SECURITY KEY DISTRIBUTION

A state machine on computing devices in vehicles manages security key updates based on device state and lock status, enhancing network security by only allowing updates when conditions are met, thus preventing unauthorized access.

DE102025110504A1Pending Publication Date: 2025-09-25FORD GLOBAL TECH LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE102025110504
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-22
Filing Date
2025-03-18
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Existing systems lack effective methods for securely managing and updating security keys in networked computing devices, particularly in vehicles, which can lead to unauthorized access and security breaches.

Method used

Implementing a state machine on computing devices to manage security key updates based on device state, mode, and lock status, allowing or denying updates based on predefined conditions to ensure secure communication and prevent unauthorized changes.

Benefits of technology

Enhances the security of vehicle communication networks by ensuring that security key updates are only permitted when the device is in a suitable state, thereby preventing unauthorized access and maintaining network integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Communications between computing devices connected over a network may be secured with digital keys (e.g., encryption keys). The key may be updated based on states of a state machine. The computing device may receive a key update command to update a key value. In response to the key update command, upon determining that the computing device is in a first state, the computing device may update the key value based on state data defining the first state, wherein the state data includes the key value, a machine mode specifying a current operating environment, and a lock value specifying that memory storing the key value is one of locked or unlocked.
Need to check novelty before this filing date? Find Prior Art

Description

AREA

[0001] This disclosure relates to techniques for managing, distributing, and / or updating security keys to computing devices over a network. BACKGROUND

[0002] Communications between computing devices connected over a network may be secured with digital keys (e.g., encryption keys). For example, a device may use an encryption key to encrypt a communication sent over the network for other devices, and / or may use the encryption key or an encryption key to decrypt communication from another device received over the network. A security key may be initially installed or deployed (e.g., a security key in a device may be updated from a default or initial security key). Alternatively, or additionally, a security key may be updated from time to time. SUMMARY

[0003] In one non-limiting example discussed herein, the computing devices are electronic control units (ECUs) connected to a network in a vehicle. The computing devices may communicate with each other according to a stored security key. For example, communications encrypted with the security key may be sent over a vehicle communications bus. As described herein, respective devices, such as ECUs, may manage security keys, including installing and / or updating security keys, by managing a state machine that determines whether a state of the device permits and / or justifies updating the security key (e.g., from a default security key and / or from a previously installed or updated security key).As described in more detail below, the state machine may track attributes of a computing device, including whether it is in a locked or unlocked state, whether it is in an initial mode or an operational mode, and / or whether a security key value is a default value or a previously distributed or installed value, to determine whether the device is in a state to update a security key, install a security key, and / or reset a security key to a default value.

[0004] Accordingly, included in the present disclosure is a system comprising a computing device, the computing device including a processor and a memory, the memory having stored thereon instructions executable by the processor, including instructions to: receive a key update command to update a key value, and update the key value in response to the key update command upon determining that the computing device is in a first state based on state data specifying the first state, the state data including the key value, a machine mode specifying a current operating environment, and a lock value indicating that memory storing the key value is one of locked or unlocked.

[0005] A second state can be entered after the key value has been updated.

[0006] The computing device may be permitted to authenticate communications with the key value based on the second state.

[0007] The machine mode can change from the first state to the second state.

[0008] The first state can be a default state and a key value in the default state can be a default value.

[0009] The computing device may be configured to communicate with a second computing device over a network.

[0010] A gateway computing device may be configured to provide the key update command to the computing device over the network. The gateway may be further configured to provide the key update command based on determining that the computing device is in the first state.

[0011] The computing device may be an electronic control unit (ECU) for a vehicle.

[0012] The first state can be entered from an error state.

[0013] A method includes: receiving a key update command to update a key value, and updating the key value in response to the key update command upon determining that the computing device is in a first state based on state data specifying the first state, the state data including the key value, a machine mode specifying a current operating environment, and a lock value indicating that memory storing the key value is one of locked or unlocked.

[0014] A second state can be entered after the key value has been updated.

[0015] The computing device may be permitted to authenticate communications with the key value based on the second state.

[0016] The machine mode can change from the first state to the second state.

[0017] The first state can be a default state and a key value in the default state can be a default value.

[0018] The computing device may be configured to communicate with a second computing device over a network.

[0019] A gateway computing device may be configured to provide the key update command to the computing device over the network. The gateway may be further configured to provide the key update command based on determining that the computing device is in the first state.

[0020] The computing device may be an electronic control unit (ECU) for a vehicle.

