Motor vehicle and method for mutual integrity check during a boot process of computing devices

DE102024118774B4Active Publication Date: 2026-07-23AUDI AG
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
AUDI AG
Filing Date
2024-07-02
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Ensuring the integrity and authenticity of software during the boot process of computing devices in motor vehicles is crucial for safety-related functions, as existing methods do not adequately address the need for mutual verification between computing units.

Method used

A method where at least two computing units in a motor vehicle mutually verify their boot status indicators, ensuring both units have successfully completed their boot processes before enabling safety-related functions, using secure boot processes, digital signatures, and hardware security modules to protect the boot process.

Benefits of technology

This approach ensures a consistent and secure state for driving safety-relevant functions by preventing the execution of safety-related functions if any boot process fails, thereby enhancing system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for mutual integrity checking during a boot process of computing units (12, 14) of a motor vehicle (10), wherein the motor vehicle (10) comprises at least two computing units (12, 14) for driving safety-relevant functions (16, 18), each configured such that in the event of an impairment of one of the computing units (12, 14) the other takes over the driving safety-relevant functions (16, 18) of the impaired computing unit (12, 14), wherein the following steps are carried out during a boot process of the computing units (12, 14): - Booting the computing units (12, 14), wherein the computing units (12, 14) generate a respective boot status indicator (22, 24) during booting, which indicates a state of the respective boot process; - Transmitting the respective generated boot status indicator (22, 24) to the respective other computing unit (12, 14) via a data connection (26);- Checking its own boot status indicator and the transmitted boot status indicator of the other computing unit by the respective computing unit (12, 14); - Enabling the computing units (12, 14) to perform the driving safety-relevant functions (16, 18) only if the respective boot status indicators (22, 24) are available to the computing units (12, 14) and the check shows that the boot status indicators (22, 24) each indicate a successful boot process, whereby the execution of the driving safety-relevant function on the computing unit (12, 14) is prevented if either of the two boot status indicators (22, 24) indicates that the boot process was not successful or if a boot status indicator (22, 24) of a computing unit (12, 14) is not available.;
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for mutual integrity checking during the boot process of computer systems in a motor vehicle. Furthermore, the invention relates to a motor vehicle configured to perform the method.

[0002] For various reasons, it is crucial in motor vehicles to ensure the integrity and authenticity of the software stored or executed on the computer, such as executable code and data. Control systems are known to achieve this by employing fail-safe computers to ensure the overall reliability of safety-related functions. This can be accomplished using two similar computers, typically providing a primary and a redundant path to guarantee the necessary availability for the safety-related function. In other words, so-called fail-operational systems can be implemented, which maintain the safety-related function even if a subsystem fails.

[0003] From DE 10 2021 209 674 A1, a method for automated driving of a motor vehicle is known, using at least one control unit for calculating a trajectory, wherein control commands for actuators for adjusting longitudinal and lateral guidance of the motor vehicle are calculated for the trajectory and implemented by the actuators, wherein the control commands are updated at defined times, wherein at each time an up-to-date emergency trajectory is calculated to bring the motor vehicle to a standstill, wherein for the emergency trajectory a set of control commands for actuators for adjusting at least the lateral guidance is calculated, which are automatically implemented by the actuators for the emergency trajectory if the control commands for the trajectory fail.

[0004] German patent DE 103 03 383 A1 discloses a method and a device for monitoring the safe operation of a functional unit in a motor vehicle. The method employs two fail-safe electronic units to monitor the functional unit. During operation, data is exchanged between at least one of the two fail-safe electronic units and the data bus. Furthermore, communication takes place between the two fail-safe electronic units.

[0005] From DE 199 33 086 A1, a method and a device for mutual monitoring of control units are known, wherein the control units are structured with three program levels: a first level for executing the control unit functions, a second level for monitoring these functions, and a third level for monitoring the programs of the second level. A first control unit sends a selected question to a second control unit, which then answers it as part of a process check. The second control unit sends the generated answer back to the first control unit, which then determines the error-free operation of the second control unit based on a comparison of the generated answers with the expected answer. The first control unit is monitored accordingly through communication with the second.

[0006] The object of the invention is to ensure the integrity of computing devices during a startup process.

