TCU EXCHANGE SPITZE MODE

A cloud-based system addresses the vulnerability of TCU exchange theft by detecting and preventing unauthorized component installations, enhancing vehicle security and informing law enforcement and insurance companies.

DE102025100337A1Pending Publication Date: 2025-07-10FORD GLOBAL TECH LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE102025100337
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-10
Filing Date
2025-01-07
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing anti-theft systems for vehicles are vulnerable to theft through TCU exchange, which current methods struggle to detect, leading to increased repair costs and potential misuse of unauthorized components.

Method used

A cloud-based system that manages alerts for non-compliant vehicle controls by storing and clustering alerts from multiple vehicles, correlating locations of unauthorized component installations, and sending warnings to law enforcement or insurance companies to mitigate theft.

Benefits of technology

Enhances vehicle security by detecting unauthorized TCU exchanges, preventing vehicle operation, and providing actionable intelligence for law enforcement and insurance companies to address high-crime areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An approach for managing controller mismatch alerts is disclosed. The approach includes storing controller mismatch alerts received from a plurality of vehicles in a component database of a cloud system having one or more hardware computing devices, each of the controller mismatch alerts indicating an identifier of a current vehicle in which the controller mismatch is installed and a location of the current vehicle. The approach further includes performing clustering of the controller mismatch alerts by the cloud system to correlate the controller mismatch alerts by location.The approach further includes specifying clustered locations of alerts regarding mismatched control by the cloud system.
Need to check novelty before this filing date? Find Prior Art

Description

FIELD OF TECHNOLOGYAspects of the disclosure generally relate to telematics control unit (TCU) exchange peaking mode.BACKGROUNDAs vehicles become more powerful, networked, and valuable, thieves have updated their techniques to request existing cybersecure and physical anti-theft systems. Therefore, automobile manufacturers can take additional measures, resulting in a continued growth of new anti-theft solutions that must conform to the growing technical knowledge of thieves. In one example, a physical portion of a TCU range shield may be installed over the TCU. The shield may be installed with break-off bolts made of hardened steel. It may take 20-30 minutes to unscrew these screws, and metal chips may remain during tapping, which may introduce new problems that necessitate vehicle repair. The shield may also increase the material patch list and cost of the vehicle and may add steps for tamper-evident repair (e.g., labor and parts to install a new shield).SUMMARYIn one or more illustrative examples, a cloud system for managing alerts regarding non-compliant control includes a component database. The component database is configured to store non-matching control alerts received from a plurality of vehicles. Each of the non-matching control warnings indicates an identifier of a current vehicle in which the non-matching control is installed and a location of the current vehicle. The cloud system also includes one or more hardware computing devices. The one or more hardware computing devices are configured to perform clustering of the non-matching control alerts, to correlate the non-matching control alerts by location, and to indicate clustered locations of the non-matching control alerts.In one or more illustrative examples, a method of managing alerts to a non-consistent control is performed. The method includes storing non-matching control alerts received from a plurality of vehicles in a cloud system component database having one or more hardware computing devices, each of the non-matching control alerts indicating an identifier of a current vehicle in which the non-matching control is installed and a location of the current vehicle. The method further includes clustering the non-matching control alerts by the cloud system to correlate the non-matching control alerts by location. The method further includes indicating clustered locations of the alerts for non-consistent control by the cloud system.In one or more illustrative examples, a non-transitory computer readable medium includes instructions for managing non-compliant control alerts that, when executed by a cloud system having one or more hardware computing devices, cause the cloud system to perform operations including storing non-compliant control alerts received from a plurality of vehicles, each of the non-compliant control alerts indicating an identifier of a current vehicle in which the non-compliant control is installed and a location of the current vehicle; performing clustering of the non-compliant control alerts by the cloud system to correlate the non-compliant control alerts by location; indicating clustered locations of the alerts for non-consistent control by the cloud system, including sending data indicating the clustered locations to one or more of law enforcement agencies to mitigate areas of high crimilitity or a vehicle insurance company for use in determining insurance premiums.BRIEF DESCRIPTION OF THE DRAWINGSFIG. 1 illustrates an example system for implementing a TCU exchange peaking mode; FIG. 2A illustrates an example data flow for providing a control identifier to a component database managed by the cloud server configuration manager; FIG. 2B illustrates an alternative example data flow for providing a control identifier to the component database managed by the cloud server configuration manager; FIG. 3 illustrates an example process for validating alert messages by the cloud server; FIG. 4 illustrates an example process for analyzing multiple alerts for location to determine trends in alert generation; and FIG. 5 illustrates an example of a computing device for use in implementing a TCU exchange spike mode.DETAILED DESCRIPTIONAs required, detailed embodiments of the present invention are disclosed herein; however, it is to be understood that the disclosed embodiments are merely exemplary of the invention that may be embodied in various and alternative forms. The figures are not necessarily to scale; some features may be greatly exaggerated or minimized to show details of specific components. Therefore, specific structural and functional details disclosed herein are not to be interpreted as limiting, but merely as a representative basis for teaching one skilled in the art to variously employ the present invention.A scheme for mutual authentication between a TCU and a vehicle powertrain control module (PCM) may be used to detect and prevent tampering with a vehicle. If a TCU tampering is detected, the system may prevent internal combustion engine (ICE) start or electric vehicle (EV) torque availability. This tampering detection may include detection of one or more issues such as the TCU antenna being disconnected, the TCU antenna being affected by shielding (e.g., substantial loss of signal strength being detected), the TCU back-up battery (BUB) being removed, the TCU fuse being pulled, and / or the TCU module itself being removed. However, the system may not be able to detect a TCU exchange when these methods have been shut down.Some of the above TCU states may occur for