Method and device for securing safety-relevant instructions of diagnostic testers for control units
The method and device secure diagnostic instructions by requiring security codes and error counters to prevent unauthorized access to non-volatile memory, addressing the risk of unintended deletion and manipulation in control units, thus enhancing system safety.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2026-04-23
AI Technical Summary
Unintended deletion or manipulation of safety-critical information in non-volatile memory of control units due to faulty software or hardware errors during diagnostic procedures poses a risk to technical systems, potentially violating safety objectives.
A method and device that require a security code to be transmitted with diagnostic instructions for accessing non-volatile memory, ensuring the instructions are valid before execution, and include error counters to prevent unauthorized access.
Ensures secure and authorized execution of diagnostic instructions, preventing unintended or malicious deletion of safety-relevant memory areas, thereby enhancing system safety.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The invention relates to control units and the possibility of sending and executing diagnostic instructions to the control unit using a diagnostic tester. The invention further relates to protecting safety-relevant information in control units against faulty, unwanted, and manipulative instructions. Technical background
[0002] Modern control units use non-volatile memory, such as EEPROMs, to permanently store safety-critical information in technical systems, such as restart lock information in fuel cell control units or hydrogen supply control units. An unintended reset or deletion of this safety-critical information due to systematic software errors or random hardware failures could therefore violate safety objectives and subsequently lead to failures or damage to the technical system.
[0003] However, diagnosing the control unit using a diagnostic tester, for example in a workshop or during maintenance, also requires a procedure to reset, overwrite, or delete the non-volatile memory or a portion thereof. This poses a risk that safety-relevant memory areas could be unintentionally deleted.
[0004] Therefore, diagnostic instructions are also provided for a diagnostic tester, which trigger such an operation.
[0005] Software or hardware errors in the control unit lead to incorrect execution of diagnostic instructions, even though the instructions received from the diagnostic tester were correct (e.g., unnecessary execution of a deletion instruction even though no such request was made by the diagnostic tester, incorrect forwarding of a deletion command if, for example, the actual request did not concern safety-critical information, but the control unit forwarded the request as safety-critical information).
[0006] To prevent at least one area of the non-volatile memory from being unintentionally or maliciously deleted due to faulty software or hardware in the diagnostic tester / control unit or due to a diagnostic instruction sent to the control unit, a procedure for additional security or protection against unwanted access is therefore necessary. Disclosure of the invention
[0007] According to the invention, a method for securing a diagnostic instruction by which a memory area of a non-volatile memory is erased or overwritten is provided according to claim 1, as well as a corresponding device according to the dependent claim.
[0008] Further details are specified in the dependent claims.
[0009] According to a first aspect, a computer-implemented method for securing memory access to a memory area of non-volatile memory in a control unit of a technical system by means of a diagnostic instruction, in particular a diagnostic tester, which causes an overwriting or deletion of the memory area, is provided, comprising the following steps: - Receiving a specific diagnostic instruction indicating access to write or erase the memory area of the non-volatile memory, especially from a diagnostic tester; - Receiving or expecting to receive a security code associated with the diagnostic information; - If it is determined that the received security code matches one of the security codes associated with the specific diagnostic information, execute the specific diagnostic instruction.
[0010] In particular, the security code can be recognized as being associated with the specific diagnostic instruction if it is received promptly or simultaneously.
[0011] According to the above procedure, securing a diagnostic instruction that causes an overwrite or deletion of a memory area of a non-volatile memory in a control unit is only permitted if a security code is also transmitted along with the diagnostic instruction.
[0012] The security code is transmitted to the control unit in close proximity to, or simultaneously with, the diagnostic instruction. It is specifically tailored to that instruction and identifies it as valid, or invalid if the security code is incorrect. If the transmitted diagnostic instruction lacks the necessary security code to instruct the control unit to erase or overwrite a memory area of non-volatile memory, the corresponding diagnostic instruction is not executed.
[0013] If it is determined that the received security code does not match a security code associated with the specific diagnostic information, or if no security code associated with the specific diagnostic instruction is received, the execution of the specific diagnostic instruction may be blocked.
[0014] It may be provided that if it is determined that the received security code does not correspond to a security code assigned to the specific diagnostic information, or if no security code assigned to the specific diagnostic instruction is received, an error counter is incremented.
[0015] In particular, if it is determined that the value of the error counter has reached a predetermined threshold, the execution of any received diagnostic instruction can be blocked.
