Methods and devices for securing a system with multiple computing units
A cooperative method among multiple computing units in a system ensures reliable operation by monitoring and securely managing power supply to counteract malware, addressing the challenge of maintaining operational reliability in critical systems.
Patent Information
- Application Number
- DE102024201355
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-14
- Publication Date
- 2025-08-14
AI Technical Summary
Existing systems with multiple computing units face challenges in reliably securing and maintaining operational reliability against malicious software attacks, particularly in critical systems like motor vehicles, where incorrect power supply interruptions can lead to safety risks.
A method involving cooperative operation among multiple computing units, where a second unit monitors the first unit's reliability, a third unit manages energy supply, and a watchdog function ensures secure power interruptions and reinitialization to counteract malware, ensuring safe and reliable operation.
Enhances system safety by reliably identifying and mitigating compromised units, preventing incorrect power interruptions, and restoring normal operation, thereby improving overall system reliability and preventing unauthorized software influence.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
State of the art
[0001] The invention is based on a method and devices for securing a system with multiple computing units according to the class of the independent patent claims.
[0002] Methods for securing a system with multiple computing units are already known from the German patent application DE 10 2022 209 778. Advantages of the invention
[0003] The method and devices according to the invention have the advantage of providing a particularly secure method for deactivating compromised computing units. This allows the no longer operationally reliable computing unit to be reset with high reliability. Overall, this improves the operational reliability of the system with multiple computing units.
[0004] Further advantages and improvements arise from the features of the dependent patent claims. After switching off, operation of the affected computing unit can be resumed by switching the power supply back on. After the same computing unit has been switched off and on again several times, it can be concluded that there is a permanent disruption to operational reliability, and a permanent shutdown then occurs. This clearly distinguishes whether a malfunction affecting operational reliability can be remedied or not. The checking of a first computing unit is advantageously carried out by a second computing unit, as this improves the reliability of the system comprising several computing units. The interruption of the power supply is expediently carried out by a third computing unit. The reliability of the method is increased by distributing the monitoring across several computing units, which must cooperate with one another to implement the method.In particular, this prevents the power supply interruption from being triggered incorrectly. This is also ensured by verifying the validity of the request with regard to authenticity and the time of its generation. Drawings
[0005] Embodiments of the invention are illustrated in the drawings and explained in more detail in the following description. They show: Fig. 1 schematically shows a system with several computing units, and Fig. 2 the messages exchanged between the individual computing units over time. Description
[0006] Fig. 1 schematically shows a system with multiple processing units 1, 2, 3 for controlling a technical device 10, here for example a motor vehicle 10. The processing units 1, 2, 3 are connected by means of communication lines and can thus exchange messages with one another. Such a system, in the example of a motor vehicle 10 shown here, can be a network of multiple processing units 1, 2, 3 that perform control functions for controlling an engine of the vehicle 10, controlling the driving dynamics of the vehicle 10, such as active braking systems, or controlling individual comfort components of the vehicle 10, such as seat adjustment or window lifts. The individual processing units 1, 2, 3 can differ significantly in terms of their complexity. Individual processing units can, for example, be designed as powerful microcomputers with their own memory for a program and multiple communication connections.Furthermore, computing units for processing predefined process steps can be designed as circuit logic or as simple microcomputers for executing simple programs. Furthermore, individual computers can also have communication connections to external computing units outside the system of multiple computing units 1, 2, 3, i.e., in the present example, outside the motor vehicle 10.
[0007] The computing units 1, 2, 3 of the Fig. 1 are assigned different functions. The computing unit 1 performs complex control functions of the motor vehicle 10 and is designed as a powerful microcomputer with a memory for a program. Furthermore, this microcomputer is capable of communicating with external computing units 5. The computing unit 2 primarily performs safety tasks within the system of the multiple computing units 1, 2, 3. In particular, the computing unit 2 continuously checks the operational reliability of the computing unit 1 to ensure that the computing unit 1 performs its tasks correctly and does not process any tasks that are not part of the planned scope of tasks of the computing unit 1. This monitoring by the computing unit 2 ensures the operational reliability of the computing unit 1.
[0008] An external attacker controlling the external processing unit 5 could inject malware into the computer 1 to interfere with the operation of the motor vehicle 10. Such interference could, for example, consist of intentionally disabling individual functions of the motor vehicle 10. The introduction of illegal software could also be used for unauthorized tuning, i.e., to increase the vehicle's performance. Furthermore, such infiltrated software could be used to transmit data from the motor vehicle to an external computer 5 in order to monitor the vehicle or the user.
