Vehicle diagnostic procedure, vehicle diagnostic device and vehicle
The vehicle diagnostic procedure addresses the issue of unauthorized write operations by implementing a counter-based system to ensure only authorized devices can perform write operations, enhancing security and compliance with emission regulations.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-02
- Publication Date
- 2026-04-02
AI Technical Summary
Existing vehicle diagnostic procedures lack sufficient safety measures to prevent malicious use of write operations in fault memory and control units, which can compromise vehicle integrity and compliance with emission regulations.
A vehicle diagnostic procedure that includes counting write operations using a counter and generating an error message when a threshold is exceeded, ensuring that only authorized diagnostic devices can perform write operations by matching internal and external communication protocols, and utilizing a tamper-proof counter to prevent unauthorized changes.
Enhances the security and reliability of vehicle diagnostics by preventing unauthorized write operations, ensuring compliance with regulatory protocols, and maintaining the integrity of fault memory and control units.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for vehicle diagnostics and a device for vehicle diagnostics as well as a vehicle with at least one corresponding device.
[0002] During vehicle operation, error messages from the vehicle's control units are stored in a fault memory. These stored error messages can be read out as part of a vehicle diagnostic procedure. Such a vehicle diagnostic procedure may be legally required to comply with exhaust emission limits. On-Board Diagnostics 2 (OBD-2) can be used as a communication protocol for vehicle diagnostics.
[0003] In addition to reading the fault memory mentioned earlier, vehicle diagnostics may also involve writing data, for example, to clear the fault memory or to program a replaced control unit. In the worst-case scenario, these writing operations could be used for malicious purposes.
[0004] The technical problem is to create a procedure for vehicle diagnostics, a device for vehicle diagnostics, and a vehicle with at least one such device, which will increase the safety of the vehicle diagnostics.
[0005] The solution to the technical problem is provided by the articles with the features of the independent claims. Further advantageous embodiments of the invention are described in the dependent claims.
[0006] A procedure for vehicle diagnostics is proposed, comprising the following steps: - Providing at least one internal signal, wherein the at least one internal signal signals an actual communication protocol for vehicle diagnostics, - Receiving at least one external signal, wherein the at least one external signal indicates a target communication protocol for vehicle diagnostics, - Output of vehicle diagnostics when the actual communication protocol matches the target communication protocol, - Adjusting a counter when the received external signal indicates at least one write operation, - Generate at least one error message when the counter passes a threshold for a permissible number of write operations.
[0007] A further proposed device for vehicle diagnostics is presented, wherein the device is configured to perform a method according to an embodiment described in this disclosure. The device may, for example, be configured as or comprise a microprocessor.
[0008] A further proposal is for a vehicle comprising at least one device according to an embodiment described in this disclosure. The vehicle can be, for example, a passenger car or a truck.
[0009] The technical effects and advantages described in this disclosure for the process naturally also apply to the device and the vehicle, and vice versa.
[0010] The procedure has the technical effect of allowing an exceedance of the permissible number of write operations to be registered by means of at least one error message. This is achieved technically by counting each write operation triggered by an external signal using a counter and comparing the current counter value with the threshold. This improves the reliability of vehicle diagnostics.
[0011] The internal signal can be generated and provided by a control unit, such as the engine control unit. The provision of the internal signal can occur via an internal communication bus of the vehicle, such as a CAN bus. The internal signal can contain an encoding to indicate the current communication protocol. This encoding can be implemented, for example, by a high and / or low level on the internal communication bus. The device can include an interface for communication with the internal communication bus.
[0012] The default communication protocol can be, for example, OBD-2 or UDS. However, other communication protocols are also possible. The default communication protocol can be set at the factory, for example, by storing it in the ECU's memory. Which communication protocol is set as the default may be dictated by country-specific regulations. The default communication protocol can also be set at a vehicle manufacturer's plant, for example, at the end of the assembly line, i.e., shortly before the vehicle is completed.