[0016] Alternatively, if it is determined that the error counter value has reached a predetermined threshold, the error counter value can be transmitted to a diagnostic tester.
[0017] It may also be possible to increment a fault counter if a valid security code for a diagnostic instruction is not present. If the fault counter value in the control unit exceeds a predefined maximum value, the control unit, if configured accordingly, may block or prevent the execution of diagnostic instructions that involve accessing non-volatile memory. Alternatively or additionally, the fault counter value can be transmitted to the diagnostic tester, preventing it from sending further attempts to write or erase a diagnostic instruction to the non-volatile memory.
[0018] Furthermore, it may be provided that the specific diagnostic instruction is only executed if the control unit is in one of at least one predefined operating mode.
[0019] This allows the system to check, either during or after receiving a diagnostic instruction, whether the control unit is in an authorized operating mode. If this is not the case, the specific diagnostic instruction will not be executed; that is, the specific diagnostic instruction will only be executed if an authorized operating mode and a security code associated with the diagnostic instruction are present.
[0020] It can be provided that several diagnostic instructions are each assigned a different security code, with the different security codes being chosen such that they have a minimal Hamming distance to each other.
[0021] Furthermore, it may be provided that a different security code is assigned to each of the numerous diagnostic instructions relating to non-volatile memory. These different security codes can be chosen to have a minimum Hamming distance between the valid security codes in order to ensure protection against a specific number of bit errors.
[0022] The required Hamming distance is determined based on the ASIL rating of the safety objective / safety mechanism according to the automotive functional safety standard ISO 26262 (each ASIL requires a specific Hamming distance to achieve the corresponding diagnostic coverage). If safety coverage is required for multiple safety-related diagnostic test interventions associated with different safety objectives (with different ASIL ratings), the highest ASIL rating among the relevant safety objectives is used to determine the Hamming distance. Brief description of the drawings
[0023] The embodiments are explained in more detail below with reference to the accompanying drawings. These show: Fig. 1 a schematic representation of a test environment in which a diagnostic tester is connected to a control unit; and Fig. 2. A flowchart illustrating a procedure for securing access to non-volatile memory in the control unit by the diagnostic tester. Description of embodiments
[0024] Fig. Figure 1 shows a schematic representation of a test environment 1 with a diagnostic tester 2 and a control unit 3 of a technical system. The diagnostic tester 2 is connected to the control unit 3 via a suitable data communication link 4.
[0025] To diagnose the functions of control unit 3, the diagnostic tester 2 can send specific diagnostic instructions to control unit 3 and receive resulting responses from control unit 3. The responses from control unit 3 contain information that allows the diagnostic tester 2 to determine, in a known manner, whether control unit 3 is operating correctly or incorrectly, or to read entries from a fault memory 31 of control unit 3 in order to analyze any faults that have occurred.
[0026] The control unit 3 further comprises a processing unit 32 for executing program code, a program memory 33 for storing the program code, and a non-volatile memory 34, such as an EEPROM, in which operationally relevant and safety-critical data for the operation of the technical system are stored. The program memory 33 contains the program code for all procedures executed in the control unit 3, including a procedure for communication with the diagnostic tester 2 for evaluating diagnostic instructions and providing corresponding responses to the diagnostic tester 2.
[0027] The control unit 2 can be a control unit for any technical system, such as for a vehicle, for a fuel cell system or the like, where the diagnostic tester 2 can be a portable device that can be connected to the technical system at its location.
[0028] To perform a diagnosis, the diagnostic tester sends 2 diagnostic instructions to the control unit 3. These diagnostic instructions may also include instructions that access the non-volatile memory 34, overwrite memory areas there, or delete them.
[0029] To prevent unauthorized, erroneous, or malicious access to the non-volatile storage, the following is based on the method described in Fig. The flowchart shown in Figure 2 illustrates a procedure executed in the control unit 3 that prevents such erroneous accesses to the non-volatile memory 34. This is further explained below using the following diagram. Fig. The two described methods can be implemented in the control unit as software and / or hardware.
[0030] In step S1, a diagnostic instruction is first received from the connected diagnostic tester 2.
[0031] In step S2, it is checked whether the received diagnostic information involves an overwriting or deletion access to a memory area of non-volatile memory 34 and thus corresponds to a specific diagnostic instruction. If this is the case (alternative: Yes), the procedure continues with step S3; otherwise (alternative: No), the procedure continues with step S10.