[0021] The first state can be entered from an error state. BRIEF DESCRIPTION OF THE DRAWINGS Fig.1 is a block diagram of an example vehicle. Fig. Figure 2 illustrates an example device network. Fig. Figure 3 is a state diagram illustrating a state machine for key distribution. Fig. 4 is a process flow diagram of an example process for computing devices to operate over a network according to a state machine. Fig. 5 is a process flow diagram illustrating an example process for managing key distribution according to a state machine. DETAILED DESCRIPTION

[0022] Fig.1 is a block diagram of a vehicle system 100. The vehicle 102 includes computing devices 104, 106, 108, including a security manager 104, one or more control devices 106, and / or a gateway 108. A control device 106 may be, for example, an electronic control unit (ECU). Each computing device 104, 106, 108 may include memory containing instructions executable by the computing device 104, 106, 108 to perform processes and operations, including those described herein. The computing devices 104, 106 may be communicatively coupled to a gateway 108, sensors 110, and vehicle subsystems 112, such as a powertrain controller, a steering controller, etc., via a communications network, such as a vehicle network 114.The vehicle 102 may be any passenger or commercial vehicle, such as a car, a truck, an SUV, a crossover, a van, a minivan, a taxi, a bus, etc.

[0023] Each computing device 104, 106, 108 includes a processor and memory. The memory includes one or more forms of computer-readable media and stores instructions executable by the processor to perform various operations, including those disclosed herein. For example, the control device 106 may be a generic computer with a processor and memory, as described above, and / or may include an electronic control unit (ECU) or controller for a specific function or set of functions, and / or a dedicated electronic circuit including an ASIC (application-specific integrated circuit) manufactured for a specific operation (e.g., an ASIC for processing sensor data and / or communicating the sensor data).In another example, the computing device 104, 106, 108 may include an FPGA (field-programmable gate array) incorporated into an integrated circuit fabricated to be user-configurable. Typically, a hardware description language, such as VHDL (very high-speed integrated circuit hardware description language), is used in electronic design automation to describe digital and mixed-signal systems, such as FPGAs and ASICs. For example, an ASIC is fabricated based on VHDL programming provided prior to fabrication, whereas logical components within an FPGA may be configured based on VHDL programming (e.g., stored in memory electrically connected to the FPGA circuitry).In some examples, a combination of processor(s), ASIC(s), and / or FPGA circuits may be included in the computing device 104, 106, 108.

[0024] The memory includes any suitable type of storage, as known. Types of storage may include hard disk drives, solid-state drives, servers, or any volatile or non-volatile media. The memory may be a separate device from the computing device 104, 106, 108, and the computing device 104, 106, 108 may retrieve information stored by the memory via the network 114 in the vehicle 102 (e.g., via a CAN bus, a wireless network, etc.). Alternatively or additionally, the memory may be part of the computing device 104, 106, 108 (e.g., as a memory of the computing device 104, 106, 108).

[0025] The computing devices 104, 106, 108 may include or be communicatively coupled (e.g., via the vehicle network 114, such as a communication bus, as described in more detail below) to more than one processor (e.g., included in components such as sensors 110, control devices 106 such as electronic control units (ECUs), or the like, disposed within the vehicle 102 for monitoring and / or controlling various vehicle components or subsystems 112 (e.g., a powertrain controller, a steering controller, etc.)). The computing device 104, 106, 108 is generally arranged for communication within the vehicle communication network 114, which may include a bus within the vehicle 102, such as a Controller Area Network (CAN) or the like, and / or other wired and / or wireless mechanisms.Alternatively or additionally, in cases where the computing device 104, 106, 108 actually includes a plurality of devices, the vehicle communication network 114 may be used for communication between devices depicted in this disclosure as the computing device 104, 106, 108. Further, as mentioned below, various controllers and / or sensors 110 of the computing device 104, 106, 108 may provide data via the vehicle communication network 114.

[0026] Via the vehicle network 114, the computing devices 104, 106, 108 may transmit and / or receive messages to and / or from various devices in the vehicle 102, including sensors 110; actuators; other computing devices 104, 106, 108; etc. Various controllers and / or sensors 110 may provide data to the computing devices 104, 106, 108 via the vehicle network 114. The vehicle network 114 may be one or more of a combination of wired and / or wireless networks, such as a CAN (Controller Area Network) bus, and / or may also include Ethernet, Wi-Fi, etc.

[0027] The vehicle 102 may include a security manager 104 for monitoring communications between the control devices 106 and the remote access device 116 and for controlling operations of vehicle subsystems 112. The security manager 104 may include a processor and memory storing instructions executable by the security manager 104 and may be communicatively coupled to the control devices 106 and the vehicle subsystems 112 via the vehicle network 114. The security manager 104 may communicate with the control devices 106 (e.g., exchange messages). That is, the security manager 104 may forward instructions to the control device 106, for example, to operate a vehicle subsystem 112. The security manager 104 may request that the control devices 106 authenticate to the security manager 104.If at least one of the control devices 106 fails authentication, the security manager 104 may "immobilize" the vehicle 102 by disallowing operation of the vehicle subsystem 112. For example, if some control devices 106 fail authentication, the security manager 104 may prevent the actuation of an ignition system in the vehicle 102.

[0028] As mentioned above, the security manager 104 may be configured for wireless communication with the remote access device 116. The security manager 104 and the remote access device 116 may communicate wirelessly according to a wireless protocol, such as, for example, Wi-Fi or Bluetooth. An example communication from the remote access device 116 to the security manager 104 is a request to actuate a vehicle subsystem 112, such as vehicle ignition or power engagement, unlocking doors, etc. The security manager 104 may forward the request to the control device 106 so that the control device 106 may actuate the vehicle subsystems 112 based on the request.