reasons other than a TCU attack. Thus, an engine mitigation approach may convert a low severity loss of one or more connectivity functions to a high severity primary vehicle function. For example, an improperly mounted TCU connector or coax connector may result in loss of connectivity features, which would also become a major problem due to loss of vehicle mobility and potentially higher repair costs. It may also appear random or intermittent to the customer and service technician and could create additional unnecessary repairs and customer discomfort.One challenge with removal & replacement (R&R) detection systems is that when the TCU R&R theft technique is performed with an electronic control unit (ECU) that is valid for that vehicle age, the system may not be able to detect the changed TCU. One approach to combat R&R theft methods is to pair the TCU with a plurality of vehicle modules or controllers (e.g., three or four controllers) using mutual authentication. Such an approach may require each of the controllers to mutually identify to enable start-up or other function. Such an approach is more difficult to overcome, but does not solve the problem, since a malicious user can replace all of the modules if they are given enough time. Or, the malicious user may use a tow car to bring the vehicle to a more private area and to replace the parts to restore the vehicle to an operational state for sale.An improved approach may be implemented by the vehicle to alleviate issues with TCUzu control verification strategies. The approach may be implemented by the TCU and / or the PCM or any other modules added to the mutual authentication. The approach may store a history of the vehicle identification number (FIN) of any vehicle in which it / it was operating and optionally the last installation date. Even if a malicious user installs valid old hardware for R&R based theft in the vehicle, this improved approach can detect the mismatch and can use the malicious user's own TCU to send a message to the original equipment manufacturer (OEM) or other party to assist him or her in restoring the vehicle.It may be possible for a malicious user to read a FIN from the targeted vehicle and use that FIN to reprogram the R&R parts before performing the R&R theft. However, the installation records for the vehicle would not match the OEM history records. Up to this date, there would be a record installation date for a TCU and / or a PCM of the vehicle that would not match the R&R event being performed (e.g., without involvement of the dealer or shop that would have updated the history records).In response to the system detecting that starting function components have been replaced with components unauthorized for the specific vehicle, the TCU may send a warning (e.g., to a cloud server) that extraneous vehicle components have been detected. This information may include an identification of such components as well as an identifier of the original vehicle (e.g., FIN), or that the component was in maintenance inventory and was never installed in a vehicle. The current location of the vehicle may also be included, as well as the ability to continue to collect location information for the next day or other predefined time periods, similar to early theft warnings.Thus, in response to identifying that the foreign components have been installed in the vehicle, the vehicle may be locked and / or disabled from movement. Additionally, a warning may be sent from the vehicle to a cloud server. Some examples where this alert may be utilized are anti-theft packages for retail vehicles and for fleets as part of owner alerts. Providing such alarms may also be useful for retrieving and discovering additional vehicles that may also have been carried along or modified. The alerts may also be useful to insurance companies to determine premiums for different locations. In some examples, a database for different OEMs or other entities may be created to collect the alerts and help catch malicious users who steal different vehicles at similar locations. The location may accordingly be used to understand the patterns during theft and location susceptibility.In some examples, a override option may also be placed in the application account of the vehicle owner to allow the user to override the TCU override. This may be done, for example, by a multi-factor approval process and / or by the use of security recovery issues.Thus, the system can be better immunized against parts change by placing an element of the safety system outside the vehicle. Additionally, by intelligentizing the TCU to request permission to be in the selected vehicle based on style information and not just the age of a part, the ability to ensure original and / or correct spare parts are used in the vehicle is enhanced.FIG. 1 illustrates an example control system 100 for implementing a TCU exchange spike mode. As shown, the control system 100 includes a vehicle 102. The vehicle 102 includes a plurality of starting function controllers 104 and a TCU 106. Each of the start function controllers 104 and the TCU 106 may be assigned a respective unique controller identifier 108 and may be associated with the FIN of the vehicle 102. The TCU 106 and the start function controllers 104 may be in communication with a gateway controller 112 via various vehicle buses 110. The TCU 106 may use a wireless transceiver 114 to communicate these controller identifiers 108 and other information over a communication network 116. In other examples, the gateway controller 112 may utilize the services of a mobile device 118 for communication over the communication network 116. A cloud server 120 may be connected to the communication network 116 and may host a configuration manager 122 and a component database 124. The gateway controller 112 may be configured to validate that the controller identifiers 108 of the start function controllers 104 and the TCU 106 match the expected configuration of the vehicle 102. In cases where the configuration does not match, the gateway controller 112 may send a non-matching control alert 126 to the cloud server 120 via the communication network 116. Although an example system 100 is shown in FIG. 1, the example components illustrated are not intended to be limiting. Indeed, the system 100 may include more or fewer components and additional or alternative components and / or implementations may be used.The vehicle 102 may include various types of motor vehicles, crossover utility vehicle (CUV), sport utility vehicle (SUV), trucks, recreational vehicles (RV), boats, airplanes, or other mobile machines for transporting people or goods. In many cases, the vehicle 102 may be powered by an internal combustion engine. As another possibility, the vehicle 102 may be a hybrid electric vehicle (HEV) powered by both an internal combustion engine and one or more electric motors. In another example, the vehicle 102 may be a pure electric vehicle powered solely by electric motors. For registration purposes, inventory purposes, and other purposes, vehicles 102 may be associated with unique identifiers, such as FINs, e.g., as defined by International Organization for Standardization (ISO) 3779 and ISO 4030.The vehicle 102 may include a plurality of controllers configured to perform and manage various functions of the vehicle 102. In particular, these controllers may include, among other things, one or more starting function controllers 104. As mentioned herein, the start function controllers 104 refer to a subset of components of the vehicle 102 that are validated before allowing