[0032] In step S3, it is checked whether one of the security codes assigned to a specific diagnostic instruction has been received by diagnostic tester 2. If this is the case (alternative: Yes), the procedure continues with step S4; otherwise (alternative: No), the procedure continues with step S11.
[0033] In step S4, it is checked whether the security code matches a valid security code, which may be stored, for example, in a suitable lookup table depending on the specific diagnostic instruction. If this is the case (alternative: Yes), the procedure continues with step S5; otherwise, the procedure continues with step S11.
[0034] In step S5, it is further checked whether an operating mode of control unit 3 allows the execution of the received diagnostic instruction. Such an operating mode might, for example, indicate that the vehicle is stationary, that the accelerator or brake pedal is not depressed, that the gear selector is in neutral, or similar conditions, in the case of a vehicle control unit. Control units for special technical systems, such as fuel cell systems, might, for example, require an operating mode for the execution of the diagnostic instruction in which the actuators, such as an anode shut-off valve or anode fan, are switched off, or similar conditions.
[0035] If an operating mode exists in which access by the diagnostic tester 2 is permitted (alternative: Yes), the procedure continues with step S10 and the specified diagnostic instruction is executed. Otherwise (alternative: No), the procedure continues with step S11.
[0036] In step S10, the specific diagnostic instruction is executed and a corresponding response is transmitted to the diagnostic tester 2.
[0037] In step S12, the diagnostic instruction is ignored or suppressed.
[0038] In step S11, an error can be signaled and / or an error counter incremented, and either made available for retrieval by diagnostic tester 2 or transmitted directly to the diagnostic tester. If, in step S12, it is determined that a predefined maximum number of errors has occurred (alternative: Yes), the procedure can be terminated and any further diagnostic instructions from the diagnostic tester ignored to prevent malicious manipulation attempts by an unauthorized user. This also prevents repeated access to safety-relevant memory areas due to hardware and software errors in the control unit. Otherwise (alternative: No), the procedure continues without executing the last received diagnostic instruction.
[0039] It may be provided that 34 different security codes can be used for accessing different memory areas of the non-volatile memory. These security codes can be chosen to meet a minimum Hamming distance criterion in order to ensure protection against a number of bit errors.
Claims
[1] Computer-implemented method for securing a memory access to a memory area of a non-volatile memory (34) in a control unit (3) of a technical system, which causes an overwriting or deletion of the memory area (34), comprising the following steps: - Receiving (S1) a specific diagnostic instruction indicating access to write or erase the memory area of the non-volatile memory (34), in particular from a diagnostic tester (2); - Receiving (S3) or expecting to receive a security code associated with the diagnostic information; - If it is determined (S4) that the received security code matches one of the security codes associated with the specific diagnostic information, execute (S10) the specific diagnostic instruction. [2] Method according to claim 1, wherein the security code is recognized as being assigned to the specific diagnostic instruction when it is received promptly or simultaneously. [3] Method according to claim 1 or 2, wherein, if it is determined that the received security code does not correspond to a security code associated with the specific diagnostic information or no security code associated with the specific diagnostic instruction is received, the execution of the specific diagnostic instruction is blocked. [4] Method according to any one of claims 1 to 3, wherein, if it is determined that the received security code does not correspond to a security code assigned to the specific diagnostic information or no security code assigned to the specific diagnostic instruction is received, an error counter is incremented. [5] Method according to claim 4, wherein, when it is determined (S12) that the value of the error counter has reached a predetermined threshold, the execution of each received diagnostic instruction is blocked. [6] Method according to claim 4 or 5, wherein, when it is determined (S12) that the value of the error counter has reached a predetermined threshold, the value of the error counter is transmitted to a diagnostic tester. [7] Method according to any one of claims 1 to 6, wherein the specific diagnostic instruction is executed only when the control unit (3) is in one of at least one predetermined operating mode. [8] Method according to any one of claims 1 to 7, wherein several diagnostic instructions are each assigned different security codes, wherein the different security codes are chosen such that they have a minimal Hamming distance to each other. [9] Apparatus for carrying out one of the methods according to any one of claims 1 to 8. [10] Computer program product comprising instructions which, when the program is executed by at least one data processing device, cause it to perform the steps of the method according to any one of claims 1 to 8. [11] Machine-readable storage medium comprising instructions which, when executed by at least one data processing device, cause it to perform the steps of the method according to any one of claims 1 to 8.