[0029] As mentioned above, the security manager 104 may communicate with the computing devices 106, 108. The communication between the security manager 104 and the computing devices 106, 108 may be encrypted with a security key. That is, a security key value may be used to encrypt a communication according to a stored algorithm such that the communication is impossible to decrypt without access to the security key. The security manager 104 and the computing devices 106, 108 may store the security key to encrypt and decrypt communications.

[0030] Authentication of messages in the computing device 104, 106, 108, such as the control device 106, may employ various suitable mechanisms, such as a message authentication code (MAC) (sometimes referred to as a message integrity code or MIC). MAC authentication may involve inputting the security key and a message into a signing algorithm to output a tag; a verification algorithm may then verify that the message is authentic (or to be rejected) using the tag and the security key as input. MAC authentication may be used in cypher-based message authentication codes (CMAC). As will be understood, CMAC authentication may involve a block cipher.

[0031] The security manager 104 may be in communication with the remote access device 116. The remote access device 116 is a device that may be configured to communicate wirelessly with the security manager 104 (e.g., via Bluetooth). The remote access device 116 may be any device capable of communicating wirelessly with the security manager 104 (e.g., via Bluetooth). The remote access device 116 may be a dedicated device (e.g., a remote key fob, such as a radio-frequency identification (RFID) device). Additionally or alternatively, the remote access device 116 may be a portable computing device, such as a smartphone. The remote access device 116 may be actuated by a vehicle operator to send a command to the security manager 104 to actuate a vehicle subsystem 112.As one example, the remote access device 116 may send a command via the security manager 104 instructing the control device 106 to unlock the vehicle doors. The remote access device 116 may store a security key shared among the control devices 106 so that when the remote access device 116 sends a communication to the security manager 104, the security manager 104 is able to authenticate the remote access device 116. The remote access device 116 may be detected by sensors 110 within an interior of the vehicle 102. Based on detecting the remote access device 116 within the interior of the vehicle 102, the security manager 104 may actuate vehicle subsystems 112.

[0032] The control devices 106 can receive wired or wireless communication from the remote device 120 via the gateway 108. The remote device 120 is in Fig. 1 as communicating with the gateway 108 via the wide area network 118 and the vehicle network 114, but in many examples, it could be directly connected (e.g., via a wired connection) to the vehicle network 114. As one example communication, the remote device 120 could command the computing devices 104, 106, 108 via the gateway 108 to update the security key.

[0033] The vehicle may include gateway 108. Gateway 108 may be connected to a plurality of control devices 106, such as ECUs, via one or more vehicle buses. Gateway 108 may be configured to communicate signals between different vehicle buses connected to gateway 108. Gateway 108 may include processors and memory storing instructions executable by the processor. Gateway 108 may receive communications from remote device 120 and forward the communications to control devices 106.

[0034] The vehicle 102 typically includes a variety of sensors 110. A sensor 110 is a device that can obtain one or more measurements of one or more physical phenomena. Some sensors 110 detect internal conditions of the vehicle 102, for example, wheel speed, wheel alignment, and engine and transmission variables. Some sensors 110 detect the position or orientation of the vehicle 102, for example, global positioning system (GPS) sensors. Some sensors 110 detect objects, for example, radar sensors, laser scanner rangefinders, light detection and ranging devices (LIDAR), and image processing sensors such as cameras. Other sensors 110 detect sound, for example, dynamic or condenser microphones, piezoelectric transducers, ultrasonic sensors, acoustic emission sensors, etc.

[0035] The wide area network 118 represents one or more mechanisms by which the computing device 104, 106, 108 can communicate with remote computing devices (e.g., the remote device 120, another vehicle computer, etc.). Accordingly, the wide area network 118 can be one or more of various wired or wireless communication mechanisms, including any desired combination of wired (e.g., cable and fiber optic) and / or wireless (e.g., cellular, wireless, satellite, microwave, and radio frequency) communication mechanisms and any desired network topology (or network topologies if multiple communication mechanisms are utilized). Example communication networks include wireless communication networks (e.g., using Bluetooth®, Bluetooth® Low Energy (BLE), IEEE 802.11a, IEEE 802.11b, IEEE 802.11g ...11, vehicle-to-vehicle (V2V), such as dedicated short-range communications (DSRC), etc.), local area networks (LAN) and / or wide area networks (WAN), including the Internet, providing data communication services.

[0036] Now, with reference to Fig. 2 together with Fig. 1 illustrates a communication system 200 including the vehicle network 114 and the wide area network 118 with devices 104, 106, 108, 116, and 120 arranged to communicate via one or both of the networks 114, 118. The computing devices 104, 106, 108 may receive communications from the remote device 120 via the wide area network 118 and the gateway 108. The remote device 120 may transmit security keys to the gateway 108 to be distributed to the devices 104, 106.

