Monitoring system and method for monitoring function calls in a vehicle, computer program product, and storage medium

EP4655669A1Pending Publication Date: 2025-12-03VOLKSWAGEN AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2024701680
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-01-26
Filing Date
2024-01-23
Publication Date
2025-12-03

AI Technical Summary

Technical Problem

Modern vehicles face challenges in ensuring system stability and safety when interacting with third-party programs through existing programming interfaces, as these interfaces often lack robust security measures to prevent data overload and safety hazards.

Method used

A control system with a programming interface that includes a security layer to verify function call data, ensuring system stability and safety by checking data against predefined stability and safety parameters, and preventing unauthorized or unsafe function calls from being executed.

Benefits of technology

The system effectively guarantees system stability and safety by filtering out potentially harmful or excessive function calls, protecting the vehicle's platform and occupants from unwanted interventions without revealing sensitive data to third-party programs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024051518_02082024_PF_FP
    Figure EP2024051518_02082024_PF_FP
Patent Text Reader

Abstract

The invention relates to a monitoring system (10) for monitoring function calls in a vehicle (11), having a programming interface (12) with a security layer (16) which is provided between a linking layer (15) of the programming interface (12) and a communication layer (18) of the programming interface (12) and which is configured so as to check function call data transmitted from the linking layer (15) to the security layer (16) with respect to a vehicle (11) operating system (14) stability to be ensured and allow or prevent a transmission of the function call data from the security layer (16) in the direction of the communication layer (18) on the basis of the check which has been carried out. The invention also relates to a method and to a computer program product (19) for operating such a monitoring system (10) and to a computer-readable storage means (20), on which such a computer program product (19) is stored.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Kontra 11 system and method for controlling function calls in a vehicle, computer program product and storage medium

[0003] The present invention relates to a control system and a method for controlling function calls in a vehicle using a programming interface. The invention further relates to a computer program product for executing the method and a storage medium on which such a computer program product is stored.

[0004] Modern vehicles have a complex structure with a multitude of sensors, actuators, and system functions, for example, in an infotainment system. Since such vehicle components are generally not used in isolation but exchange data with each other, communication protocols and networks have been created to link the various, sometimes computer-implemented, vehicle components. For example, in many vehicles, the vehicle components are connected via a star-shaped network architecture in which a central gateway is used to facilitate communication between the various components. For modern vehicles, work is underway on programming interfaces designed to improve communication between an in-vehicle operating system and third-party programs.Generic systems and methods are described, for example, in US 11 132 650 B2, in which it is proposed to encode and decode data exchanged between a third-party program and the vehicle system via a programming interface at various points in the programming interface.

[0005] The object of the present invention is to improve existing systems and methods for the interaction between third-party programs and vehicle systems. The above object is solved by the patent claims. In particular, the above object is solved by the control system according to claim 1, the vehicle according to claim 9, the method according to claim 10, the computer program product according to claim 12, and the storage medium according to claim 13. Further advantages of the invention emerge from the subclaims, the description, and the figures.In this case, features that are described in connection with the control system naturally also apply in connection with the vehicle according to the invention, the method according to the invention, the computer program product according to the invention, the storage medium according to the invention and vice versa, so that with regard to the disclosure of the individual aspects of the invention, reference is and / or can always be made mutually.

[0006] According to a first aspect of the present invention, a control system for controlling function calls in a vehicle is proposed. The control system comprises a programming interface for connecting a third-party program to a computer-implemented operating system of the vehicle for sending function call data from the third-party program to the operating system for executing function calls and corresponding functions in the vehicle that are perceivable by the driver of the vehicle. The programming interface comprises a connection layer for sending the function call data from the third-party program to the programming interface and a communication layer for sending the function call data from the programming interface to the operating system.The programming interface further comprises a security layer provided between the connection layer and the communication layer, which is configured to perform a check of the function call data sent from the connection layer to the security layer with respect to a system stability of the operating system to be ensured and to enable or prevent a sending of the function call data from the security layer towards the communication layer based on the check performed.