the vehicle 102 to be started. In an example, the start function controllers 104 may include one or more of the PCM, a body control module (BCM), an anti-lock brake system (ABS) controller, and the TCU 106. In another example, the launch function controllers 104 may include a motion subsystem that includes a combined BCM / PCM / ABS launch function controller 104.As depicted, the launch function controllers 104 are shown as discrete components. However, the launch function controllers 104 may share physical hardware, firmware, and / or software such that the functionality of multiple launch function controllers 104 may be integrated into a single launch function controller 104 or distributed among a plurality of controllers 104. The vehicle launch function controllers 104 may include various components configured to receive updates of associated software, firmware, or configuration settings.The TCU 106 may be configured to provide telematics services to the vehicle 102. These services may include, as some non-limiting possibilities, navigation, turn-by-turn directions, vehicle state messages, local enterprise search, accident message, and hands-free calling.The controller identifiers 108 may refer to unique identifiers assigned to the starting function controllers 104 and the TCU 106 when the starting function controller 104 and the TCU 106 are produced. Each start function controller 104 and TCU 106 may be assigned a unique, different controller identifier 108. For example, each of the starting function controllers 104 and TCUs 106 may be assigned an electronic serial number (ESN) when the starting function controller 104 is built.The TCU 106 may be configured to utilize a wireless transceiver 114 to communicate with a communication network 116. The communication network 116 may provide communication services to devices connected to the communication network 116, such as packet switched network services (e.g., Internet access, voice over Internet Protocol (VoIP) communication services). For example, the TCU 106 may access the communication network 116 via a connection to one or more cell towers. To facilitate communication over the communication network 116, the TCU 106 may be associated with unique device identifiers (e.g., mobile device numbers (MDNs), Internet Protocol (IP) addresses, etc.) to identify that communication of the TCU 106 over the communication network 116 is associated with the vehicle 102.The TCU 106 may include network hardware configured to facilitate communication between the vehicle 102 and other devices of the system 100. For example, the TCU 106 may include or otherwise access a wireless transceiver 114 configured to facilitate communication with other vehicles 102 or with infrastructure. The TCU 106 may accordingly be configured to communicate over different protocols over a communication network 116 via a network protocol (such as Uu, user-to-user, user-to-user). The TCU 106 may additionally be configured to communicate via a peer-to-peer transmission protocol (such as PC5) to facilitate cellular vehicle-to-everything (C-V2X) communication with devices such as other vehicles 102. It should be noted that these protocols are merely examples and other wireless, peer-to-peer, and / or cellular technologies may be used for vehicle-to-vehicle communication. To name a few other examples, BLUETOOTH, Ultra Wide Band (UWB), and / or WiFi communication may be performed between the vehicles 102.The vehicle buses 110 may include various communication methods available between the start function controllers 104. The vehicle buses 110 may also support communication between the gateway controller 112, the TCU 106, and the start function controllers 104. These vehicle buses 110 may be implemented as a series of wiring segments. For example, a vehicle bus 110 may include a plurality of wiring segments from the gateway controller 112 to a terminal. As some non-limiting examples, the vehicle bus 110 may be a controller area network (CAN) of the vehicle, an Ethernet network, or a media oriented system transfer (MOST) network. The CAN network or networks may be of various types, including, but not limited to, high speed CAN (HS-CAN) having a data capacity of up to 500 kbit / s, mid-speed CAN (MS-CAN) having a data capacity of up to 125 kbit / s, and / or flexible data rate CAN (FD-CAN) having a data capacity of up to 2,000 kbit / s or more. It should be noted that the illustrated bus topology is merely an example and a different number and different arrangements of vehicle buses 110 may be used.The gateway controller 112 may be configured to provide an electrical interface between the vehicle buses 110 that is used to communicate within the vehicle 102. In one example, the gateway controller 112 may be configured to route signals from one CAN bus to another CAN bus. In another example, the gateway controller 112 may be configured to translate signals and commands between the CAN and / or the in-vehicle Ethernet vehicle buses 110 connected to the gateway controller 112. The gateway controller 112 may also implement other functions, such as a user interface between the vehicle 102 and the brought smartphone or other mobile device 118 of the user.The gateway controller 112 may be further configured to support computational functionality to support message traffic in the CAN area of the vehicle 102. The gateway controller 112 may be configured to route information between the various vehicle buses 110 connected to the gateway controller 112. The gateway controller 112 may include software code programmed to support the configuration verification functionality discussed in detail herein.The gateway controller 112 may be configured to store the controller identifiers 108 of the starting function controllers 104 of the vehicle 102. For example, each of the starting function controllers 104 may be assigned to an ESN when the starting function controller 104 is built. This ESN may serve as a unique identifier of the start function controllers 104. In another example, the controller identifiers 108 may include the original FIN of the vehicle 102 for which the launch function controller 104 was originally built to be installed therein. This original FIN and / or ESN may / may be flashed into non-volatile memory of the launch function controller 104 and / or TCU 106 during construction.The cloud server 120 may be an example of a networked computing device accessible to the vehicle 102 via the communication network 116. A configuration manager 122 may be an example of an application executed by the cloud server 120. The configuration manager 122 may be configured to perform one or more of the operations discussed herein, e.g., with respect to operation of the cloud server 120 for communication to and from the vehicles 102.The cloud server 120 may be configured to maintain a component database 124. The component database 124 may include information regarding the controller identifiers 108 of each of the starting function controllers 104 of the vehicles 102.The component database 124 may maintain location information related to the vehicles 102. In one approach, the cloud server 120 may receive a location of the vehicle 102 from the communication network 116. This information may be based on, for example, a home location database of the communication network 116 that retains information indicative of which cells of the communication network 116 are connected to the TCUs 106 of which vehicles 102. In another example, the vehicles 102 may report their locations to the cloud server 120, e.g., by using