[0037] The system 200 typically includes a plurality of control devices 106-1, 106-2, 106-3, 106-4, 106-5. Various of the control devices 106 may be programmed or configured to provide commands to actuate or control vehicle components in a vehicle subsystem 112, such as propulsion, ignition, etc. The computing devices 104, 106, 108 may exchange communication with other computing devices 104, 106, 108, as well as the remote access device 116, via the vehicle network 114.

[0038] As an example of security key distribution, remote device 120 may send a message including an updated security key (i.e., to replace a default security key and / or a previously updated security key) over wide area network 118 to control devices 106 via gateway 108 over Wi-Fi. That is, remote device 120 may send a message intended to reach at least one of control devices 106. The message is first received by gateway 108 and then broadcast and / or forwarded over vehicle network 114 to be received by one or more of control devices 106.

[0039] The controllers 106 may determine whether to allow or deny an update of the security key to which the controller 106 has access based on whether the controller 106 is in a state where the update is permitted. For example, the controller 106 may store instructions to deny a key update if the vehicle 102 in which the controller 106 is installed is in a maintenance mode and the value of the security key is a specified default value. Alternatively or additionally, the controller 106 may allow a security key update if the vehicle 102 is in a vehicle operating mode and the key is a non-default value.

[0040] The controller 106 may implement a finite state machine to determine whether to update the security key. A finite state machine may be implemented according to programming in the controller 106 that transitions the controller 106 from a first state (or a start condition) to a second state based on changes to one or more variables or values, typically taking the first state into account (e.g., an equal value may transition a first state to a second state and a third state not to the second state but to a fourth state). For example, one or more changed values ​​in a state machine may cause the state machine to determine a state transition of the controller 106 from a first state to a second state.Thus, a finite state machine herein means a model that includes a finite plurality of states and that can transition between the states (i.e., from a first state to a second state), where the second state is determined or selected from the plurality of states based on one or more values ​​received when the finite state machine is in the first state. Note that the modifiers "first," "second," etc., are for convenience in the present context and do not necessarily imply an order of priority or an order in which states are selected or visited in the state machine.

[0041] Implementing the finite state machine as described herein may improve the security of communications between networked devices (e.g., devices 106 in a network 114 in a vehicle 102). Furthermore, security of a machine that includes or uses networked devices may also be improved. For example, providing secure key updates of control devices 106 in the vehicle 102 may improve security of the vehicle 102. In one example, if a bad actor attempts to replace a control device 106 in the vehicle 102 with an unauthorized or malicious control device 106 to thereby steal or misuse the vehicle 102, enforcing secure key updates could help prevent or hinder the bad actor's attempt to misuse the vehicle 102.

[0042] In Fig.3, which now together with the Fig. Referring to Figure 1-2, an exemplary state diagram is illustrated that includes various states and the values ​​for transitioning between states. The controller 106 may determine that a state machine executing in the device 106 is in a first state based on state data defining the first state. The state data illustrated in the present example includes the following: Condition definition Locking Specifies whether a security key can be updated or changed; can be "locked" (no change or update possible) or "unlocked" (change or update possible). That is, it is impossible to change a locked key value, and an unlocked key value could be changed. mode Specifies a current operating environment or mode of a machine incorporating device 106 (e.g., vehicle 102). Typically, the mode specifies whether the machine is in a pre-service mode (e.g., it is in a factory environment prior to being deployed for field use) or a service mode (e.g., has been deployed for field use). The pre-service mode may be referred to as "initial," and the service mode may be referred to as "in service" or "service." Key_Value Value of a security key (i.e., a data string representing the security key) currently stored in a device 106; for state machine purposes, a device 106 may determine that the key value is either a default value (i.e., a value provided when the device 106 is initially installed in the vehicle 102 or when the device 106 has been reset) or a non-default value (i.e., the key has been updated from the default value). CMAC allows Specifies whether CMAC communications (i.e., CMAC authentication) are permitted between devices 104, 106, 108. If permitted, devices 104, 106, 108 can communicate using the key in a MAC algorithm. If denied, no communication can occur between devices 104, 106, 108. update Specifies whether key_val is allowed to be read by device 106 allowed is updated.

[0043] The following table (Table 1), which can be called the “state table”, lists state values ​​that correspond to the Fig. 3 illustrated state diagram: Table 1 Condition mode Key value Key locking CMAC allows Update allowed Condition1 Initially standard Unlocked Allowed Allowed Condition6 Initially Non-standard Unlocked Allowed Allowed Condition3 service standard Unlocked Refused Allowed Condition5 service Non-standard Unlocked Allowed Allowed Condition2 service standard Locked Refused Refused Condition4 service Non-standard Locked Allowed Refused Condition7 Initially standard Locked Refused Refused Condition8 Initially Non-standard Locked Refused Refused

[0044] Table 1 shows values ​​for state values ​​(e.g. values ​​of state data) in respective states in the exemplary state machine Fig.3. In examples described herein, a computing device 104, 106, 108 may determine a current state by determining values ​​for mode, key value, key lock, and CMAC allowed state data. Then, by determining the current state, the computing device 104, 106, 108 may determine whether an update of the key value is permitted or not (i.e., allowed or denied). For example, state data in state 1 may have the following values: the mode is initial, the key state is default (i.e., the key is a specified default value), the key lock is unlocked (i.e., it is possible to update the key value), and an update of the key value is allowed. Accordingly, in state 1, the control device 106 may issue a key update command (e.g.,from the remote device 120 via the gateway 108) to update the key value.