[0007] With the Kontra II system according to the invention, interactions between third-party programs and the vehicle's operating system can be improved in a simple and reliable manner, ensuring the stability of the operating system at all times, while eliminating the need to disclose sensitive operating system and / or vehicle data to a third-party program. In this way, the vehicle platform and associated vehicle functions can be protected from unwanted interference in a correspondingly simple and reliable manner.

[0008] A third-party program can be understood as a program from a third-party provider that is not part of the core vehicle system, which is developed during vehicle production and installed in the vehicle. A third-party program can therefore be understood as an application for the operating system, for example, in the form of an application (app) that can be installed in the vehicle and provided by a third-party provider. A programming interface can be understood as a so-called API (Application Programming Interface), in particular an API that can be implemented in the vehicle or an on-board API. The programming interface can serve as a gateway for various vehicle functions.

[0009] A computer-implemented operating system can be understood as an in-vehicle system that is or can be executed by a computer or a corresponding processing unit. The operating system can comprise a compilation of computer programs that manages the system resources of a computer or computer system provided in the vehicle. The system resources can include a main memory, hard disks, input and output devices, a communications bus system (CAN, Ethernet, LIN, etc.), and processors, which can also be understood as components of the operating system. The operating system according to the invention is therefore not to be considered limited to a conventional, purely software-based operating system.

[0010] In contrast to known programming interfaces for vehicles, the programming interface according to the invention has the security layer, which is configured and designed to check the function call data with direct reference to the system stability to be ensured of the operating system. Checking with reference to the system stability to be ensured is to be understood here as meaning that all function call data sent and passing through the security layer are checked to determine whether forwarding the data could potentially lead to problems with the desired execution of the operating system, for example, in the communications bus system. Checking with reference to the system stability to be ensured can therefore be understood as checking based on predefined stability parameters to influence system stability.This check must be distinguished, for example, from a check with regard to a possibly required data encoding, which is performed at least in the programming interface without reference to the desired system stability. Function call data that has the required encoding and enters the operating system can nevertheless lead to system instability, for example, if the operating system is overloaded by a third-party program with particularly high performance requirements. In this case, function call data refers in particular to data and / or signals that initiate or are intended to initiate a function call by the operating system, i.e., the execution of a desired function by the operating system.A function call can encompass many different calls, for example, a call to activate seat heating, open a sliding door, activate a turn signal, influence the vehicle speed and / or direction, set a navigation route, and change a radio station. It is always important that the desired calls do not lead to a predefined system stability. This can be ensured by means of the control system according to the invention, and in particular by means of the security layer, in particular without the third-party program needing to know information from the vehicle and / or the vehicle's operating system. This means that the security layer can be configured to perform the check without data exchange between the operating system and the third-party program.The verification can be performed using a set of rules, i.e., based on a predefined set of rules and / or conditions. The verification is preferably performed on all data of the third-party program, regardless of, for example, whether a secure data connection has already been established between the third-party program and the operating system. Enabling or preventing the transmission of function call data can be understood as accepting or rejecting the function call data provided and verified by the third-party program depending on the verification and subsequently forwarding it out of the security layer. The security layer can be configured to perform the verification using suitable comparisons between determined data and / or parameters and reference data and / or reference parameters.

[0011] The programming interface according to the invention can have a plurality of layers, whereby the terms “layers” can be understood not only as layers but also as various modules, which do not necessarily have to be arranged or designed in layers. In the present application, the term “layer” is nevertheless used to ensure the most consistent notation possible. In addition to the connection layer, the security layer and the communication layer, the programming interface can also have a protocol layer, which can be provided between the security layer and the communication layer or for processing data sent between the security layer and the communication layer. The respective layers or modules can be understood as so-called middleware functions. The Kontra II system can have a diagnostic module, via which the middleware functions orThe corresponding layers can be configured via diagnostics, for example, to adjust thresholds and / or rules. The protocol layer is specifically configured for logging function call data from the safety module as well as feedback data from the operating system. In the protocol layer, function call data from the safety layer as well as data and / or signals from the operating system can be written to a data memory, which can be part of the Kontra II system but is preferably not part of the programming interface. In the case of a predefined or predefinable key event and / or trigger signal, the data written to the data memory can be stored from a volatile buffer into a non-volatile memory.