a global navigation satellite system (GNSS) controller of the vehicle 102 to identify the location of the vehicle 102 and send this information to the cloud server 120 by the TCU 106 via the communication network 116. Regardless of the approach, cloud server 120 may receive this location information via communication network 116 and store this information in component database 124.As mentioned above, the gateway controller 112 may be configured to validate that the controller identifiers 108 match the expected configuration of the vehicle 102. In cases where the configuration does not match, the gateway controller 112 may send a non-matching control alert 126 to the cloud server 120 via the communication network 116. For example, in the case of a replaced TCU 106, the discordant control alert 126 may specify the following information: a. TCU [ESN********] b. of original vehicle [FIN***********] c. was found in vehicle [FIN***********], d. with missing original TCU [ESN**********]Similar information may be provided in the non-matching control alert 126 to other exchanged start function controllers 104. The non-matching control alert 126 may be communicated to nearby vehicles 102 via various approaches, such as via Wi-Fi, via BLUETOOTH Low Energy (BLE), via Ultra Wide Band (UWB), while also being sent to the OEM cloud via cellular / Wi-Fi in parallel. If any current devices are connected (such as a mobile phone), these devices may also be used to send the non-matching control alert 126 to the cloud. Thus, the vehicle 102 may send the information to the OEM cloud using the TCU 106, or may use the customer's connected phone to send the information to the OEM cloud.FIG. 2A illustrates an example data flow 200A for providing a controller identifier 108 to a component database 124 managed by the configuration manager 122 of the cloud server 120. In an example, data flow 200A may be performed by the elements of system 100 discussed with respect to FIG. 1.At index (A), the gateway controller 112 requests the controller identifiers 108 in response to a start of the vehicle 102. This start may be initiated in various ways, such as in response to a user pressing the start button in the cabin of the vehicle 102, in response to the user selecting a remote start button from a key fob or phone-as-key application, etc. In one example, the gateway controller 112 may send a message requesting the controller identifiers 108 of the start function controllers 104 and the TCU 106 to the start function controllers 104 via the vehicle buses 110. These control identifiers 108 may be used to validate the configuration of the vehicle 102. The controller identifiers 108 may also include, in some examples, the FIN of the vehicle 102 for which the start function controllers 104 and / or the TCU 106 are intended to be connected. Note that in some examples, the gateway controller 112 may be activated based on start messages sent over the vehicle buses 110 from another controller (such as via the BCM, PCM, etc.). In such an example, the sending of the controller identifiers 108 may be triggered based on this other controller rather than being specifically requested by the gateway controller 112.At index (B), the gateway controller 112 receives the controller identifiers 108. This information may be received by the gateway controller 112 via the vehicle buses 110. For example, the gateway controller 112 may listen to the vehicle buses 110 to receive the controller identifier 108 to validate the configuration. The gateway controller 112 may accordingly receive the original FIN and / or ESN of the start function controllers 104 and the TCU 106 via the vehicle buses 110. The gateway controller 112 may also listen for location information indicating the current location of the vehicle 102, which may be received from a GNSS controller (regardless of whether the GNSS controller is a start function controller 104), for example, via the vehicle bus 110.At index (C), the gateway controller 112 validates the controller identifiers 108 received at index (B). For example, the gateway controller 112 may maintain a configuration of the last known valid controller identifiers 108 for the vehicle 102. Using the stored controller identifiers 108, the gateway controllers 112 may confirm that none of the start function controllers 104 or the TCU 106 has changed since the last start of the vehicle 102. For example, the gateway controller 112 may confirm that the original FINs of the start function controllers 104 and the TCU 106 match those of the gateway controller 112 and / or other components of the vehicle 102. Additionally or alternatively, the gateway controller 112 may confirm that the ESNs of the start function controllers 104 and the TCU 106 match those recorded in memory of the gateway controller 112.At index (D), if a mismatch at index (C) is detected by the gateway controller 112, the gateway controller 112 may send a non-matching control alert 126. This non-matching control alert 126 may include the ESN, FIN, and location information, as noted above. In the example shown in data flow 200A, the discontinuance 126 of non-matching control is commanded by gateway controller 112 to TCU 106.At index (E), the TCU 106 sends the non-matching control alert 126 to the cloud server 120. In essence, the non-matching control alert 126 may be sent even if the TCU 106 is the component noted as not matching the vehicle 102.At index (F), the cloud server 120 stores the information from the non-matching control alert 126 into the component database 124. Further aspects of the analysis of the component database 124 by the cloud server 120 are discussed below.FIG. 2B illustrates an alternative example data flow 200B for providing a controller identifier 108 to a component database 124 managed by the configuration manager 122 of the cloud server 120. In the alternative example data flow 200B, the operations at indices (A), (B), (C), and (F) may be performed as discussed for data flow 200A. However, unlike data flow 200A, data flow 200B at indices (D') and (E') may use mobile device 118 to send warning 126 of non-matching control, rather than using the services of TCU 106.At index (D'), the gateway controller 112 instructs the mobile device 118 to send the non-matching control alert 126 to the cloud server 120 via the communication network 116. This can be accomplished without the need for the vehicle 102 to resort to using the TCU 106. For example, if it is determined that the TCU 106 is the component not associated with the vehicle 102, a different communication path may be preferred in the event the TCU 106 is otherwise compromised. Thus, in cases where the TCU 106 is the non-compliant control, the approach of the data flow 200B may be preferred over that of the data flow 200A. Accordingly, at index (E'), the mobile device 118 forwards the non-matching control alert 126 to the cloud server 120 via the communication network 116.As another variation, the gateway controller 112 may connect to other vehicles 102, mobile devices 118, WiFi connections, etc. to send the non-matching control alerts 126. In such an approach, the vehicle 102 may use multiple channels to send the non-matching control alert 126 even if the TCU 106 has been replaced with a unit that does not provide functionality for the non-matching control alert 126.FIG. 3 illustrates an example process 300 for validating messages for alert 126 regarding non-matching control by cloud server 120. In one example, the process 300 may be performed by the cloud server 120 hosting the communication