[0045] The following Boolean equation (Equation 1) can be used to determine the "CMAC Allowed" state value (i.e., if the equation evaluates to "true," then CMAC authentication of communication between computing devices 104, 106, 108 is allowed; if not true or "false," then CMAC authentication of communication is denied (not allowed)). Typically, CMAC Allowed means that computing device 104, 106, 108 has a non-standard security key, and other state values ​​indicate that CMAC authentication is allowed and, therefore, communications between computing devices 104, 106, 108 can occur. CMAC Denied can occur when a non-standard security key value is present (see State 8) and also occurs when computing device 104, 106, 108 has a standard security key.For the equation, initial mode is true if it is in initial mode and false otherwise, key state is true if it is a default value and false otherwise, and key lock is true if it is unlocked. CMAC communication allowed=initial mode OR(key state NOT standard) AND NOT error state

[0046] The state machine may transition from a first state (or initial condition or entry condition) to a second state based on one or more "transition events." A transition event herein means an event or occurrence that changes a state value of the state machine, such as the receipt of data or a change in the physical status of the computing device 104, 106, 108. The controller 106 may transition the state machine from a first state to a second state upon detecting one or more transition events. A transition event could be the receipt of a command or data from the remote device 120 connected to the vehicle 102.For example, a transition event may include a command to update a security key value from a default value to a non-default value, or to update or reset a non-default value to a default value, or to update a non-default value. As one example, a transition event including a command to distribute a key update (a "key update" command) transitions the state machine from state 3 to state 4 and from state 1 to state 6. In another example, with reference to FIG. Fig.3, the state machine transitions from state 5 to state 2 based on an event. In such an example, the event may be "key reset" and "key lock" commands sent by the remote device 120 to the control device 106. The same event may transition the state machine to different second states, depending on which state is the first state when an event occurs. For example, a "device reset" event transitions to state 2 if the state machine is in state 3, but transitions to state 4 if the state machine is in state 8.

[0047] Transition events including commands may be sent by the remote device 120 to the control devices 106 in accordance with user input to the remote device 120 (e.g., by a technician or the like).

[0048] Transitional events in Fig. 3 are represented by the marked arrows. Table 2 below provides explanations of the respective transition events. Table 2 Transitional event Explanation Key update Received command to update a key value. Key reset Received command to reset a key value to a default value. Mode change Changing a mode (e.g. from "Initial" to Service or vice versa). Unlock key Received command to unlock a key in memory (e.g., allow the memory location storing the key value to be updated). Lock key Received command to lock a key in memory (e.g., prohibit the memory location storing the key value from being updated). Reinstallation Device installed in new vehicle (i.e. not previously in service). Replacement installation Device installed in new vehicle (i.e. not previously in service). Device reset Device resets to specified reset values. In service mode, resetting locks the key. In initial mode, resetting unlocks the key.

[0049] Upon initial power-up of a controller 106, the state machine may enter either state 1 or state 2, depending on whether a transition event involves a new installation or a replacement installation.

[0050] State 1 is reached from a start-up or entry condition upon a new installation of the control device 106 in a vehicle 102. State 1 includes the following state values: the current machine mode is initial; the key value of the stored key is a default value; and the key is unlocked. The "CMAC Allowed" value is "allowed." Furthermore, the update value is "allowed." Therefore, in state 1, the control devices 106 can allow updates to the security key and perform CMAC communications with other control devices 106. The state machine 300 transitions from state 1 to state 4 when the remote device 120 sends a key update command and a mode change occurs. The state machine 300 transitions from state 1 to state 6 upon receiving the key update command but without a mode change.Since the key value is unlocked in state 1, the key is updated to a non-default value provided by the key update command, as reflected by the key value shown as "non-default" in each of states 4 and 6.

[0051] State 2 is reached from a start or entry condition upon replacement installation of the control device 106 in the vehicle. State 2 includes the following values: the current machine mode is "service," the key value of the stored key is a default value, and the key is locked. Furthermore, the update value is "denied." State 2 transitions to State 3 when an unlock command is received, changing the key lock value to "unlocked."

[0052] State 3 includes the following values: the current machine mode is service, the key value of the stored key is a default value, and the key is unlocked. The value for "CMAC allowed" is "denied" (see Equation 1). Furthermore, the update value is "allowed." State 3 transitions to state 2 upon an event that includes a reset of a controller 106, which changes the key lock value to locked. State 3 transitions to state 4 upon an event that includes receipt of a command to update the key and lock the key in memory.Since the key value is unlocked in state 3, the key is updated to a non-default value provided by the key update command, as reflected by the key value shown as "non-default" in state 4; further, the "lock" state value in state 4 is "locked" due to the lock command.