[0009] The monitoring of the operational reliability of the first computing unit 1 by the second computing unit 2 can be carried out in different ways. A particularly simpler approach is for the second computing unit 2 to perform a watchdog function in which the computing unit 1 regularly sends a request to the computing unit 1 and evaluates a corresponding response from the computing unit 1. Such a watchdog function can also simply consist of the computing unit 1 sending a predetermined signal to the computing unit 2 at predetermined intervals. However, more complex monitoring functions are also possible using a second computing unit 2, in which data from the computing unit 1 is continuously read and evaluated using statistical methods. The second computing unit 2 can be simpler or more complex depending on the methods used to monitor the operational reliability of the first computing unit 1.
[0010] Furthermore, the system with multiple processing units also includes a third processing unit 3, which performs the energy management function of the technical device, or in this case, in the motor vehicle 10. A system of multiple processing units 1, 2, 3 controls components of the technical devices 10 whose energy requirements exceed the available energy supply when all functions of the components are activated. The task of the third processing unit 3 is to monitor the vehicle's power supply network and to detect and react to safety-relevant incidents. An excessive current flow could, for example, indicate a short circuit. In response, the third processing unit 3 can deactivate the corresponding line to prevent further damage, e.g.Because the high current flow could generate excessive heat, which could damage control devices and cables or even cause a fire. For this purpose, the processing unit 3 is connected to switching units 4, which can control the power supply to individual processing units or components. In particular, the third control unit 3 is connected to a switching unit 4, which can switch the power supply of the processing unit 1 on or off. This switching unit 4 was described in . Fig. 1 is shown as a separate switching unit 4 to clearly illustrate the connection to the computing unit 1. However, such switching units 4 can also be arranged directly in the computing unit 3.
[0011] To secure the system with multiple processing units 1, 2, 3, cooperation between the individual processing units 1, 2, 3 is particularly necessary. Fig. 2, the individual steps for implementing the method according to the invention are explained schematically. Fig. 2, the individual processing units 1, 2, 3, and the communication messages exchanged between these units are schematically depicted with a time axis progressing from top to bottom. Furthermore, an external unit 5 is depicted, through which an external attacker transmits malware to the first processing unit 1 in a first message 21. The malware is processed by the processing unit 1, thereby changing the function of the processing unit 1. The processing unit 2 continuously checks the proper function of the processing unit 1. In the example of Fig. 2 this is done by the computing unit 2 sending a question 22 to the computing unit 1, which, if operating correctly, is answered by the computing unit 1 with an answer 23. Due to the change in the functionality of the computing unit 1 caused by the malware, the answer 23 is changed. This can, for example, consist of the question 22 requesting a checksum for a specific memory area and the checksum transmitted with the answer 23 being compared with a comparison value. Malware in a working memory of the computing unit 1 would change the checksum and be detected by the computing unit 2. By evaluating the answer 23, the computing unit 2 detects the disrupted function of the computing unit 1 and sets the operational reliability of the computing unit 1 to the status "compromised".If the status of computing unit 1 is set to "compromised" by computing unit 2, computing unit 2 sends a request 24 to computing unit 3, with the content to temporarily interrupt the power supply to computing unit 1. Computing unit 3 then checks the admissibility of this request in step 25 and if the request is classified as admissible in step 26, computing unit 3 interrupts the power supply to computing unit 1 in step 27. In the example according to the . Fig. 1 this is done by a step to interrupt the power supply 27 by which the switching unit 4, which is in the Fig. 1 assigned to the computing unit 1 is switched off.
[0012] By interrupting the power supply to computing unit 1, computing unit 1 is switched off and the contents of the volatile main memory of computing unit 1 are deleted, since the contents of the main memory are only retained if the power supply to computing unit 1 or the volatile main memory is continuous. In particular, this also deletes malware that was transmitted from external computing unit 5 to computing unit 1 via message 21. After a short wait time, which is long enough to reliably delete all contents of the volatile main memory of computing unit 1, computing unit 3 switches the power supply to computing unit 1 back on in step 28. Computing unit 1 is then reinitialized, i.e. the volatile main memory is read from an internal memory of computing unit 1 oranother internal memory of the system of the multiple computing units 1, 2, 3 is rewritten. Unless this internal, permanent memory is already infected by the malware, normal operation of computing unit 1 is restored.