manager 122 in connection with the control system 100.At operation 302, the cloud server 120 receives a non-matching control alert 126. In one example, the discordant control alert 126 may be generated by the gateway controller 112 in response to the gateway controller 112 detecting a change in the configuration of the vehicle 102. The non-matching control may be a start function control 104 or TCU 106 of the current vehicle 102 that is validated by the current vehicle 102 before allowing the current vehicle 102 to start. As some specific possibilities, the start function controller 104 may be one or more of PCM, BCM, or ABS control. Examples of generating and sending the non-matching control alert 126 are shown in FIGS. 2A-2B.The non-matching control alert 126 may be received via the communication network 116 from the TCU 106, from the mobile device 118, and / or via a Wi-Fi communication channel from the gateway controller 112 of the vehicle 102 at the cloud server 120. Note that the warning may be sent from the vehicle 102 using the TCU 106, although the TCU 106 is the non-matching control. In another example, the non-matching control alert 126 is sent from the current vehicle 102 to the cloud system by a mobile device 118 in communication with the current vehicle 102 without using the TCU 106 of the current vehicle 102. In yet another example, the non-matching control alert 126 is sent from the current vehicle 102 to the cloud system from a Wi-Fi connection communication with the current vehicle 102 without using the TCU 106 of the current vehicle 102.The non-matching control alert 126 may include information such as the FIN of the vehicle 102, the ESN and / or associated non-matching FIN of the starting function controller 104 or TCU 106, and the ESN expected for the non-matching starting function controller 104 and / or the TCU 106. The vehicle 102 sending the non-matching control alert 126 may have been disabled by the gateway controller 112 due to the detection of the non-matching control.At operation 304, the cloud server 120 identifies a verification device to confirm the warning 126 of non-matching control. In an example, the cloud server 120 may access the component database 124, or another database or service, to identify a verification device (e.g., a mobile device 118) of a user account corresponding to the FIN of the vehicle 102 for which the non-matching control alert 126 was received. In another example, the cloud server 120 may access the component database 124, or another database or service, to identify a dealer device corresponding to a dealer or other repair facility that has performed maintenance on the vehicle 102. For example, the vehicle 102 is at a dealer or authorized shop, where the dealer may have sent a message to the cloud server 120 indicating that maintenance is being performed.At operation 306, the cloud server 120 confirms the alert 126 of non-matching control over the verification device. In an example, the cloud server 120 may send a verification message to a mobile device 118 of the user, e.g., via the user's key-function phone or other connected mobile application installed on the mobile device 118. In another example, the cloud server 120 may send the non-matching control alert 126 to the merchant device for confirmation.At operation 308, the cloud server 120 determines whether the vehicle change indicated by the non-matching control alert 126 is authorized. For example, the user may use the mobile application to confirm that the change was authorized on the vehicle 102 or indicate that the change was unauthorized. Or, the dealer may use the dealer system to confirm that the change was authorized on the vehicle 102 or indicate that the change was not authorized. If the user or dealer indicates that the change is authorized, control passes to operation 310. If not, control passes to operation 312.At operation 310, the cloud server 120 permits the non-matching control alert 126 to be authorized. For example, the configuration of the vehicle 102 in the component database 124 may be updated to include the new ECU / TCU, etc. In another example, the vehicle 102 may be re-made unable to move to enable the vehicle 102 to be used if the vehicle 102 itself has determined to be disabled from movement due to the configuration change.At operation 312, the cloud server 120 indicates that the non-matching control alert 126 is not authorized. For example, the configuration of the vehicle 102 in the component database 124 may be updated to indicate the location of the vehicle 102 at the non-matching control alert 126 as well as to keep track of the location of the vehicle 102 while in the state of the non-matching control alert 126. In another example, the vehicle 102 may be rendered non-moving by, e.g., the vehicle 102 receiving an acknowledgement from the cloud server 120 that the change is not authorized. However, in other examples, the vehicle 102 may already have been rendered unable to move by the self-check performed by the gateway controller 112. After operation 310 or 312, the process 300 ends.FIG. 4 illustrates an example process 400 for analyzing multiple non-matching control alerts 126 by location to determine trends in generating the non-matching control alert 126. In one example, process 400, such as process 300, may be performed by cloud server 120 hosting communication manager 122 in connection with control system 100.At operation 402, the cloud server 120 validates the non-matching control alert 126. In one example, these non-matching control alerts 126 are received and confirmed as discussed with respect to operation 302.At operation 404, the cloud server 120 stores the non-matching control alert 126 into the component database 124. In one example, the non-matching control alerts 126 may be stored as records in the component database 124 with fields available for retrieval, such as location of the non-matching control alert 126, FIN of the vehicle 102 sending the non-matching control alert 126, ESN of the newly found component, FIN of the newly found component, ESN of the expected component, etc. The records of the component database 124 may accordingly be configured to store non-matching control alerts 126 received from a plurality of vehicles 102, wherein each of the non-matching control alerts 126 includes an identifier of a current vehicle 102 in which the non-matching control is installed and a location of the current vehicle 102. The non-matching control alerts 126 may further include an identifier of an original vehicle 102 in which the non-matching control was previously installed. (Note that in some examples, the non-matching controller may originate from a maintenance inventory and may never have been installed in a vehicle. This could also be detected based on cloud server 120 knowing the controls in the inventory.)At operation 406, the cloud server 120 correlates the non-matching control by location alert 126. In an example, the cloud server 120 may perform clustering techniques on the location data of the records of the component database 124. This may be performed to identify common locations of the non-matching control alert 126. Example clustering techniques for clustering locations may include K-means clustering, density-based spatial clustering of noise applications (DBSCAN), hierarchical clustering, etc. In some examples, the cloud server 120 may attempt to identify the clustered locations using map data, e.g., to determine which enterprise, which parking lot, etc., is located at the clustered location.At operation 408, the