[0012] Once the function call data has successfully passed the security layer and the protocol layer, it can be forwarded via the communication layer to the desired and / or predefined target functions in the operating system. The communication adapter can be configured to adapt to different vehicle platforms to accommodate changes in the vehicle platform and / or third-party programs.

[0013] The security layer can be configured to perform the check in two stages, wherein in a first check stage the check is carried out with regard to the system stability of the operating system and in a second check stage, at least partially simultaneously or subsequently, a check is or can be carried out with regard to vehicle and / or vehicle occupant safety. For this purpose, the security layer can be embedded in the communication flow between the connection layer and the communication layer and / or in the communication flow between the third-party program and the operating system. At this point, the security layer does not change the function call data, for example, does not refactor it for any encoding or decoding. Only if it is determined during the check of the function call data that the function call data orIf at least one function call contained in the function call data could lead to system instability in the operating system, communication between the respective modules is interrupted. Subsequently, corresponding rejection information can be sent to the sender, i.e., to the third-party program or to the third-party program via the connection layer. The rejection information can include data on the reason for the rejection.

[0014] The check in the second verification stage with regard to vehicle and / or vehicle occupant safety can be understood as checking the function call data to determine whether forwarding the function call data to the operating system and resulting function calls could endanger vehicle and / or vehicle occupant safety. Vehicle safety is understood here to mean, in particular, mechanical and / or electromechanical vehicle security, i.e., not data security, for example. In other words, a check with regard to vehicle safety can be understood as carrying out the check to prevent mechanical and / or electronic damage to the vehicle. The same applies analogously to vehicle occupant safety.The function call data can again be checked with reference to the vehicle and / or vehicle occupant safety to be ensured using a predefined set of rules and / or conditions. A simple example of a check with reference to vehicle and vehicle occupant safety is a set of rules according to which no acoustic output and / or no door opening is permitted at a vehicle speed greater than zero. If a function call is detected in the function call data that would result in a violation of this set of rules, the function call data is retained in the security layer or is not forwarded to the operating system and / or not forwarded to the communication layer.

[0015] Controlling function calls can be understood as controlling and / or regulating function calls. In particular, controlling function calls can be understood as enabling or preventing requested function calls or corresponding function call data sent by the third-party program.

[0016] The security layer can be configured. In particular, the security layer or part of the security layer can be configured to be deactivated. For this purpose, the control system can have a suitable deactivation module, preferably operable by a vehicle occupant. The programming interface can be considered part of the operating system or as a standalone component independent of the operating system. The check can be performed using artificial intelligence in the control system. This means that the artificial intelligence can be configured to perform the check.

[0017] According to a further embodiment of the present invention, it is possible for the security layer in a control system to be configured to determine a number of function calls in the function call data and to perform the check based on the determined number of function calls. In other words, depending on the determined number of function calls, the function call data can be forwarded or not. In this way, system stability can be ensured by, for example, preventing an unreliable number of function calls from being sent to the operating system, thereby overloading the operating system. In particular, it can be prevented, for example, from overloading a communication bus system, which in turn could cause system instability.In addition or alternatively to determining the number of function calls, function calls can be summed up to perform the check. As soon as a predefined number of function calls is exceeded or as soon as a predefined threshold is reached or exceeded, the forwarding or sending of the function call data can be prevented or prohibited. The threshold can be predefined based on the vehicle's system parameters and / or dynamically determined during data transmission and adjusted accordingly. In addition to the number of function calls, a time factor can be taken into account. Over time and after the function calls have been processed, the summation described above can be reset. The security layer can be configured accordingly to carry out these steps.