[0053] State 4 thus includes the following values: the key is locked, the mode is "service," and the key is a non-default value. The "CMAC Allowed" value is "allowed." Furthermore, the update value is "denied." State 4 could represent a case where the control device 106 was maliciously or improperly installed in the vehicle 102, and a bad actor then attempts to update the security key to a key that would allow improper access to the vehicle 102 and / or the network 114 where the control devices 106 are located to update the key. Therefore, the control devices 106 deny CMAC-authenticated communications and deny key updates. State 4 transitions to State 5 upon a command from a device 120 to change the key lock value from "locked" to "unlocked" so that the key can be updated.

[0054] State 5 thus includes the following values: the key is unlocked, the mode is "Service," and the key is a non-default value. The "CMAC Allowed" value is "Allowed." Furthermore, the update value is "Allowed." State 5 transitions to State 2 upon receipt of a command that updates the key to the default value and locks the key. State 5 transitions to State 4 upon a command from the remote device 120 to update the key value from a non-default value to a new non-default value and to lock the key. The controller 106 may also transition from State 5 to State 4 based on a transition event that includes an ECU reset. According to Table 2, the ECU reset locks the key because the mode is Service.

[0055] State 6 includes the following values: the key is unlocked, the mode is "initial," and the key is a non-default value. The "CMAC Allowed" value is "allowed." Furthermore, the update value is "allowed." State 6 transitions to State 4 upon receipt of a command to unlock the key, as well as upon a change of mode to "service." In one example, this command is a "force counter synchronization" (FCS) command. An FCS command may occur when all control devices 106 have been installed in the initial mode of the vehicle 102 and the control devices 106 are to be placed or forced into a service mode. Accordingly, the FCS command locks the key and changes the mode from initial to service. State 6 transitions to State 1 upon receipt of a command to reset the key value to a default value.State 6 transitions to state 2 upon receipt of a command from device 120 that updates the key to the default value and locks the key.

[0056] State 7 represents a fault state, which includes the following values: the key is "locked," the mode is "initial," and the key is a default value. The "CMAC allowed" value is "denied." Furthermore, the update value is "denied." The controller 106 may enter state 7 as a result of a fault in the operation of the controller 106 (which could be caused, for example, by an unexpected fluctuation in electrical power (or what may be referred to as a "fault")). Upon a device reset command, the controller 106 transitions from state 7 to state 2.

[0057] State 8 represents a second error state. State data in state 8 is the same as in state 7, except that the security key in state 8 has a non-default key value. Upon a device reset command, the controller 106 transitions from state 4 to state 8. Example processes

[0058] Fig. 4, which, with reference to the elements described above, are taken from the Fig.1-3, a process flow diagram of an exemplary process 400 for operating computing devices 104, 106, 108 includes receiving commands (such as a command to update a security key) and sending and / or receiving messages over the network 114, 118 according to a state machine. The process may be performed according to program instructions executed by the computing device 104, 106, 108, such as the controller 106 (i.e., program instructions for a state machine, such as the state machine, could be implemented in a computing device 104, 106, 108, such as a controller 106), which could be a controller or ECU or the like communicating over the vehicle network 114. Accordingly, the process 400 will be explained with reference to the controller 106.

[0059] The process 400 begins in a block 410 when the state machine executing in the controller 106 enters an initial state from a start condition. For example, in the state machine Fig. 3, the starting condition is the installation of a new device 106. The initial state could be state 1 for a new or initial installation (e.g., when a vehicle is manufactured and components including the control devices 106 are initially installed). Furthermore, the initial state could be state 2 for a replacement installation (e.g., when a vehicle was previously manufactured and placed into service and components including the devices 106 are initially installed).

[0060] Next, in a decision block 415, the controller 106 executing the state machine determines whether authentication of messages received at the controller 106 is permitted in the current state, which could be the initial state or a second or subsequent state. In the state machine example, determining whether authentication of messages was permitted would mean checking whether CMAC was "allowed" or "denied." If the controller 106 determines that authentication of messages is permitted in the current state, then a block 420 follows block 415. If authentication of messages is not permitted, a block 425 is executed next.

[0061] In block 420, the controller may begin authenticating messages received or detected via the vehicle network 114. For example, a stored key value (key_val in the example of Fig. 3) be a value for a security key that can be used to perform authentication, such as CMAC authentication.

[0062] At decision block 425, which may follow one of blocks 415, 420, controller 106 determines whether a transition event has been detected. If a transition event is detected, the process proceeds to block 430. Otherwise, the process proceeds to block 435.

[0063] At block 430, the state machine transitions from the initial state to a second or subsequent state in response to the transition event. The transitioned state may also be referred to as a "new" state, in the sense that it is a different state than the current state of block 425.