cloud server 120 sends indications of the clustered locations. In one example, the locations may be sent to law enforcement agencies to examine behavior at the specified locations, e.g., to attempt to locate malicious users changing the start function controllers 104 and / or the TCU 106. In another example, the locations may be sent to insurance providers to enable updating insurance premiums near the clustered locations, e.g., to indicate the increased likelihood of theft or damage to the vehicle 102 in these areas.At operation 410, also based on the component database 124 updated at operation 404, the cloud server 120 may identify the donor vehicle 102 of the alert 126 as to a non-matching control. In one example, the non-matching control alert 126 may include information indicative of the FIN of the vehicle 102 in which the added start function controller 104 and / or TCU 106 was originally installed. Similar to operation 304, the cloud server 120 may access the component database 124, or another database or service, to identify a user account corresponding to the donor vehicle 102 FIN indicated by the non-matching control alert 126.At operation 412, the cloud server 120 sends a verification message to a mobile device 118 corresponding to the donor vehicle, e.g., via the donor vehicle user's phone with key function or another connected mobile application installed on the mobile device 118. In another example, if donor vehicle 102 is at or previously was at a dealer or authorized shop, the dealer may have sent a message to cloud server 120 indicating that maintenance is being performed. In such a case, the cloud server 120 may request an acknowledgement at that merchant regarding the remote component's inventory.At operation 414, the cloud server 120 determines whether the vehicle change indicated by the non-matching control alert 126 is authorized. For example, the donor user may use the mobile application to confirm that the change was authorized on the vehicle 102, or alternatively indicate that the change was unauthorized. Or, the dealer may use the dealer system to confirm that the change was authorized on the donor vehicle 102 or indicate that the change was not authorized. If the user or dealer indicates that the change to the dealer was authorized, control passes to operation 416. If not, control passes to operation 418.At operation 416, the cloud server 120 permits the non-matching control alert 126 to be authorized. For example, the configuration of the vehicle 102 in the component database 124 may be updated to include the donor ECU / TCU being properly installed. In another example, despite including the donor component, the vehicle 102 may be re-made movable to allow the vehicle 102 to be used if the vehicle 102 itself has determined to be made non-movable due to the configuration change.At operation 418, the cloud server 120 indicates that the non-matching control alert 126 is not authorized. For example, the cloud server 120 may track the locations of the vehicle 102 and / or donor vehicle to identify where the change may have occurred. In another example, the vehicle 102 and / or donor vehicle may be rendered unable to move, e.g., to prevent use of any of the vehicles involved in the unauthorized swap operation. However, in other examples, the vehicle 102 may already have been rendered unable to move by the self-check performed by the gateway controller 112. After operation 310 or 312, the process 300 ends.FIG. 5 illustrates an example 500 of a computing device 502 for use in implementing a replacement spike mode for the TCU 106. Referring to FIG. 5 and with reference to FIGS. 1-4, the vehicles 102, the launch function controllers 104, the TCU 106, the gateway controller 112, the wireless transceiver 114, the communication network 116, the mobile device 118, and the cloud server 120 may be examples of such computing devices 502. As shown, computing device 502 includes a processor 504 operatively connected to a memory 506, a network device 508, an output device 510, and an input device 512. Note that this is merely an example and computing devices 502 with more, fewer, or different components may be used.The processor 504 may include one or more integrated circuits that implement central processing unit (CPU) and / or graphics processing unit (GPU) functionality. In some examples, the processors 504 are a system on a chip (SoC) incorporating the functionality of the CPU and the GPU. The SoC may optionally include other components, such as the memory 506 and the network device 508, in a single integrated device. In other examples, the CPU and the GPU are networked together via a peripheral connection device, such as Peripheral Component Interconnect (PCI) Express or other suitable peripheral data connection. In one example, the CPU is a commercially available central processing device that implements an instruction set, such as one of the x86, ARM, Power, or Microprocessor with Interlocked Pipeline Stage (MIPS) instruction set families.Regardless of the details, during operation, processor 504 executes stored program instructions that are retrieved from memory 506, such as those of configuration manager 122. The stored program instructions accordingly include software that controls the operation of the processors 504 to perform the operations described herein. The memory 506 may include both non-volatile memory and volatile memory devices. The non-volatile memory includes solid state memory, such as Not-And-Flash (NAND) memory, magnetic and optical storage media, or any other suitable data storage device that stores data when the system is powered down or power is interrupted. The volatile memory includes static and dynamic random-access memory (RAM) that stores program instructions and data during operation of the control system 100. Examples of data stored in the memory 506 may include the controller identifier 108, FINs, information included in the component database 124, alerts 126 of non-matching control, etc.The GPU may include hardware and software for displaying at least two-dimensional (2D) and optionally three-dimensional (3D) graphics on the output device 510. The output device 510 may include a graphical or visual display device, such as an electronic display screen, a projector, a printer, or any other suitable device that reproduces a graphical display. As another example, the output device 510 may include an audio device such as a speaker or a headphone. As yet another example, the output device 510 may include a tactile device, such as a mechanically elevatable device, which in one example may be configured to display blind text or other physical output that may be touched to provide information to a user.The input device 512 may include any of various devices that enable the computing device 502 to receive control inputs from users. Examples of suitable input devices that receive input via a human interface may include keyboards, mice, trackballs, touch screens, voice input devices, graphics tablets, and the like.The network devices 508 may each include any of various devices that enable the vehicles 102 to send and / or receive data from external devices over networks. Examples of suitable network devices 508 include an Ethernet interface, a Wi-Fi transceiver, a cellular transceiver, or a BLUETOOTH or BLE transceiver, a UWB transceiver, or other network adapter or peripheral connection device that receives data from another computer or external data storage device, which may be efficiently useful for receiving large sets of data.The processes, methods, or