[0013] It should be noted that a communication protocol other than the standard communication protocol can also be used for vehicle diagnostics. This alternative communication protocol can be used, for example, when the target communication protocol signals its use. By receiving the target communication protocol, the system can switch between a standard communication protocol, such as OBD-2, and the target communication protocol, such as OBD-on-UDS. This switch can be registered by adjusting the counter. This will be explained in more detail below.
[0014] The external signal can be generated and provided, for example, by an external diagnostic device. Receiving the external signal can occur, for example, via another communication bus, such as CAN, a K-bus, and / or an L-bus. Receiving the external signal can, for example, be done as part of vehicle diagnostics. The external signal can include an encoding to signal the target communication protocol. The external signal can also include a further encoding to signal the write operation. The encoding and / or further encoding of the external signal can be implemented, for example, by a high and / or low level on the other communication bus. The device can include an interface for communication with the other communication bus.
[0015] The target communication protocol can be set by the external diagnostic device or selected by a user of the diagnostic device from several possible communication protocols. The target communication protocol could be, for example, OBD-2 or UDS. However, other communication protocols are also possible. Which communication protocol is set or selected as the target communication protocol may be specified, for example, by country-specific regulations.
[0016] The vehicle diagnostic output can include a comparison of the external signal with the internal signal. For example, it can be checked whether the encoding of the internal signal matches the encoding of the external signal. The output can also include the authorization of at least one write and / or read operation. This can be achieved, for example, by generating an output signal.
[0017] In a write operation, for example, a fault memory or the memory of a control unit can be erased and rewritten. The write operation can include, for example, setting the target communication protocol as the actual communication protocol. This setting of the target communication protocol as the actual communication protocol can also be referred to as switching the communication protocol. The target communication protocol can be stored, for example, in the memory of the device and / or the vehicle. To save the target communication protocol as the actual communication protocol, the external signal must indicate at least one memory value. The write operation can, for example, be used to teach a newly installed or replaced control unit. The device or the vehicle can include the fault memory, the control unit, and / or the memory of the control unit.
[0018] Alternatively or cumulatively, the external signal can indicate a read operation, e.g., to read the error memory. The external signal can contain additional encoding that signals the read operation.
[0019] The counter can be updated by receiving an external signal or by a write operation. Updating the counter can be done, for example, by adding or subtracting at least one counter value from the current counter reading. This process can therefore be described as incrementing or decrementing. The counter value can be an integer, such as "1". The counter can be implemented on a microcontroller within the device.
[0020] By adjusting the counter, it is particularly possible to register every switch between multiple available communication protocols.
[0021] The error message can be generated by the device, for example. The error message can be stored in the vehicle's fault memory, for example. The error message can trigger the engine warning light to illuminate. For example, the engine warning light can remain illuminated if the counter exceeds the threshold for the permissible number of write operations. The threshold can be a maximum value. Exceeding the maximum value can be described as exceeding it. The maximum value can be an integer, for example, "5". The maximum value can be known in advance. In particular, no further vehicle diagnostics output can be generated if the counter exceeds the maximum value for the permissible number of write operations. Furthermore, a write operation can no longer be permitted if the counter exceeds the maximum value for the permissible number of write operations. Alternatively, the threshold can also be a minimum value.Passing the minimum value can be described as falling below it.
[0022] It should be noted that providing the internal signal and / or outputting the vehicle diagnostics can be optional features of the proposed procedure. The essential point is that the write operations are counted by receiving the external signal and the error message is generated depending on the counter value.
[0023] In another embodiment, the actual communication protocol and / or target communication protocol is OBDonUDS or ZEVonUDS. These communication protocols require a particularly high level of security for vehicle diagnostics, which is provided by the present invention. This is because, compared to conventional communication protocols, OBDonUDS or ZEVonUDS allow write operations that can result in particularly profound changes to the vehicle's fault memory and control units.
