Method for authorisation management, computer program product and vehicle
Patent Information
- Application Number
- EP2024716662
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-30
- Filing Date
- 2024-03-22
- Publication Date
- 2026-02-11
AI Technical Summary
Existing authorization management systems for vehicle functions-on-demand are vulnerable to manipulation, lacking effective means to detect unauthorized use and prevent unauthorized execution, particularly at the vehicle level.
A method that involves detecting physical parameters associated with the execution of vehicle functions, such as power supply currents, using a control unit to identify unauthorized use and implement reaction measures, including deactivation of the function and reporting to a control center, enhancing security against manipulation.
This approach provides reliable detection and prevention of unauthorized use by leveraging physical parameters, increasing security against manipulation and enabling robust authorization management, even in complex vehicle systems.
Smart Images

Figure EP2024057776_03102024_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Authorization management procedures, computer program product and vehicle
[0003] The invention relates to a method for authorization management for at least one electrical functional unit for executing a vehicle function in a vehicle, a computer program product and a vehicle.
[0004] It is well known that software-based functionalities on demand, also known as functions on demand, are increasingly finding their way into production vehicles from various vehicle manufacturers. The basic idea of functions on demand is that the hardware required for a function is always included in the vehicle, but the functionality can be activated via software for a fee. However, this activation of functionalities via software, with the hardware always present, can be vulnerable to manipulation of the software, allowing unauthorized use by the vehicle user.
[0005] For this purpose, it is known from EP 3665 891 B1, for example, to secure a function-on-demand functionality using blockchain technology. However, to better detect local manipulation at the vehicle level, expanded diagnostic capabilities in the vehicle are desirable.
[0006] It is an object of the present invention to at least partially remedy the above-mentioned disadvantages known from the prior art. In particular, it is an object of the present invention to improve authorization management for at least one functional unit and, preferably, to reliably enable physical detection of tampering in the vehicle.
[0007] The above object is achieved by a method having the features of claim 1, a computer program product having the features of claim 9, and a vehicle having the features of claim 10. Further features and details of the invention emerge from the respective subclaims, the description and the drawings. Features and details described in connection with the method according to the invention naturally also apply in connection with the computer program product according to the invention and / or the vehicle according to the invention and vice versa, so that with regard to the disclosure of the individual aspects of the invention, reference is or can always be made to each other. According to a first aspect of the invention, a method for authorization management for at least one functional unit for executing a vehicle function in a vehicle is provided.The vehicle function is deactivated, in particular for execution by a user of the vehicle. The method comprises, in particular in the form of method steps: detecting authorization information for executing the vehicle function, in particular by a control unit of the vehicle; detecting a physical parameter associated with the execution of the functional unit, in particular by the control unit; identifying an unauthorized execution of the vehicle function based on the physical parameter and the authorization information, in particular by the control unit; and implementing a response measure depending on the identification of the unauthorized execution, in particular by the control unit.
[0008] The vehicle is, in particular, a motor vehicle, e.g., in the form of an electric vehicle. The functional unit can preferably be an electrical functional unit of the vehicle. The vehicle function can preferably comprise an entertainment function and / or a comfort function of the vehicle. The vehicle function can comprise a primary function and / or a secondary function of the functional unit. For example, the functional unit can comprise a seat heater for heating a vehicle seat, interior lighting for illuminating the vehicle interior, an entertainment system, a navigation system, and / or a massage unit of a vehicle seat. It is conceivable for the authorization management system to comprise multiple vehicle functions.
[0009] Deactivating the vehicle function can prevent the user from executing the vehicle function. Deactivating the vehicle function can involve software- and / or hardware-assisted deactivation. For example, activation, i.e., in particular, starting the vehicle function, can be prevented by the control unit by making the vehicle function unselectable and / or undisplayable to the user via a user interface.
[0010] The authorization information can be a software-supported parameter that identifies the user's authorization. For example, the authorization information can be a Boolean parameter. Furthermore, the authorization information can include information indicating whether the user has subscribed to the vehicle function. The authorization information can be assigned directly to the user, for example, via a user profile or a vehicle key. However, it is also conceivable for the authorization information to be assigned to the vehicle. When the deactivation of the vehicle function is detected based on the authorization information, it can be checked whether the user is authorized to execute the vehicle function. For this purpose, the authorization information itself can be checked, for example if the authorization information is a Boolean parameter.However, it is also conceivable that the authorization information includes a target value of the physical parameter.
[0011] The physical parameter can be assigned to the vehicle function, in particular directly or indirectly. For example, the physical parameter can be a physical quantity by which the functional unit is operated when executing the vehicle function and / or which is influenced by the functional unit when executing the vehicle function. For example, the physical parameter can comprise a temperature, a voltage, an amperage and / or a volume flow. To detect the physical parameter, an actual value of the physical parameter can be measured, in particular in the vehicle and / or at the functional unit. Furthermore, it is conceivable that a profile of the physical parameter is detected, in particular recorded, when the physical parameter is detected.