[0018] The invention further relates to a control system in which the security layer is configured to determine the type of at least one function call in the function call data and to perform the check based on the determined type of the at least one function call. In other words, depending on the determined type of the at least one function call, the function call data can be forwarded or not. The type of function call can be understood to mean a predefined and / or predefinable type of function call. Function calls can differ in their type, for example, in that function calls of one type relate to the adjustment of lighting devices in the exterior of the vehicle and another type relate to the adjustment of lighting devices in the interior of the vehicle.Other types of function calls can, for example, relate to adjusting the engine, adjusting the air conditioning, and / or adjusting the infotainment system. Many other, more general or more detailed types of function calls are conceivable. When performing the check based on the determined type, the determined type can be compared with predefined types. If the determined type corresponds to one of the predefined types, or if the determined type does not correspond to a predefined type, the function call data can be forwarded or not forwarded. This also allows unwanted function calls to be prevented in a simple and reliable manner.

[0019] According to a further embodiment of the present invention, it is possible for the security layer in a control system to be configured to determine the amount of payload of the function call data and to perform the check based on the determined amount of payload. In other words, depending on the determined amount of payload, the function call data can be forwarded or not. By checking all function calls towards the vehicle for the amount of payload they contain or the corresponding payload, it is possible, for example, to prevent an excessive amount of payload from overloading the operating system and in particular the associated communication bus system, and consequently leading to system instability. The check based on the determined amount of payload can be performed by comparing the determined amount of payload with a predefined or predefinable reference amount of payload.If the predefined reference payload volume is reached or exceeded, the forwarding of the function call data is prevented. The reference payload volume can be predefined based on a maximum permissible bus load for the respective vehicle; exceeding this maximum load would result in an overload of the communication bus system. The check based on the determined payload volume can also be understood to mean that the payload volume is assessed and / or checked to see whether the data in the payload volume is within the correct or predefined and / or desired range. This can also prevent problems in components, as it can prevent components from becoming inaccessible and / or lying outside of an operating range, for example.

[0020] Furthermore, in a control system according to the invention, it is possible for the security layer to be configured to detect an anomaly in the function call data and to perform the check based on the detected anomaly. In other words, depending on a detected anomaly, the function call data can be forwarded or not. This also makes it possible to easily and reliably ensure the system stability of the operating system. Anomalies can be detected in particular when the function call data contains multiple function calls or when multiple function calls are detected based on the function call data. An anomaly can be detected when a function call or function calls are detected that would never occur under predefined conditions.An anomaly can also be understood as an unexpected change or an unexpected deviation from an expected pattern in a data set. The anomaly can be detected using artificial intelligence. Accordingly, the security layer can have a detection unit, for example, with artificial intelligence, to detect the anomaly accordingly.

[0021] Furthermore, in a control system according to the present invention, it is possible for the security layer to be configured to assess the plausibility of at least one function call in the function call data and to perform the check based on the assessed plausibility. In other words, depending on the assessed plausibility, the function call data can be forwarded or not. This also makes it possible to easily and reliably ensure the system stability of the operating system. The plausibility of the system call data or the corresponding system calls can be assessed or checked, for example, with reference to a timestamp. This means that if the timestamp does not match the current system time of the vehicle, the function call data can be assessed as implausible, and forwarding of the function call data can be prohibited.Plausibility can be assessed using artificial intelligence. Accordingly, the security layer can have an investigative unit, for example, with artificial intelligence, to assess plausibility accordingly.