[0024] In another embodiment, the at least one external signal is received via at least one vehicle diagnostics interface. This allows the external signal to be received, for example, as part of a vehicle diagnostics check. This simplifies the output of the vehicle diagnostics, as no additional interface is required to receive the external signal. The device can include the at least one vehicle diagnostics interface. This interface can, for example, be an OBD-II port.
[0025] In one embodiment, the at least one write operation only occurs if the external signal has been verified beforehand. This further increases the security of vehicle diagnostics, as no write and / or read operations can be permitted without verification. The at least one external signal can, for example, signal a verification key. For this purpose, the external signal can have an additional encoding. Conversely, the internal signal can signal a lock for the verification key. For this purpose, the internal signal can also have an additional encoding. It is also possible that another external signal signals the verification key and / or another internal signal signals the lock. The at least one additional external signal can, for example, be provided by the diagnostic device. The at least one additional internal signal can, for example,The external signal can be provided by the device or the vehicle. The external signal can be verified when the verification key opens the lock. The device can be configured to verify the received external signal. The verification key corresponding to the lock can, for example, be generated by a vehicle manufacturer and provided to an authorized diagnostic service provider. For this purpose, the vehicle and the external diagnostic device can communicate with an external server of the manufacturer. This ensures that only authorized diagnostic service providers receive write access. A possible verification method is, for example, SFD-Basic or SFD Level 2.
[0026] In one embodiment, the counter is stored on at least one memory, wherein the at least one memory is not writable by the at least one external signal. This ensures that the counter is not reset by the external signal. The device can include the memory. The memory is, in particular, non-volatile memory, so that the counter cannot be reset, for example, by switching off the device or the vehicle. The memory can, for example, be flash memory.
[0027] In one embodiment, the counter is reset when at least one memory chip is flashed. This allows the counter to be reset safely while simultaneously flashing new software or firmware. The counter can, for example, be reset to a predefined reset value. This reset value could be, for example, "0" or "1" or any other counter value. Resetting the counter can, in particular, clear the error message generated when the threshold is exceeded.
[0028] In one embodiment, the counter is reset when at least one verified reset signal is received. This allows the counter to be reliably reset as needed. The reset signal can be provided, received, and verified analogously to the external signal, mutatis mutandis. Alternatively, the reset signal can be provided, received, and verified by the device itself.
[0029] In one embodiment, at least one additional error message is generated if the target communication protocol does not match the actual communication protocol. This allows the system to detect that the received target protocol does not correspond to the actual protocol. The additional error message can, for example, be stored in the vehicle's fault memory.
[0030] The invention is explained in more detail using exemplary embodiments. The figures show: Fig. 1 a schematic representation of an embodiment of a vehicle with a device for vehicle diagnostics and Fig. 2 a schematic representation of another embodiment of a vehicle with a device for vehicle diagnostics.
[0031] In the following, identical reference symbols denote elements with the same technical characteristics.
[0032] Fig. Figure 1 shows a schematic representation of an embodiment of a vehicle 200 designed as a passenger car with a device 100 for vehicle diagnostics. The device 100 has a microcontroller (not shown) and is configured to perform a method for vehicle diagnostics. The method comprises the steps described below.
[0033] In step S1, an internal signal 10 is provided. This internal signal 10 is generated, for example, by a control unit 210 of the vehicle 200. The control unit 210 could, for example, be the engine control unit of the vehicle 200. The internal signal 10 is communicated via an internal communication bus 220 of the vehicle 200, configured as a CAN bus, to an interface 11 of the device 100. The internal signal 10 indicates a current communication protocol for vehicle diagnostics, for example, OBDonUDS. The current communication protocol may have been factory-defined for the vehicle 200 and may be permanently stored, for example, in a memory (not shown) of the control unit 210. However, at least one other communication protocol besides the current communication protocol may be stored in the memory of the control unit 210 and / or in another memory (not shown).The other communication protocol only replaces the current communication protocol when this is specified by a target communication protocol.