[0007] This problem is solved by the independent patent claims. Advantageous embodiments of the invention are disclosed in the dependent patent claims, the following description, and the figures.

[0008] The invention is based on the idea that the overall system only starts when both computing units mutually assure each other of its integrity, so that the driving safety-relevant functions are only started when both computing units have reported an "OK" status to the other computing unit.

[0009] One aspect of the invention relates to a method for mutual integrity checking during a boot process of computing devices of a motor vehicle, wherein the motor vehicle comprises at least two computing devices for driving safety-relevant functions, each of which is designed such that, in the event of an impairment of one of the computing devices, the other takes over the driving safety-relevant functions of the impaired computing device, wherein the following steps are carried out during a boot process of the computing devices.The computing units are booted, whereby each unit generates a boot status indicator indicating the state of the respective boot process, transmits the generated boot status indicator to the other computing unit via a data connection, checks its own boot status indicator and the transmitted boot status indicator of the other computing unit, and is only released to perform the driving safety-relevant functions if the respective boot status indicators are available to the computing units and the check shows that the boot status indicators indicate a successful boot process.

[0010] In other words, the procedure can be designed for two computer units in the vehicle, which are "fail-operational" units. When booting or starting up these units, boot status indicators can be generated, for example, upon completion of the boot process. These boot status indicators indicate the current state of the booted computer unit. That is, the boot status indicator can show whether the boot process was successful or if errors occurred.

[0011] This boot status indicator can then be sent to the other computing unit. This can be done, for example, via a data connection such as Ethernet, PCIe, or a CAN bus. This means that after transmitting the generated boot status indicator, each computing unit can display its own boot status indicator and the boot status indicator of the other computing unit. These can then be checked to see if both boot processes were completed successfully. If so, the system can be enabled to execute the safety-related functions. This means that the safety-related functions can be executed on the computing units, and the computing units can be put into operation.

[0012] If either boot status indicator shows that a boot process was unsuccessful, or if a boot status indicator is missing for a computer unit, the execution of the safety-relevant function on the computer unit can be prevented. In particular, an error message can also be issued indicating this error condition.

[0013] The computing devices can be, for example, vehicle computers and / or control units of the motor vehicle, on which programs for carrying out driving safety-relevant functions can be executed. These driving safety-relevant functions can include, for example, the control of steering, brakes, and / or autonomous or semi-autonomous driving tasks.

[0014] The invention offers the advantage that a consistent state for the driving safety-relevant functions can be generated through mutual integrity checking. In particular, it eliminates the need for complicated handling of error states that can occur when a problem is detected during the operation of the computing devices.

[0015] The invention also includes embodiments that offer additional advantages.

[0016] One implementation involves the computer systems performing a secure boot process. A secure boot process restricts the startup process to pre-signed bootloaders, thereby preventing malware or other programs from launching. This means that only trusted programs are used for the boot process, thus increasing security during system startup.

[0017] Another embodiment involves using a hardware security module (HSM) to perform the boot process of the respective computing device. This means that a protected hardware environment can be provided for the boot process. A HSM protects sensitive, security-relevant information from unauthorized access or manipulation within a dedicated hardware area. This information can include, in particular, programs used for the boot process of the computing device. For example, the HSM can provide keys and services for encryption, decryption, signing, and / or authentication by other applications. Components for a key management system (KMS) can also be provided.This design offers the advantage of further increasing security during the boot process of the computing equipment.

[0018] Another embodiment provides that the boot status indicators of the respective computing units are digitally signed. In particular, authorization to execute the safety-relevant functions can then be granted once the digital signature has been verified and confirmed by the respective computing unit.

[0019] A digital signature, or digital signature method, can be implemented using an asymmetric cryptosystem, where a sender calculates a value for the transmitted boot status indicator using a private signature key. This value allows the authorship and integrity of the transmitted boot status indicator to be verified using a public verification key.

[0020] In particular, it can be stipulated that a pairing process is performed between the computing devices upon commissioning, during which a key exchange for the digital signature takes place. This initial connection can be established, for example, after the vehicle has been manufactured or in a workshop, during which the computing devices exchange identifying data, especially information for exchanging the digital signature key. This ensures that the two computing devices belong to each other and that no foreign or external device possesses a key for the connection. The digital signature and pairing process offer the advantage of further enhancing security during integrity verification.