[0013] Immediately thereafter or continuously, the operational reliability of computing unit 1 continues to be checked by computing unit 2 using messages 22 and 23. If, immediately after the power supply is restored, computing unit 1 is assigned the status "compromised" again in step 28, this also means that the internal memory used to reinitialize computing unit 1 has been affected. In such a case, operation of computing unit 1 must be permanently prevented. Alternatively, it can also be logged how often computing unit 1 is assigned the status "compromised" within a predetermined time interval. If this value exceeds a threshold, computing unit 1 is also permanently shut down. In this case, computing unit 2 can generate a further message 29, which triggers a permanent shutdown of computing unit 1.Computing unit 3 then performs step 27 (shutdown), but without performing step 28 (restoring the power supply) after a waiting period. In this case, a corresponding error message should also be issued regarding a malfunctioning system of computing units 1, 2, and 3. Request 24 thus corresponds to a request for a "reset" of computing unit 1, and request 29 corresponds to a permanent shutdown.
[0014] In step 25, the computing unit 3 checks the legitimacy of the request 24 to interrupt the power supply to the computing unit 1. This legitimacy can be verified, for example, by a cryptographically secured signature of the request 24. Furthermore, it can be verified whether the message was actually sent by the computing unit 2, for example, by a MAC (Message Authentication Code), in particular a CMAC (Cipher-Based Message Authentication Code). Furthermore, the request 24 should be provided with a novelty value, which is also checked by the computing unit 3. A novelty value is understood here to be any type of information that ensures the novelty or timeliness of the request 24, for example, a timestamp.The novelty value can prevent an external attacker from repeatedly sending requests 24 sent in the past to computing unit 3, thus preventing the system consisting of computing units 1, 2, and 3 from functioning. A corresponding check is also performed for a message 29 for permanently shutting down computing unit 1.
[0015] Special measures are required if important functions of the controlled technical system, in particular safety-relevant functions, are performed by the computing unit 1. In the example of a motor vehicle 10 used here, such an important function could, for example, consist of controlling the braking system. Before switching off such a computing unit 1, which performs important functions for the technical system, it must therefore be ensured that the technical function is performed by another computing unit in the system comprising computing units 1, 2, 3. Only then may the computing unit 1 be switched off. The triggering of such a takeover of functions for controlling the technical system by other computing units can, for example, be carried out by the computing unit 2 before the request 24 is sent or by the computing unit 3 before step 27 for interrupting the power supply.The transmission of the request 24 or the interruption of the power supply 27 must then be delayed until the takeover of the control function by another processing unit is ensured. QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] DE 10 2022 209 778
[0002]
Claims
[1] Method for securing a system with several computing units (1, 2, 3), in particular in a motor vehicle (10), characterized by that the operational reliability of the computing units (1, 2, 3) of the system is monitored, that a first computing unit (1) is assigned the status "compromised" if a lack of operational reliability is detected, and that the power supply of the first computing unit (1) with the status "compromised" is interrupted. [2] Method according to claim 1, characterized by that after the interruption of the power supply, the power supply is switched on again and that after switching on the operational reliability of the first computing unit (1) is checked. [3] Method according to claim 1, characterized by that after the power supply of the first computing unit (1) has been switched off and on several times, the power supply of the first computing unit (1) is permanently switched off. [4] Method according to one of the preceding claims, characterized by that the checking of the operational reliability of the computing units (1, 2, 3) is carried out by a second computing unit (2). [5] Method according to claim 4, characterized by that the checking of operational safety by the second computing unit (2) is carried out by communication with the first computing unit (1), in particular by checking responses from the first computing unit (1). [6] Method according to one of the preceding claims, characterized by that the interruption of the power supply is triggered by a third computing unit (3). [7] Method according to claim 6, characterized by that the third computing unit (3) receives a request (24) from the second computing unit (2) to interrupt the power supply to the first computing unit (1). [8] Method according to claim 7, characterized bythat the third computing unit (3) only implements the request if a check of the admissibility of the request (24), in particular with regard to authenticity and time of generation, confirms the admissibility of the request. [9] Computing unit for securing a system with several computing units (1, 2, 3), with means for monitoring the operational reliability of computing units (1, 2, 3) in order to implement the method according to one of claims 1 to 8. [10] Computing unit for securing a system with several computing units (1, 2, 3), with means for interrupting the power supply of computing units (1, 2, 3) in order to implement the method according to one of claims 1 to 8.
Citation Information
Patent Citations
Mitigation of vehicle software manipulation
DE102022201901A1
Electronic element, system comprising such an electronic element and method for monitoring a processor
US20200257603A1