[0064] At block 440, controller 106 determines whether to continue the process. Process 400 may be terminated by an external input or action. For example, if implemented in vehicle 102, controller 106 may execute process 400 as long as vehicle 102 is in an ignition-ON state. If process 400 continues, process 400 returns to block 415. Otherwise, process 400 ends following block 435.

[0065] Fig. 5, which, with reference to the elements from the Fig.1-3 described above, is a process flow diagram illustrating an exemplary process 500 for managing key distribution according to a state machine. The process 500 may be implemented and executed, for example, by the controller 106 of the vehicle 102. For example, the process 500 may be executed in the context of the process 400 described above. If the device 106 receives or determines a transition event, for example, at block 425, this transition event could include a key update command. The process 500 begins at block 510, where the controller 106 receives a key update command.

[0066] Next, in a decision block 515, the controller 106 determines whether an update is permitted in a current state. As explained above, the controller 106 may determine a current state based on state data values. For example, upon receiving a key update command, the controller 106 may determine that a current state is a state where the update permitted value is "permitted." In the example of Fig. 3, this could be any of states 1, 3, 5, or 6. The controller 106 could alternatively determine that a current state is a state in which the update allowed value is "denied." In the example of Fig.3, this could be any of states 2, 4, 7, or 8. If the current state does not allow a key update, the process 500 proceeds to a decision block 520. Otherwise, the process 500 proceeds to a block 525.

[0067] In decision block 520, the controller 106 determines whether a transition event has occurred (i.e., an event to transition the state machine in the controller 106 to a new state (i.e., a second state following the first or current state evaluated in block 515)). If a transition event has occurred, the process 500 returns to block 515. Otherwise, the process 500 proceeds to block 530.

[0068] In block 525, which may follow block 515, the controller 106 has transitioned to or is in a state that allows the key to be updated. Accordingly, the controller 106 performs a key update. The key update may reset the key value to the default value, update the key value from the default value to a non-default value, or update the non-default value (e.g., as described above). Following block 525, the method 500 then ends.

[0069] In block 530, which follows decision block 520, controller 106 determines whether process 500 should continue. Process 500 could be terminated, for example, by an external input or action. For example, if implemented in vehicle 102, controller 106 may execute process 500 as long as vehicle 102 is in an ignition-ON state. Thus, process 500 could be terminated by vehicle 102 transitioning to an ignition-OFF state. If process 500 continues, process 500 returns to block 520. Otherwise, process 500 ends after block 530.

[0070] Computing devices 104, 106, 108, such as those discussed herein, generally each include instructions executable by one or more computing devices 104, 106, 108, such as those identified above, and for performing blocks or steps of processes described above. For example, the process blocks described above may be embodied as computer-executable instructions.

[0071] Computer-executable instructions may be compiled from or interpreted by computer programs created using a variety of programming languages ​​and / or technologies, including, among others, either alone or in combination, Java™, C, C++, Python, Julia, SCALA, Visual Basic, Java Script, Perl, HTML, etc. In general, a processor 116 (i.e., a microprocessor) receives instructions (i.e., from memory, a computer-readable medium, etc.) and executes those instructions, thereby performing one or more processes that include one or more of the processes described herein. Such instructions and other data may be stored in files and transmitted using a variety of computer-readable media. A file in a computing device is generally a collection of data stored on a computer-readable medium, such as a storage medium, random access memory, etc.

[0072] A computer-readable medium (also called a processor-readable medium) includes any non-transitory (i.e., physical) medium involved in providing data (i.e., instructions) that can be read by a computer (i.e., by a processor of a computer). Such a medium can take many forms, including, but not limited to, non-transitory media and volatile media. Instructions can be transmitted through one or more transmission media, including fiber optics, wires, wireless communications, including internal structural elements comprising a system bus coupled to a processor of a computer. Common forms of computer-readable media include, for example, RAM, a PROM, an EPROM, a FLASH EEPROM, any other memory chip or cartridge, or any other medium from which a computer can read.

[0073] All terms used in the claims are intended to have their common and ordinary meaning as understood by one skilled in the art, unless expressly stated otherwise. In particular, the use of the singular articles, such as "a," "an," "the," "the," "the," etc., is to be interpreted to refer to one or more of the listed elements, unless a claim expressly limits the matter to the contrary.