algorithms disclosed herein may be executable / implemented by a processing device, controller, or computer, which may include any existing programmable electronic control unit or dedicated electronic control unit. Likewise, the processes, methods, or algorithms can be stored as data and instructions executable by a controller or computer in many forms including, but not limited to, information permanently stored on non-writable storage media such as read-only memory (ROM) devices and information alterably stored on writeable storage media such as floppy disks, magnetic tapes, compact discs (CDs), RAM devices, and other magnetic and optical media. The processes, methods, or algorithms can also be implemented in a software executable object. Alternatively, the processes, methods, or algorithms can be embodied in whole or in part using suitable hardware components, such as Application Specific Integrated Circuits (ASIC), Field Programmable Gate Arrays (FPGA), state machines, controllers or other hardware components or devices, or a combination of hardware, software and firmware components.While exemplary embodiments are described above, it is not intended that these embodiments describe all possible forms encompassed by the claims. The terms used in the specification are words of description rather than limitation, and it is understood that various changes may be made without departing from the spirit and scope of the disclosure. As previously described, the features of various embodiments may be combined to form further embodiments of the invention that may not be expressly described or illustrated. While various embodiments could have been described as advantageous or preferred over other embodiments or prior art implementations with respect to one or more desired characteristics, those of ordinary skill in the art recognize that one / more features or characteristics can be compromised to achieve the desired overall system attributes, which depend on the specific application and implementation. These attributes may include, but are not limited to, strength, durability, life cycle, marketability, appearance, building, size, maintainability, weight, mullability, ease of assembly, etc. Thus, where any embodiments are described as less desirable than other embodiments or prior art implementations with respect to one or more characteristics, these embodiments are not outside the scope of the disclosure and may be desirable for particular applications.With respect to the processes, systems, methods, heuristics, etc. described herein, it should be understood that although the steps of such processes, etc. have been described as occurring according to a particular ordered sequence, such processes could be practiced with the described steps performed in an order that varies from the order described herein. It will be further understood that certain steps could be performed simultaneously, that other steps could be added, or that certain steps described herein could be omitted. In other words, the descriptions of processes herein are for the purpose of illustrating certain embodiments and should not be construed as limiting the claims.Accordingly, it is to be understood that the foregoing description is intended to be illustrative and not restrictive. From reading the foregoing description, many embodiments and applications other than the examples provided will be apparent. The scope should be determined, not with reference to the foregoing description, but should instead be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled. It is to be understood and intended that there will be future developments in the art discussed herein, and that the disclosed systems and methods will be incorporated into such future embodiments. Overall, it is understood that the application may be modified and varied.All terms used in the claims are intended to be accorded their broadest comprehensible constructions and their general meanings as known to those skilled in the art having the techniques described herein, unless expressly stated to the contrary herein. In particular, the use of the singular articles such as "a", "an", "the", "the", etc. should be construed to mean one or more of the listed elements unless a claim expressly indicates a limitation to the contrary.The Abstract of the Disclosure is provided to enable the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the proviso that it is not used to interpret or limit the scope or meaning of the claims. In addition, it will be apparent from the foregoing detailed description that various features have been incorporated in various embodiments for the purpose of simplifying the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as the following claims reflect, the subject matter of the invention lies in less than all features of a single disclosed embodiment. Thus, the following claims are hereby incorporated into the Detailed Description, each claim standing on its own as a separately claimed subject matter.While exemplary embodiments are described above, it is not intended that these embodiments describe all possible forms of the invention. Rather, the terms used in the specification are words of description rather than limitation, and it is understood that various changes may be made without departing from the spirit and scope of the invention. In addition, the features of various implementing embodiments may be combined to form further embodiments of the invention.According to the present invention, there is provided a cloud system for managing non-matching control warnings, comprising: a component database configured to store non-matching control warnings received from a plurality of vehicles, each of the non-matching control warnings indicating an identifier of a current vehicle in which the non-matching control is installed and a location of the current vehicle; and one or more hardware computing devices configured to: perform clustering of the non-matching control warnings to correlate the non-matching control warnings by location, and indicate clustered locations of the non-matching control warnings.According to an embodiment, the non-matching control is a start function control of the current vehicle that is validated by the current vehicle before allowing the current vehicle to start.According to an embodiment, each of the non-matching control warnings further indicates an identifier of an original vehicle in which the non-matching control was previously installed.According to one embodiment, the one or more hardware computing devices are further configured to: receive a warning from the current vehicle, the current vehicle being disabled due to detection of the non-compliant control; identify a verification device corresponding to the current vehicle; confirm the warning by sending a message to the verification device requesting authorization to install the non-compliant control; send a message to the current vehicle to cause the current vehicle to be disabled longer responsive to the non-compliant control installed in the current vehicle being confirmed to be authorized.According to one embodiment, the verification device is a mobile device of an owner or vehicle operator of the current vehicle.According to one embodiment, the verification device is a dealer device of a dealer who has maintained the current vehicle.According to one embodiment, the non-matching control is a TCU of the current vehicle.According to one embodiment, the warning is sent from the current vehicle using the TCU, although the TCU is the non-matching control.According