[0034] For vehicle diagnostics, an external diagnostic device 300 is connected to a diagnostic interface 230 of the vehicle 200, which is configured as an OBD-2 port. The external diagnostic device 300 can also be referred to as a tester. Vehicle diagnostics can be performed, in particular, by a government authority—such as the police—of the country in which the vehicle 200 is registered, or by a service center. The external diagnostic device 300 can be verified, for example, by the manufacturer of the vehicle 200. For this purpose, a verification key 420 can be provided to the external diagnostic device 300 via an external server 400 of the manufacturer. Simultaneously, a lock symbol 410 can be provided to the control unit 210 of the vehicle 200 via the external server 400 for verification purposes.
[0035] An external signal 20 can be generated by the external diagnostic device 300 and provided via a further communication bus 240 of the vehicle 200, configured as a K-bus. The external signal 20 indicates a target communication protocol for vehicle diagnostics, e.g., OBDonUDS. For verification purposes, the external signal 20 can be encoded with the verification key 420. The internal signal 10, on the other hand, can be encoded by the control unit 210 with the lock 410 for this purpose.
[0036] Additionally, the external signal 20 can also signal a write operation. This write operation can, for example, result in the deletion of a fault memory 250 of the vehicle and / or switch the actual communication protocol to the target communication protocol. Alternatively or cumulatively, the external signal 20 can, of course, also signal a read operation. This read operation can, for example, result in the reading of the fault memory 250 of the vehicle.
[0037] In step S2, the external signal 20 is received via an interface 21 of the device 100.
[0038] In step S3, vehicle diagnostics are output if the actual communication protocol matches the target communication protocol. For example, the encoding of the internal signal 10 is compared with the encoding of the external signal 20. The external signal 20 can be further verified in step S3 (not shown) by checking whether the verification key 420 opens the lock 410. If the communication protocols match and the external signal 30 is verified, the result of step S3 is "Yes". In this case, the device 100 can generate an output signal 30 and communicate with the diagnostic interface 230 via the further communication bus 240.
[0039] Alternatively, in step S3, the vehicle diagnostics can be output using the actual communication protocol if the actual communication protocol does not match the target communication protocol.
[0040] If, however, the target communication protocol does not match the actual communication protocol, the result of step S3 is "No". In this case, device 100 can generate an error message 55 and output it via interface 12. The error message 55 is then communicated, for example, via the internal communication bus 220 to the error memory 250 and stored there. In this way, attempts to communicate with vehicle 200 using a different communication protocol than the actual communication protocol can be registered.
[0041] In step S4, a computer-implemented counter 40 can be incremented. This includes a substep S41, in which it is checked whether the external signal 20 signals the write operation. This is in Fig. 1 is indicated by a pen and a piece of paper. For verification, for example, a further encoding of the external signal 20 can be compared with an encoding known for permissible write operations. If the external signal 20 signals a write operation, the result of sub-step S41 is "Yes". In a further sub-step S42, the counter 40 is then incremented by the integer "+1". For example, the counter value of counter 40 increases from the counter value "4" to the counter value "5", since four permissible write operations have already been counted during previous vehicle diagnostics. If the external signal 20 does not signal a write operation, the result of sub-step S42 is "No", and the counter 40 is not incremented in the further sub-step S42. This is in Fig. 1 is marked by a “+0”. This allows the signaled write operations to be recorded.
[0042] Alternatively, in step S4 the counter can be decremented by 40 (not shown) and, for example, counted down from a starting value to a minimum value until the minimum value is undershot.
[0043] The reading of counter 40 can be permanently stored in a flash memory 60. The flash memory 60 cannot be written to by the external signal 20. This means that the flash memory 60 cannot be erased or modified by the external signal 20. Therefore, counter 40 cannot be manipulated by the external signal 20.