[0022] According to a further embodiment of the present invention, it is possible for the safety layer in a control system to be configured to determine the operating state of the vehicle and to perform the check based on the determined operating state of the vehicle. In other words, the function call data can be forwarded or not depending on the determined operating state of the vehicle. This can also contribute to the desired system stability in a relatively simple manner. The rule set described above can be provided as part of the safety layer and configured to configure itself automatically based on an operating state of the vehicle. Based on the operating state, it can be determined, for example, whether the vehicle is currently stationary or moving and at what speed and / or direction the vehicle is moving.The vehicle's operating state can be influenced by parameters relating to the engine and / or a possible drive battery. Depending on the determined operating state of the vehicle, various functions can be prohibited in the operating system. Depending on the defined permitted and prohibited functions, certain function call data or corresponding function calls can be forwarded or not. If the vehicle is in an autonomous operating state, for example, in a dangerous situation in which manual intervention by the driver in the ferry operation is not permitted, function calls for changing the driving behavior by third-party programs are not forwarded to the operating system or are blocked accordingly in the security layer.Accordingly, it is possible for the security layer in a Kontra II system according to the invention to be configured to determine the functional state of functional modules for executing the operating system and to perform the check based on the determined functional state of the functional modules or at least one functional module. Functional modules can be understood to mean, in particular, functional modules such as a main memory, a processor, a communications bus system, and / or a data storage device, each of which can be understood as part of the operating system. If it is detected that the functional modules are already at full capacity, at least certain functional requests from the third-party program could lead to an overload of the operating system. This can be reliably prevented in the proposed manner.

[0023] A further aspect of the invention relates to a vehicle with a Kontra II system as described above. Thus, the vehicle according to the invention offers the same advantages as those described in detail with reference to the control system according to the invention. The term "vehicle" refers, in particular, to a road vehicle, for example, a car or a truck. However, the term "vehicle" can also be understood to mean a rail vehicle, a watercraft, an aircraft, or a robot.

[0024] A further aspect of the invention relates to a method for controlling function calls in a vehicle as described above, comprising the steps:

[0025] Sending function call data from a third-party program to the connection layer of the programming interface,

[0026] Sending the function call data from the binding layer to the security layer, checking the function call data by the security layer, and

[0027] Allow or prevent the function call data from being sent from the security layer to the communication layer based on the verification performed.

[0028] Thus, the method according to the invention also provides the advantages described above. The method can be configured to operate the control system described above. Thus, the following steps can be performed within the scope of the method: Determining a number of function calls in the function call data and performing the check based on the determined number of function calls; Determining a type of at least one function call in the function call data and performing the check based on the determined type of the at least one function call;

[0029] Determining a payload of the function call data and performing the check based on the determined payload,

[0030] Detecting an anomaly in the function call data and performing the check based on the detected anomaly,

[0031] Assessing a plausibility for at least one function call in the function call data and performing the check based on the assessed plausibility, determining an operating state of the vehicle and performing the check based on the determined operating state of the vehicle, and / or

[0032] Determining a functional state of functional modules for executing the operating system and performing the check based on the determined functional state of the operating system.

[0033] A further aspect of the invention relates to a computer program product comprising instructions that cause the control system described above to execute or be able to execute the described method steps. Furthermore, the invention relates to a computer-readable, in particular non-volatile, storage medium on which such a computer program product is stored. Thus, the computer program product according to the invention and the storage medium according to the invention also provide the advantages described above.

[0034] The computer program product may be implemented as computer-readable instruction code in any suitable programming language and / or machine language, such as JAVA, C++, C#, and / or Python. The computer program product may be stored on a computer-readable storage medium, such as a data disk, a removable drive, volatile or non-volatile memory, or a built-in memory / processor. The instruction code may program a computer or other programmable devices, such as a control unit that may be part of the control system, to perform the desired functions. Furthermore, the computer program product may be provided and / or be provided on a network, such as the Internet, from which it can be downloaded by a user as needed.The computer program product can be and / or be implemented by means of software as well as by means of one or more special electronic circuits, i.e. in hardware or in any hybrid form, i.e. by means of software components and hardware components.