[0021] Another embodiment provides that, after transmitting its respective boot status indicator, each computing unit waits for an acknowledgment of receipt from the other computing unit. If no acknowledgment is received, the transmission is repeated for a predetermined number of attempts. For example, the transmission of the boot status indicator can be repeated two, three, or five times if no acknowledgment is received. In particular, it can be provided that, to ensure the transmission of the boot status indicator, methods such as a three-way handshake are used, in which the computing units mutually acknowledge receipt and confirm it again. Before a computing unit transmits the boot status indicator, it can wait until a connection has been established, thus ensuring a secure connection.This offers the advantage that measures can be taken against packet loss or timeouts.

[0022] Another embodiment provides that the boot status indicators are flags that indicate the final state of the respective boot process. Flags are status indicators used in computer science to identify specific program states. For example, flags can indicate the state of the entire boot process of the respective computing device or the state of sub-segments of the boot process.

[0023] Another embodiment provides that the driving safety-relevant functions include steering functions, braking functions, and / or functions for autonomous driving. Particularly with regard to autonomous driving functions, ensuring the operation of the computing units and a successful boot process can be crucial for safety.

[0024] Another embodiment provides that the data connection of the computing equipment includes Ethernet, PCIe, and / or CAN. This means that the data connection to which the computing equipment is connected and through which the respective boot status indicator is exchanged can take place via one or more of the aforementioned transmission paths.

[0025] Another aspect of the invention relates to a motor vehicle with at least two computing units for driving safety-related functions, each configured such that, in the event of a malfunction of one computing unit, the other takes over the driving safety-related functions of the malfunctioning computing unit. The computing units are configured to perform a method according to one of the preceding aspects during a boot process. This offers the same advantages and possibilities for variation as the method described above. The motor vehicle according to the invention is preferably configured as a motor vehicle, in particular as a passenger car or truck, or as a passenger bus or motorcycle.

[0026] For use cases or application situations that may arise during the procedure and are not explicitly described here, it may be provided that, according to the procedure, an error message and / or a request for user feedback is issued and / or a default setting and / or a predetermined initial state is set.

[0027] The invention also includes the control device for the motor vehicle. The control device can comprise a data processing device or a processor circuit configured to carry out an embodiment of the method according to the invention. For this purpose, the processor circuit can comprise at least one microprocessor and / or at least one microcontroller and / or at least one FPGA (Field Programmable Gate Array) and / or at least one DSP (Digital Signal Processor). In particular, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), or an NPU (Neural Processing Unit) can be used as the microprocessor. Furthermore, the processor circuit can comprise program code configured to carry out the embodiment of the method according to the invention when executed by the processor circuit.The program code can be stored in a data memory of the processor device. The processor device can be based, for example, on at least one circuit board and / or on at least one SoC (System on Chip).

[0028] The invention also includes further developments of the motor vehicle according to the invention, which have features as already described in connection with the further developments of the method according to the invention. For this reason, the corresponding further developments of the motor vehicle according to the invention are not described again here.

[0029] As a further solution, the invention also includes a computer-readable storage medium comprising program code which, when executed by a computer or a computer network, causes it to execute an embodiment of the method according to the invention. The storage medium can be provided at least partially as a non-volatile data storage medium (e.g., as flash memory and / or as an SSD - solid state drive) and / or at least partially as a volatile data storage medium (e.g., as RAM - random access memory). The storage medium can be located within the computer or computer network. The computer or computer network can provide a processor circuit with, for example, at least one microprocessor. The program code can be provided as binary code and / or as assembly code and / or as source code of a programming language (e.g., C) and / or as a program script (e.g., Python).The computer-readable storage medium can alternatively be implemented by a signal containing computer-readable data, e.g., a time-varying voltage signal and / or a radio signal.

[0030] The invention also includes combinations of the features of the described embodiments. The invention therefore also includes realizations that each exhibit a combination of the features of several of the described embodiments, provided that the embodiments have not been described as mutually exclusive.

