Method and device for protecting a control unit against attempted manipulation
The connection configuration register in microcontrollers detects manipulation tools at the debugging interface, ensuring secure operation by activating tamper protection measures like error logging or reset, addressing the issue of unauthorized access and memory alteration in control units.
Patent Information
- Application Number
- DE102024200834
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-30
- Publication Date
- 2025-07-31
AI Technical Summary
Existing microcontrollers in control units, particularly in automotive applications, lack effective methods to detect and counter manipulation attempts via debugging interfaces, which can lead to unauthorized access and memory content alteration.
Implement a connection configuration register in the microcontroller to monitor and configure debugging interface terminals, enabling detection of manipulation tools by checking terminal states, and activate tamper protection functions such as error logging, function restriction, or reset when manipulation is detected.
Effectively identifies and counters manipulation attempts by ensuring secure operation of the microcontroller, preventing unauthorized access and memory alterations.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical area
[0001] The invention relates to control units with one or more microcontrollers that have a debugging interface for debugging or analyzing internal sequence control and memory contents. The invention further relates to a method for detecting a tampering attempt using a manipulation tool connected to the debugging interface. Technical background
[0002] ECUs typically implement commercially available microcontrollers that have external connections and are generally designed for a wide range of applications. In addition to the conventional power supply, data communication, and other connections, conventional microcontrollers also feature debugging interfaces, such as JTAG, DAP, SWD, LPD-4, and the like.
[0003] When microcontrollers are used in ECUs, the debugging interface is usually disabled for use in customer applications, for example, via software or by physically interrupting the relevant connections. However, by connecting a tamper-evident tool to the debugging interface, an attempt can be made to interfere with the ECU's functionality, read memory contents, or modify them.
[0004] It is therefore an object of the present invention to detect attempts at manipulation when a manipulation tool is connected to the debugging interface and to take appropriate countermeasures. Disclosure of the invention
[0005] This object is achieved by the method for detecting a manipulation attempt in a control unit using a manipulation tool connected to a debugging interface according to claim 1 and a corresponding control unit according to the independent claim.
[0006] Further embodiments are specified in the dependent claims.
[0007] According to a first aspect, a method for detecting an attempt to manipulate a control unit using a manipulation tool is provided, comprising the following steps: - Querying one or more register locations of a connection configuration register assigned to a debugging interface of a microcontroller of the control unit, - Check whether a register location of the port configuration register associated with the debugging interface of the control unit's microcontroller is configured as an output; - If at least one of the pins of the pin configuration register associated with the debugging interface of the ECU microcontroller is detected as an output, performing a tamper protection function.
[0008] Microcontrollers used in conventional control units, particularly for automotive applications, have pin configuration registers with register locations that specify whether a corresponding pin on the microcontroller is configured or wired as an input or output. After the microcontroller is powered on, all register locations of the pin configuration register are in an initial state that configures all pins on the microcontroller as inputs. As soon as a pin on the microcontroller is electrically contacted, so that the respective pin can be used as a data output, this is recorded by an entry in the corresponding memory location of the pin configuration register assigned to this pin.
[0009] For this purpose, a software function can be implemented that checks the configuration status at an appropriate time, such as during startup or cyclically. Furthermore, a hardware error detection module in the microcontroller can detect the unexpected activation of the debugging interface and report it via register entries or take other actions, such as interrupts, resets, etc.
[0010] The assignment or writing of the connection configuration register is usually based on hardware functions and therefore cannot be influenced by software functions.
[0011] Typically, when a manipulation tool is connected to the microcontroller, at least one pin is wired as an output to enable communication between the manipulation tool and the microcontroller. For the debugging interface pins that are to be connected to a manipulation tool and used as data outputs, the corresponding register locations are written to indicate that these pins are configured as outputs. This causes the register location of the pin configuration register assigned to the corresponding pin to configure the corresponding pin as an output. Thus, it can be detected that a manipulation tool is connected to the debugging interface by checking the pin configuration register.Thus, a function can be implemented in the microcontroller that checks the port configuration register immediately after power-up, periodically during operation, and upon certain events to determine whether one of the debugging interface ports is configured as an output.