[0035] Further measures improving the invention will become apparent from the following description of various exemplary embodiments of the invention, which are schematically illustrated in the figures. All features and / or advantages apparent from the claims, the description, or the figures, including structural details and spatial arrangements, may be essential to the invention both individually and in various combinations.

[0036] They show schematically:

[0037] Figure 1 is a block diagram for explaining a control system according to the invention and a method for controlling function calls in a vehicle,

[0038] Figure 2 shows a storage medium with a computer program product stored thereon according to an embodiment of the invention, and

[0039] Figure 3 shows a vehicle with a control system according to an embodiment of the invention.

[0040] Fig. 1 shows a control system 10 for controlling function calls and associated functions in a vehicle 11, which is illustrated in Fig. 3. The control system 10 has a programming interface 12 for connecting a third-party program 13 to a computer-implemented operating system 14 of the vehicle 11. If the third-party program 13 is connected to the programming interface 12, the third-party program 13 can send function call data via the programming interface 12 to the operating system 14 so that the function calls contained in the function call data, or at least one contained function call, can be executed in the vehicle 11. For this purpose, the programming interface 12 has a connection layer 15 for sending the function call data from the third-party program 13 to the programming interface 12 and a communication layer 18 for sending the function call data from the programming interface 12 to the operating system 14.Furthermore, the illustrated programming interface 12 has a security layer 16 provided between the connection layer 15 and the communication layer 18 and a protocol layer 17 provided between the security layer 16 and the communication layer 18.

[0041] The security layer 16 is configured to perform a check of the function call data sent from the connection layer 15 to the security layer 16 with respect to ensuring the system stability of the operating system 14. Furthermore, the security layer 16 is configured to enable or prevent the function call data from the security layer 16 from being sent to the communication layer 18 based on the check performed, or in this case, to forward it to the protocol layer 17 or not depending on the check.

[0042] The security layer 16 shown in Fig. 1 is configured to perform the check in two stages, with a first check stage performing the check with respect to the system stability of the operating system 14, and a second check stage performing a check with respect to vehicle and / or vehicle occupant safety. For this purpose, the security layer 16 is embedded in the communication flow between the connection layer 15 and the communication layer 18, and correspondingly in the communication flow between the third-party program 13 and the operating system 14.To perform the first verification level, the security layer 16 is configured to determine a number of function calls in the function call data, to determine the type of at least one function call in the function call data and to determine the amount of payload data of the function call data, to determine the functional state of function modules for executing the operating system 14 and / or to perform the verification based on the determined number of function calls, based on the determined type of the at least one function call, based on the determined functional state of the function modules and / or based on the determined amount of payload data.To perform the second verification level, the security layer 16 is configured to detect an anomaly in the function call data, assess the plausibility for at least one function call in the function call data and / or assess the operating state of the vehicle, and perform the verification based on the detected anomaly, based on the assessed plausibility and / or based on the detected operating state of the vehicle 11.

[0043] If the check was successfully performed and the security layer 16 decides that the function call data may be forwarded or that sending the function call data is permitted, the function call data is sent further toward the communication layer 18 according to the arrow shown in Fig. 1. However, if the check determines that the function call data may not be forwarded or that sending the function call data should be prevented, the function call data is not forwarded toward the operating system. Instead, a corresponding error message is sent to the third-party program 13, as shown by the dashed arrow in Fig. 1.

[0044] With reference to Fig. 1, a method for controlling function calls in a vehicle 11 can be further described. To execute the method, function call data is first sent from the third-party program 13 to the connection layer 15. Subsequently, function call data is sent from the connection layer 15 to the security layer 16. The function call data is then checked by the security layer 16, as described in detail above. Depending on the check, forwarding of the function call data from the security layer 16 to the communication layer 18 is enabled or disabled.

[0045] Fig. 2 shows a computer-readable and non-volatile storage medium 20 in the form of a memory stick or flash drive. A computer program product 19 is stored on the storage medium 20, which includes instructions that cause the control system 10 shown and described to execute the method steps described above.

