: - To initiate a repeat of at least one reaction (Rn) if the at least one reaction (Rn) was unsuccessful, in order to reduce the potential for damage in the operation of the vehicle (100) and / or at least one other vehicle (101), - Causing other known reactions (Rn), - Conducting an additional analysis, - Developing new reactions (Rn*), - Initiating a recall of the vehicle (100) and / or the vehicle fleet or accepting the risk in the operation of the vehicle (100) and / or the vehicle fleet if at least one response (Rn) has not been successful. [9] Method according to any one of the preceding claims, wherein the initiation of at least one reaction (Rn) during operation of the vehicle (100) is caused either on the vehicle side, e.g. by a control unit (ECU) of the vehicle (100), or externally on the vehicle, e.g. by a control unit (ECU) of a backend device (200), and / or wherein the initiation of at least one reaction (Rn) during the operation of the vehicle (100) and / or of at least one other vehicle (101) is carried out automatically and / or manually, e.g. by an analysis team, by a control unit (ECU) of a backend device (200). and / or wherein the initiation of the at least one response (Rn) is carried out by means of the vehicle (100) when operating at least one other vehicle (101) of a vehicle fleet, in particular by providing direct feedback on the at least one response (Rn) from the vehicle (100) to the at least one other vehicle (101). [10] Computer program product comprising instructions which, when executed by a computer, cause the computer to perform the method according to any of the preceding method claims. [11] Electronic control unit (ECU) comprising a computing unit and a storage unit in which instructions are stored which, when at least partially executed by the computing unit, perform a method according to any one of the preceding method claims 1 to 7, in particular the control unit (ECU) is provided as a central control unit (ECU) of the vehicle (100). [12] Vehicle (100) comprising a control unit (ECU) according to the preceding claim. [13] Control unit (ECU) comprising a computing unit and a storage unit in which instructions are stored which, when at least partially executed by the computing unit, perform a method according to one of the preceding method claims 1 to 6 or 8, wherein in particular the control unit (ECU) is provided in an external backend device (200). [14] Backend device (200) comprising a control unit (ECU) according to the preceding claim.
Citation Information
Patent Citations
Mitigation of vehicle software manipulation
DE102022201901A1
Intrusion response apparatus and method for vehicle network
US20190332823A1
Intrusion monitoring system, method and related products
US20230231864A1
Universal intrusion detection and prevention for vehicle networks
US20230396634A1