[0031] The following are exemplary embodiments of the invention described. This is illustrated by: Fig. 1 a schematic representation of a motor vehicle according to an exemplary embodiment; Fig. 2 a schematic process diagram according to an exemplary embodiment.

[0032] The exemplary embodiments described below are preferred embodiments of the invention. In these exemplary embodiments, the described components each represent individual features of the invention, which can be considered independently of one another and each further develops the invention independently. Therefore, the disclosure is intended to include combinations of features of the embodiments other than those shown. Furthermore, the described embodiments can also be supplemented by further features of the invention already described.

[0033] In the figures, identical reference symbols denote functionally equivalent elements.

[0034] In Fig. Figure 1 depicts a highly schematic motor vehicle 10, which has at least a first computing unit 12 and a second computing unit 14. The computing units 12, 14 can be configured to perform a driving safety-relevant function 16, 18, such as steering functions, braking functions, and / or functions for autonomous driving. For example, the computing units 12, 14 can be control units of the motor vehicle 10. Furthermore, the computing units 12, 14 can be configured as redundant computing units 12, 14, which means that, for example, if the second computing unit 14 fails, the first computing unit 12 can additionally take over the driving safety-relevant function 18 of the impaired computing unit 14.

[0035] To ensure the integrity of the computing devices 12 and 14, it may be possible to perform a check during the startup process. In particular, an integrity check can be carried out during the boot process.

[0036] The first computing device 12 can perform a boot process, in particular a secure boot process. This can be performed in a protected hardware environment 20, such as a hardware security module. As a result of the boot process of the first computing device 12, an initial boot status indicator 22 can be generated, which indicates the success of the boot process of the first computing device 12. In particular, the boot status indicator 22 can be a flag that indicates a final state of the boot process, for example, successful or unsuccessful.

[0037] The second computing unit 14, which can also perform a boot process, in particular a secure boot process in a protected hardware environment 20, can generate a second boot status indicator 24 for the boot process, which indicates the success of the boot process of the second computing unit 14.

[0038] The first boot status indicator 22 of the first computing unit 12 can then be transmitted to the second computing unit 14, and the second boot status indicator 24 of the second computing unit 14 can be transmitted to the first computing unit 12. This can be done via a data connection 26, for example, via Ethernet, PCIe, and / or a CAN bus. Pairing can be performed during the commissioning of the computing units for the transmission of the respective boot status indicators 22 and 24, whereby a suitable key for communication can also be negotiated during pairing. Preferably, the respective boot status indicators 22 and 24 can be digitally signed, which ensures the origin of the respective boot status indicator 22 and 24.Furthermore, after transmission of the respective boot status indicator 22, 24, an acknowledgment can be received from the respective computing unit 12, 14, i.e., confirmation of receipt of the boot status indicator 22, 24 from the other computing unit. If such an acknowledgment is not received, the transmission can be repeated, in particular for a predetermined number of attempts, for example, five attempts.

[0039] If the respective boot status indicators 22 and 24 have been successfully transmitted, they can be checked for a successful boot process, for example, in a program element 28. For instance, the first computing unit 12 can check its own boot status indicator 22 and the received boot status indicator 24 to determine whether the respective boot process was successful. Only if both boot status indicators 22 and 24 indicate a successful boot process is the first computing unit authorized to perform its safety-related functions 16. If, however, only one boot status indicator is present, or if one of the two boot status indicators 22 and 24 indicates a negative boot process, the starting of the safety-related function can be prevented. In this case, for example, an error message can be generated and / or the operation of the motor vehicle 10 can be prevented.

[0040] In a corresponding manner, the second computing unit 14 can check its own boot status indicator 24 and the received boot status indicator 22 to determine whether the boot processes were successful and only then release the driving safety-relevant function 18 or not.

[0041] In Fig. Figure 2 shows a schematic procedure diagram for mutual integrity checking during a boot process of computing devices 12, 14 of a motor vehicle 10, wherein the computing devices 12, 14 can be “fail-operational” computing devices.

[0042] In step S10, the computing units 12 and 14 can be started up, whereby the computing units 12 and 14 each generate a boot status indicator 22 and 24, respectively, which indicates the state of the respective boot process. The boot process can be a Secure Boot process, which restricts initialization to previously signed bootloaders.