[0046] Fig. 3 shows a vehicle 11 in the form of an autonomously drivable electric vehicle in which the control system 10 shown in Fig. 1 is installed.

[0047] The invention permits further design principles in addition to the embodiments illustrated. This means that the invention should not be considered limited to the embodiments explained with reference to the figures. List of reference symbols

[0048] Control system Vehicle Programming interface Third-party program Operating system Connectivity layer Security layer Protocol layer

[0049] Communication layer Computer program product Storage medium

Claims

Patent claims 1. Kontra 11 system (10) for controlling function calls in a vehicle (11), comprising a programming interface (12) for connecting a third-party program (13) to a computer-implemented operating system (14) of the vehicle (11) for sending function call data from the third-party program (13) to the operating system (14) for executing function calls in the vehicle (11), wherein the programming interface (12) has a connection layer (15) for sending the function call data from the third-party program (13) to the programming interface (12) and a communication layer (18) for sending the function call data from the programming interface (12) to the operating system (14), characterized in that the programming interface (12) further comprises a connection layer (15) for sending the function call data from the third-party program (13) to the operating system (14), characterized in that the programming interface (12) further comprises a connection layer (15) for sending the function call data from the third-party program (13) to the operating system (14), characterized in that the programming interface (12) further comprises a connection layer (15) for sending the function call data from the third-party program (13) to the operating system (14), characterized in that the programming interface (12) further comprises a connection layer (18 ... (15) and the communication layer (18), which is configured to carry out a check of the function call data sent from the connection layer (15) to the security layer (16) with regard to a system stability of the operating system (14) to be ensured and to enable or prevent a sending of the function call data from the security layer (16) towards the communication layer (18) based on the check carried out.

2. Kontra II system (10) according to claim 1, characterized in that the security layer (16) is configured to determine a number of function calls in the function call data and to perform the check based on the determined number of function calls.

3. Kontra II system (10) according to one of the preceding claims, characterized in that the security layer (16) is configured to determine the type of at least one function call in the function call data and to perform the check based on the determined type of the at least one function call.

4. Kontra II system (10) according to one of the preceding claims, characterized in that the security layer (16) is configured to determine the amount of payload data of the function call data and to perform the check based on the determined amount of payload data.

5. Kontra II system (10) according to one of the preceding claims, characterized in that the security layer (16) is configured to detect an anomaly in the function call data and to perform the check based on the detected anomaly.

6. Kontra II system (10) according to one of the preceding claims, characterized in that the security layer (16) is configured to assess the plausibility for at least one function call in the function call data and to perform the check based on the assessed plausibility.

7. Kontra II system (10) according to one of the preceding claims, characterized in that the security layer (16) is configured to determine the operating state of the vehicle (11) and to carry out the check based on the determined operating state of the vehicle (11).

8. Kontra II system (10) according to one of the preceding claims, characterized in that the security layer (16) is configured to determine the functional state of functional modules for executing the operating system (14) and to carry out the check based on the determined functional state of the functional modules.

9. Vehicle (11) with a control system (10) according to one of the preceding claims.

10. Method (10) for controlling function calls in a vehicle (11) according to claim 9, comprising: Sending function call data from a third-party program (13) to the connection layer (15) of the programming interface (12), Sending the function call data from the connection layer (15) to the security layer (16), Verifying the function call data by the security layer (16), and enabling or preventing the function call data from being sent from the security layer (16) towards the communication layer (18) based on the verification performed.

11. Method (10) according to claim 10 for operating the control system (10) according to one of claims 1 to 8.

12. Computer program product (19) comprising instructions which cause the Kontra II system (10) according to one of claims 1 to 8 to carry out the method steps according to one of claims 10 to 11.

13. A computer-readable storage medium (20) having a computer program product (19) according to claim 12 stored thereon.