[0012] Identifying unauthorized execution of the vehicle function based on the physical parameter may include checking the actual value of the physical parameter, e.g., by verifying whether the actual value indicates that the vehicle function is being executed. Furthermore, the history of the physical parameter may be reviewed with regard to unauthorized execution of the vehicle function.
[0013] For example, the execution of the vehicle function can be identified based on certain patterns and / or peaks in the history. For example, if the authorization information includes a target value of the physical parameter, unauthorized execution of the vehicle function can be identified by comparing the target value and the actual value. If the authorization information includes a Boolean parameter, unauthorized execution of the vehicle function can be determined based on the authorization information, for example, if a non-zero value of the physical parameter is present.
[0014] In particular, the response measure can only be implemented if unauthorized execution has been detected. However, it is also conceivable that the response measure is also implemented if no unauthorized execution has been detected. In this case, the response measure could, for example, include a notification to a control center.
[0015] In contrast to checking control signals, e.g., on a vehicle's CAN bus, the detection of the physical parameter offers a high degree of security against manipulation. This allows for verification at the physical level as to whether the vehicle function is being used. Within the scope of the present invention, it has been recognized that identifying unauthorized execution based on the physical parameter assigned to the functional unit has the advantage that the physical parameter cannot be manipulated or can only be manipulated with great effort, particularly if the vehicle function cannot be used without influencing and / or changing the physical parameter.
[0016] Furthermore, in a method according to the invention it can advantageously be provided that the physical parameter is a current parameter of a power supply of the functional unit. The current parameter can in particular comprise a voltage and / or a current strength of the power supply. The power supply can comprise cables, fuses and / or a power source, such as a vehicle battery, in the vehicle. The current parameter can be measured directly at the functional unit and / or at a central or decentralized location in the vehicle. In particular, if the functional unit is an electrical functional unit, the power supply may be necessary to execute the vehicle function. As a result, the power supply cannot be bypassed or can only be bypassed with great effort, so that the current parameter represents a reliable indicator for identifying unauthorized execution of the vehicle function.This can increase security against manipulation.
[0017] Furthermore, in a method according to the invention, it can advantageously be provided that the physical parameter is detected by a measurement on an electrical fuse unit for overcurrent protection, which protects the functional unit. The fuse unit can comprise at least one electrical fuse for protecting the electrical system of the vehicle, in particular with the functional unit, against overcurrents and / or overvoltages. The fuse unit can be designed to interrupt the power supply to the functional unit, in particular for the vehicle function. For example, the electrical fuse can be formed by a fuse. Furthermore, the fuse unit can comprise, for example, a self-resetting fuse, in particular also called a "PTC fuse."The control element can comprise a resistor that reduces its electrical conductivity in the event of overcurrent or overheating, thereby reducing or completely interrupting the current flow of the power supply. Furthermore, the fuse unit can comprise a vehicle fuse box. Particularly if the physical parameter includes a current parameter and / or a temperature, a change in the physical parameter can be detected at the fuse unit. Furthermore, high reliability can be achieved by measuring the fuse unit. Furthermore, tampering with the fuse unit can be easily detected, for example, in a workshop.
[0018] Furthermore, in a method according to the invention, it can advantageously be provided that the security unit is formed by an electronic control element of a control unit of the vehicle, in particular wherein the physical parameter is detected by the control element. The electronic control element can comprise a semiconductor switch, in particular an intelligent one, and / or be designed as an electronic fuse for monitoring current flows. In this case, the control element can be designed to interrupt the power supply of the functional unit, in particular for the vehicle function. Preferably, the control element can comprise a processor and / or a microprocessor. Thus, the electronic control element can have extended diagnostic options in order to contribute to authorization management in addition to electrical protection.It can be provided that the control element can be controlled, in particular via a communication connection by a central control unit of the vehicle and / or by an external signal to the vehicle, in order to interrupt the execution of the vehicle function.
[0019] It is further conceivable in a method according to the invention that the authorization information for detecting the deactivation of the vehicle function is obtained from a server, in particular on which an authorization parameter for a plurality of vehicle functions of the vehicle is stored, each with an assignment to the user for defining the authorization information. The server can, for example, be part of an external control center. For communication with the server, the vehicle, in particular the control unit, can be connected via a wireless communication connection, e.g. in the form of a cellular connection or a WLAN connection. The user profile can be used to manage vehicle functions to which the user is subscribed. The authorization information can be used to determine, in particular based on the respective authorization parameter, whether the user is authorized to execute the vehicle function.This can simplify the management of authorizations to enable reliable identification of unauthorized execution locally in the vehicle. Furthermore, a method according to the invention can advantageously provide for at least one target state for the physical parameter to be determined, wherein the target state is compared with at least one actual state of the physical parameter to identify unauthorized execution of the vehicle function. The target state can define an expected and / or permitted state of the physical parameter, and in particular of the functional unit. The target state can be determined by capturing the authorization information. In particular, the authorization information can include the target value.In particular, the target state can comprise a target curve, a target value and / or a target value range of the physical parameter and / or the actual state can comprise an actual curve, an actual value and / or an actual value range of the physical parameter. For example, unauthorized execution of the vehicle function can always be detected when an actual value lies outside the target value range and / or deviates from the target value. Furthermore, the authorization information can comprise multiple target states. By determining the target state, unauthorized execution of the vehicle function can be reliably identified even in complex functional units. The target state can preferably be determined as a function of other vehicle functions.For example, the use of a massage function of a vehicle seat can be detected by means of an additional current independently of the use of a seat heater if the massage function and the seat heater are supplied with power together via the power supply.