[0044] In step S5, an error message 50 is generated if the counter 40 exceeds a maximum value 45 for a permissible number of write operations. For this purpose, the current counter value of counter 40 is provided from memory 60. Alternatively or cumulatively, the current counter value can be provided from a working memory of the device 100 (not shown). The maximum value 45 can be, for example, "4". Of course, step S5 can alternatively include checking whether the counter 40 is greater than or equal to the maximum value 45 for a permissible number of write operations. In such a case, the maximum value 45 would be "5". In the Fig. In the embodiment shown in Figure 1, if the counter 40 exceeds the maximum value 45, the result of step S5 is "Yes" and error message 50 is generated. If, however, the counter 40 does not exceed the maximum value 45, the result of step S5 is "No" and the process can terminate at this point.
[0045] The generated error message 50 can be output via an interface 13 of the device 100. The error message 50 is then communicated, for example, via the internal communication bus 220 to the fault memory 250 and stored there. In this way, an exceedance of the permissible number of write operations is registered. The error message 50 can, for example, cause the engine control light of the vehicle 200 to illuminate and display the error message 50. This is in Fig. 1 indicated by a symbol of the engine control light.
[0046] Since counter 40 is stored in memory 60 in a tamper-proof manner, error message 50 is still generated even if error memory 250 has been cleared, for example, as part of a tampering process. This makes vehicle diagnostics particularly secure.
[0047] Fig. Figure 2 shows a schematic representation of another embodiment of a vehicle 200 designed as a passenger car with a device 100 for vehicle diagnostics. In contrast to Fig. 1 is in Fig. Figure 2 shows how a counter can be reset to 40.
[0048] The current reading of meter 40 is stored on a memory 60 designed as flash memory.
[0049] A reset signal 80 can be generated, for example, by means of a diagnostic device 300 connected to the vehicle 200. The generated reset signal 80 can signal a flashing of the memory 60. The diagnostic device 300 can be verified, for example, via an external server 400 of the manufacturer. This allows the external diagnostic device 300 to encode the verified reset signal 80 with a verification key 420.
[0050] The device 100 can receive the reset signal 80 via an interface 21.
[0051] The device 100 can be configured to verify the received reset signal 80 in step S6. For verification purposes, a further signal 70, encoded with a lock 410, can be generated by a control unit 210 of the vehicle 200 and provided to the device 100 via an interface 11. In step S6, it can be checked, for example, whether the encoding of the received reset signal 80 matches the encoding of the further signal 70. If this is the case, the result of step S6 is "Yes". In this case, the memory 60 can be flashed using the reset signal 80, and, for example, new firmware can be uploaded to the device 100.
[0052] By flashing memory 60, counter 40 is reset to a value of 0.
[0053] If, however, the result of step S6 is "No"—i.e., the encoding of the received reset signal 80 does not match the encoding of the subsequent signal 70—the device 100 can generate a further error message 56 and output it via an interface 12. This further error message 56 is then communicated, for example, via an internal communication bus 220 to a fault memory 250 of the vehicle 200 and stored there. In this way, unverified reset attempts can be registered.
[0054] Furthermore, the reset signal 80 can also be used to change the permissible number of write operations. For example, a maximum value of 45 stored in memory 60 can be adjusted from "4" to "2". This can be useful if, for example, stricter legal regulations restrict the number of write operations to two instead of four. Other internal or external signals (not shown) can also be used to adjust the maximum value. Reference symbol list 10 internal signal 11 to 13 Interface for communication with an internal communication bus 20 external signal 21 the interface for communication with another communication bus 30 Output signal 40 counters 45 maximum value 50 error messages 55 more error messages 56 more error messages 60 storage 70 more signals 80 Reset signal 100 Device 200 vehicles 210 Control unit 220 internal communication bus 230 Interface for vehicle diagnostics 240 additional communication buses 250 fault memory 300 diagnostic device 400 external servers 410 Lock for verification 420 verification keys S1 step S2 step S3 step S4 step S41 Substep S42 Substep S5 step S6 step
Citation Information
Patent Citations
Method for operating an control device network for operating an external interface
DE102015210534A1
SURVEILLANCE DEVICE AND SURVEILLANCE PROCEDURES
DE102023103170A1