[0012] If a manipulation tool is detected by querying the connection configuration register, a corresponding manipulation protection function can be activated.
[0013] The anti-tamper function may include one of the following measures: - Making an entry in an error memory and continuing the operation of the microcontroller; - Restricting or disabling individual functions of the microcontroller; - Reset the microcontroller. Brief description of the drawings
[0014] Embodiments are explained in more detail below with reference to the attached drawings. They show: Fig. 1 a schematic representation of a control unit with a microcontroller; and Fig. 2 a flowchart illustrating a method for operating the control unit. Description of embodiments
[0015] Fig. 1 schematically shows a control unit 1, for example for automotive applications, with a microcontroller 2, a memory module 3 as program and data memory and further peripheral components 4. The microcontroller 2 has a plurality of connections 21 in order to communicate with the memory module 3, the further peripheral elements 4 and, via connections 11 of the control unit 1, with external components.
[0016] Some of the pins 21 of the microcontroller 2 serve as pins of a debugging interface 22, via which tests and error analyses are performed for debugging purposes during the production of the control unit 1. However, the pins of the debugging interface 22 are unused in the ready-to-use control unit 1, cannot be easily accessed from the outside, and can usually only be accessed by intervening in the control unit 1.
[0017] The use of the pins of microcontroller 2 is monitored by a pin configuration register 23. This register is written and read by a hardware function to determine whether a specific pin 21 of microcontroller 2 is configured as an input or output.
[0018] In the flowchart of the Fig. 2, the sequence of a function for monitoring the debugging interface 22 of the microcontroller 2 is executed.
[0019] For this purpose, in step S1, after starting the control unit 1 or at a predetermined time, the microcontroller 2 reads out register locations of the connection configuration register 23 that are assigned to the connections for the debugging interface 22.
[0020] In step S2, it is checked whether one of the ports of the debugging interface 22 is being used as a data output. If it is determined that one of the ports of the debugging interface 22 is being used as a data output (alternative: yes), it can be concluded that a manipulation tool has been connected to the debugging interface.
[0021] In this case, a tamper protection function is called in step S3. Otherwise, the method continues with step S1.
[0022] The tamper protection function can include an entry in the error memory and continue the operation of the microcontroller unchanged. Alternatively, individual functions of the microcontroller 2 can be restricted or deactivated. Alternatively, the microcontroller 2 can be reset. This results in the microcontroller 2 being reset in a function loop until the tamper tool is disconnected from the debugging interface 22.
Claims
[1] Method for detecting an attempt to manipulate a control device (1) using a manipulation tool, comprising the following steps: - querying or reading (S1) one or more register locations of a connection configuration register (23), each of which is assigned to a debugging interface (22) of a microcontroller (2) of the control unit (1), - checking (S2) whether a register location of the connection configuration register assigned to the debugging interface (22) of the microcontroller (2) of the control unit is configured as an output; - If at least one of the connections of the connection configuration register (23) assigned to the debugging interface (22) of the microcontroller (2) of the control unit (1) is detected as an output, performing (S3) a tamper protection function. [2] Method according to claim 1, wherein it is determined that a debugging interface (22) is used as a data output, is implemented by a software function that checks the state of the configuration at a predetermined time, or by a hardware error detection module that is designed to detect an unexpected activation of the debugging interface. [3] Method according to claim 1 or 2, wherein the tamper protection function comprises one of the following measures: - making an entry in an error memory and continuing the operation of the microcontroller (2); - Restricting or deactivating individual functions of the microcontroller (2); - Reset the microcontroller (2). [4] Control device (1) for carrying out one of the methods according to one of claims 1 to 3. [5] Computer program product, comprising instructions which, when the program is executed by at least one data processing device in particular in the microcontroller of the control unit, cause the latter to carry out the steps of the method according to one of claims 1 to 3. [6] Machine-readable storage medium, comprising instructions which, when executed by at least one data processing device in particular the microcontroller of the control unit, cause the latter to carry out the steps of the method according to one of claims 1 to 3.