[0043] In step S12, the respective generated boot status indicators 22 and 24 can be transmitted to the other computing unit via a data connection 26. For this purpose, the boot status indicators 22 and 24 are preferably digitally signed so that precise attribution to the sender is possible.

[0044] In step S14, it can be checked whether all boot status indicators are present and whether the user's own boot status indicator and the transmitted boot status indicator each indicate a successful boot process.

[0045] If this is the case, in step S16 a release of the computing devices 12, 14 to perform the driving safety-relevant functions 16, 18 can be generated.

[0046] Another exemplary aspect involves performing a Secure Boot process on each of the two instances of the computing system, subsystems, or control units. Subsequently, a secure transmission of the partial result can be transferred to the respective partner computing system via a communication channel between the two systems. The systems can only be enabled to start once the respective local and remote enable flags of the Secure Boot procedure are present. Additionally, a key can be provided for a secure connection between the two systems. Ideally, pairing takes place during the commissioning of the combined computing system, during which a suitable key for communication can also be negotiated.Implementation on the computing equipment can be carried out, particularly in a protected hardware environment. Furthermore, a handshake / acknowledgment procedure can be implemented for the secure transmission of partial results (boot status indicators), ensuring that the failure of individual boot status indicators has no negative impact on overall functionality.

[0047] Overall, the examples show how the invention can provide mutual integrity checking for fail operational systems. QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] DE 10 2021 209 674 A1

[0003] DE 103 03 383 A1

[0004] DE 199 33 086 A1

[0005]

Claims

[1] Method for mutual integrity checking during a boot process of computing devices (12, 14) of a motor vehicle (10), wherein the motor vehicle (10) comprises at least two computing devices (12, 14) for driving safety-relevant functions (16, 18), each of which is designed such that, in the event of an impairment of one of the computing devices (12, 14), the other takes over the driving safety-relevant functions (16, 18) of the impaired computing device (12, 14), wherein the following steps are carried out during a boot process of the computing devices (12, 14): - Booting the computing devices (12, 14), wherein the computing devices (12, 14) generate a respective boot status indicator (22, 24) which indicates a state of the respective boot process; - Transmitting the respective generated boot status indicator (22, 24) to the respective other computing unit (12, 14) via a data connection (26); - Checking its own boot status indicator and the transmitted boot status indicator of the other computing device by the respective computing device (12, 14); - The computing devices (12, 14) are only enabled to perform the driving safety-relevant functions (16, 18) if the respective boot status indicators (22, 24) are available to the computing devices (12, 14) and the check shows that the boot status indicators (22, 24) each indicate a successful boot process. [2] Method according to claim 1, wherein the computing devices (12, 14) perform a secure boot process. [3] Method according to one of the preceding claims, wherein the boot process of the respective computing device (12, 14) is carried out with a hardware security module. [4] Method according to any of the preceding claims, wherein the boot status indicators (22, 24) of the respective computing devices (12, 14) are signed with a digital signature. [5] Method according to claim 4, wherein during commissioning of the computing devices (12, 14) a pairing between the computing devices (12, 14) is carried out, in which a key exchange for the digital signature is carried out. [6] Method according to one of the preceding claims, wherein the respective computing unit (12, 14) waits for an acknowledgment of receipt from the other computing unit (12, 14) after transmitting the respective boot status indicator (22, 24), the transmission being repeated for a predetermined number of attempts if no acknowledgment of receipt is received. [7] Method according to any of the preceding claims, wherein the boot status indicators are flags that provide a final state of the respective boot process. [8] Method according to any of the preceding claims, wherein the driving safety-relevant functions (16, 18) include steering functions, braking functions and / or functions for autonomous driving. [9] Method according to any of the preceding claims, wherein the data connection (26) of the computing devices (12, 14) comprises Ethernet, PCIe and / or CAN. [10] Motor vehicle (10) with at least two computing units (12, 14) for driving safety-relevant functions (16, 18), each configured such that in the event of an impairment of one of the computing units (12, 14) the other takes over the driving safety-relevant functions (16, 18) of the impaired computing unit (12, 14), wherein the computing units (12, 14) are configured to perform a method according to one of the preceding claims during a boot process of the computing units (12, 14).