to one embodiment, the warning from the current vehicle is sent to the cloud system by a mobile phone in communication with the current vehicle without using the TCU of the current vehicle.According to one embodiment, the warning from the current vehicle is sent to the cloud system from a Wi-Fi connection communication with the current vehicle without using the TCU of the current vehicle.According to one embodiment, indicating the clustered locations includes sending data indicating the clustered locations to law enforcement agencies to mitigate areas of high crimilitity rate.According to one embodiment, indicating the clustered locations includes sending data indicating the clustered locations to a vehicle insurance company for use in determining insurance premiums.According to the present invention, a method for managing non-matching control alerts includes: storing non-matching control alerts received from a plurality of vehicles in a component database having one or more hardware computing devices, each of the non-matching control alerts indicating an identifier of a current vehicle in which the non-matching control is installed and a location of the current vehicle; clustering the non-matching control alerts by the cloud system to correlate the non-matching control alerts by location; and indicating clustered locations of the non-matching control alerts by the cloud system.In one aspect of the invention, the method includes: receiving a warning from the current vehicle, the current vehicle being disabled due to detection of the non-matching control; identifying a verification device corresponding to the current vehicle; confirming the warning by sending a message to the verification device requesting authorization to install the non-matching control; and sending a message to the current vehicle to cause the current vehicle to be disabled longer responsive to the non-matching control installed in the current vehicle being confirmed to be authorized.In one aspect of the invention, the verification device is one of: a mobile device of an owner or vehicle driver of the current vehicle or a dealer device of a dealer who has maintained the current vehicle.In one aspect of the invention, the non-matching controller is a TCU of the current vehicle.In one aspect of the invention, one of the following applies: the warning is transmitted from the current vehicle using the TCU, although the TCU is the non-matching control; the warning is transmitted from the current vehicle to the cloud system by a mobile phone in communication with the current vehicle without using the TCU of the current vehicle; or the warning is transmitted from the current vehicle to the cloud system via Wi-Fi connection communication with the current vehicle without using the TCU of the current vehicle.In one aspect of the invention, indicating the clustered locations includes sending data indicating the clustered locations to law enforcement agencies to mitigate areas of high crimilitude rate.In one aspect of the invention, indicating the clustered locations includes sending data indicating the clustered locations to a vehicle insurance company for use in determining insurance premiums.According to the present invention, there is provided a non-transitory computer readable medium having instructions for managing non-compliant control alerts that, when executed by a cloud system having one or more hardware computing devices, cause the cloud system to perform operations including: storing non-compliant control alerts received from a plurality of vehicles, each of the non-compliant control alerts indicating an identifier of a current vehicle in which the non-compliant control is installed and a location of the current vehicle; performing clustering of the non-compliant control alerts by the cloud system to correlate the non-compliant control alerts by location; indicating clustered locations of the alerts for non-consistent control by the cloud system, including sending data indicating the clustered locations to one or more of law enforcement agencies to mitigate areas of high crimilitity or a vehicle insurance company for use in determining insurance premiums.

Claims

A method for managing non-matching control alerts, comprising: storing non-matching control alerts received from a plurality of vehicles in a cloud system component database having one or more hardware computing devices, wherein each of the non-matching control alerts indicates an identifier of a current vehicle in which the non-matching control is installed and a location of the current vehicle; performing, by the cloud system, clustering of the non-matching control alerts to correlate the non-matching control alerts by location; and indicating, by the cloud system, clustered locations of the non-matching control alerts.The method of claim 1, further comprising: receiving a warning from the current vehicle, wherein the current vehicle is disabled due to detection of the non-matching control; identifying a verification device corresponding to the current vehicle; confirming the warning by sending a message to the verification device requesting authorization to install the non-matching control; and sending a message to the current vehicle to cause the current vehicle to be disabled longer from moving in response to the non-matching control installed in the current vehicle being confirmed to be authorized.The method of claim 2, wherein the verification device is a mobile device of an owner or operator of the current vehicle.The method of claim 2, wherein the verification device is a dealer device of a dealer who has maintained the current vehicle.The method of claim 2, wherein the non-matching control is a TCU of the current vehicle.The method of claim 5, wherein the warning is sent from the current vehicle using the TCU, although the TCU is the non-matching control.The method of claim 5, wherein the alert is sent from the current vehicle to the cloud system by a mobile phone in communication with the current vehicle without using the TCU of the current vehicle.The method of claim 5, wherein the alert is sent from the current vehicle to the cloud system from a Wi-Fi connection communication with the current vehicle without using the TCU of the current vehicle.The method of any of claims 2-8, wherein indicating the clustered locations includes sending data indicating the clustered locations to law enforcement agencies to mitigate areas of high crimilitude rate.The method of any of claims 2-9, wherein indicating the clustered locations includes sending data indicating the clustered locations to a vehicle insurance company for use in determining insurance premiums.The method of any of claims 2-10, wherein each of the non-matching control warnings further indicates an identifier of an original vehicle in which the non-matching control was previously installed.A cloud system for managing non-matching control warnings, comprising: a component database configured to store non-matching control warnings received from a plurality of vehicles, each of the non-matching control warnings indicating an identifier of a current vehicle in which the non-matching control is installed and a location of the current vehicle; and one or more hardware computing devices configured to perform the method of any of claims 1-11.A non-transitory computer readable medium comprising instructions for managing alerts of non-consistent control, which, when executed by a cloud system having one or more hardware computing devices, cause the cloud system to perform the method of any of claims 1-11.