[0074] In the drawings, the same reference numerals indicate the same elements. Furthermore, some or all of these elements could be changed. With respect to the media, processes, systems, methods, etc. described herein, it is understood that although the steps or blocks of such processes, etc., have been described as occurring according to a certain sequence, such processes could be implemented such that the described steps are performed in a different order than the order described herein. Further, it is understood that certain steps could be performed concurrently, other steps could be added, or certain steps described herein could be omitted. In other words, the descriptions of processes herein are provided to illustrate certain embodiments and should in no way be construed to limit the claimed invention.The use of "in response to," "based on," and "when determined" herein indicates a causal relationship, not just a purely temporal relationship. "Based on" or "in response to" may mean at least in part based on or at least in part in response to, unless expressly stated otherwise. Examples are contemplated herein. Any exemplary embodiment or exemplary feature described herein should not necessarily be construed as preferred or advantageous over other embodiments or features. Furthermore, exemplary embodiments described herein are not to be considered limiting.It should be readily understood that certain aspects of the disclosed systems and methods can be arranged and combined in a wide variety of different configurations, all of which are contemplated herein. In addition, the particular arrangements shown in the figures should not be considered limiting. It should be understood that other embodiments may include more or less of each element shown in a given figure. In addition, some of the illustrated elements may be combined or omitted. Still further, an exemplary embodiment may include elements not illustrated in the figures. The disclosure has been described in an illustrative manner, and it is understood that the terminology that has been used is intended to be in the nature of description rather than limitation.In light of the above teachings, many modifications and variations of the present disclosure are possible, and the disclosure may be practiced otherwise than as specifically described. It is understood that the use of the terms "first" and "second" is merely identifying and does not necessarily indicate priority.According to the present invention, a system is provided comprising a computing device, the computing device including a processor and a memory, the memory having stored thereon instructions executable by the processor, including instructions to: receive a key update command to update a key value; and, in response to the key update command, update the key value upon determining that the computing device is in a first state based on state data specifying the first state, the state data including the key value, a machine mode specifying a current operating environment, and a lock value indicating that memory storing the key value is one of locked or unlocked.

[0075] According to one embodiment, the instructions further include instructions to transition to a second state after updating the key value.

[0076] According to one embodiment, the instructions further include instructions to allow the computing device to authenticate communications with the key value based on the second state.

[0077] According to one embodiment, the machine mode changes from the first state to the second state.

[0078] According to one embodiment, the first state is a default state and a key value in the default state is a default value.

[0079] According to one embodiment, the computing device is configured to communicate with a second computing device over a network.

[0080] According to one embodiment, the invention is further characterized by a gateway computing device configured to provide the key update command to the computing device via the network.

[0081] According to one embodiment, the gateway is further configured to provide the key update command based on determining that the computing device is in the first state.

[0082] According to one embodiment, the computing device is an electronic control unit (ECU) for a vehicle.

[0083] According to one embodiment, the invention is further characterized in that the instructions further include instructions to transition to the first state from an error state.

[0084] According to the present invention, a method includes: receiving a key update command to update a key value; and updating the key value in response to the key update command upon determining that the computing device is in a first state based on state data specifying the first state, wherein the state data includes the key value, a machine mode specifying a current operating environment, and a lock value indicating that memory storing the key value is one of locked or unlocked.

[0085] In one aspect of the invention, the method includes transitioning to a second state after updating the key value.

[0086] In one aspect of the invention, the method includes allowing the computing device to authenticate communications with the key value based on the second state.

[0087] In one aspect of the invention, the machine mode changes from the first state to the second state.

[0088] In one aspect of the invention, the first state is a default state and a key value in the default state is a default value.

[0089] In one aspect of the invention, the computing device is configured to communicate with a second computing device over a network.

[0090] In one aspect of the invention, the method includes a gateway computing device configured to provide the command to update the key value to the computing device over the network.

[0091] In one aspect of the invention, the gateway is further configured to provide the key update command based on determining that the computing device is in the first state.

[0092] In one aspect of the invention, the computing device is an electronic control unit (ECU) for a vehicle.

[0093] In one aspect of the invention, the method includes transitioning to the first state from a fault state.

Claims

[1] Method comprising: Receiving a key update command to update a key value; and Updating the key value in response to the key update command upon determining that the computing device is in a first state based on state data defining the first state, wherein the state data includes the key value, a machine mode specifying a current operating environment, and a lock value specifying that memory storing the key value is one of locked or unlocked. [2] The method of claim 1, further comprising transitioning to a second state after updating the key value. [3] The method of claim 2, further comprising allowing the computing device to authenticate communications with the key value based on the second state. [4] The method of claim 2, wherein the machine mode changes from the first state to the second state. [5] The method of claim 1, wherein the first state is a default state and a key value in the default state is a default value. [6] The method of claim 1, wherein the computing device is configured to communicate with a second computing device over a network. [7] The method of claim 1, further comprising a gateway computing device configured to provide the command to update the key value to the computing device over the network. [8] The method of claim 7, wherein the gateway is further configured to provide the key update command based on determining that the computing device is in the first state. [9] The method of claim 1, wherein the computing device is an electronic control unit (ECU) for a vehicle. [10] The method of claim 1, further comprising transitioning to the first state from a fault state. [11] The method of claim 1, further comprising the computing device refusing the key update command upon determining that the computing device is in a second state based on the state data. [12] The method of claim 1, wherein the key update command is sent from a remote device. [13] The method of claim 1, further comprising a vehicle subsystem configured to receive commands from the computing device. [14] A computer comprising a processor and a memory, the memory storing instructions executable by the processor to perform the method of any one of claims 1-13. [15] A vehicle comprising the computer of claim 14.