[0020] Preferably, a method according to the invention can provide for the acquisition of the authorization information and / or the acquisition of the physical parameter to be repeated in a predefined diagnostic cycle, in particular wherein at least one repetition is taken into account when identifying the unauthorized execution and / or when carrying out the reaction measure. Thus, the check to determine whether an unauthorized execution of the vehicle function has occurred can preferably be carried out at regular and / or irregular intervals. For the diagnostic cycle, a time interval for repeating the acquisition of the authorization information and / or the acquisition of the physical parameter can be specified. However, it is also conceivable for the diagnostic cycle to correspond to a driving cycle of the vehicle.For example, the acquisition of authorization information and / or the acquisition of physical parameters can be performed every time the vehicle's engine is started. By taking repetition into account when identifying unauthorized execution and / or during the response action, the identified unauthorized execution can be validated. This can improve reliability and prevent unjustified response measures. By taking repetition into account when performing the response action, tolerance of individual unauthorized executions can be achieved, for example.
[0021] Furthermore, in a method according to the invention, it can advantageously be provided that the reaction measure comprises outputting a notification at a user interface and / or to an external control center. The notification can be output in the form of a signal to the user interface and / or to the external control center, in particular via an electrical and / or wireless connection. The user interface can, for example, comprise a display, an instrument cluster, or a voice output in the vehicle. By outputting the notification to the user interface, the user can be informed that unauthorized execution has been detected. For example, it can be provided that physical deactivation of the vehicle function via the security unit only occurs after one or more warnings.This allows the user to, for example, subsequently book the vehicle function and / or verify a booking of the vehicle function. The control center can, for example, include a server. In particular, by issuing the notification to the control center, information can be sent to the vehicle manufacturer to implement further consequences, such as changes to the warranty agreement.
[0022] According to a further aspect of the invention, a computer program product is provided which comprises instructions which, when executed by a control unit, cause the control unit to carry out a method according to the invention.
[0023] Thus, a computer program product according to the invention brings with it the same advantages as have already been described in detail with reference to a method according to the invention. The method can in particular be a computer-implemented method. The computer program product can be implemented as computer-readable instruction code. Furthermore, the computer program product can be stored on a computer-readable storage medium such as a data disk, a removable drive, a volatile or non-volatile memory, or a built-in memory / processor. Furthermore, the computer program product can be provided or made available in a network such as the Internet, from which it can be downloaded by a user or executed online as needed. The computer program product can be implemented both by means of software and by means of one or more special electronic circuits, i.e.It can be implemented in hardware or in any hybrid form, i.e., using software components and hardware components. According to a further aspect of the invention, a vehicle is provided. The vehicle has a functional unit for executing a vehicle function. Furthermore, the vehicle comprises a control unit for executing a method according to the invention.
[0024] Thus, a vehicle according to the invention offers the same advantages as have already been described in detail with reference to a method according to the invention and / or a computer program product according to the invention. The control unit can comprise a processor and / or a microprocessor. Furthermore, the control unit can be at least partially or completely integrated into a central control unit of the vehicle. However, it is also conceivable for the control unit to be at least partially or completely integrated into one or more decentralized control units. In particular, the security unit can be at least partially or completely part of the control unit.
[0025] Further advantages, features, and details of the invention will become apparent from the following description, which describes embodiments of the invention in detail with reference to the drawings. The features mentioned in the claims and in the description may be essential to the invention individually or in any combination. They show schematically:
[0026] Figure 1 shows a vehicle according to the invention with a control unit for carrying out a method according to the invention,
[0027] Figure 2 shows a schematic flow of the process,
[0028] Figure 3 shows a server with a user profile for providing authorization information in the method.
[0029] In the following description of some embodiments of the invention, the same reference numerals are used for the same technical features even in different embodiments.
[0030] Figure 1 shows a vehicle 1 according to the invention with a functional unit 10 for executing a vehicle function 200 in a first exemplary embodiment. In the present exemplary embodiment, the functional unit 10 is formed by a vehicle seat. The vehicle function 200 comprises operating a seat heater of the vehicle seat. However, the activation of the seat heater and the vehicle seat are used merely as examples in the present exemplary embodiment. It is thus equally conceivable for the vehicle function 200 to comprise an entertainment function and / or another comfort function of the vehicle 1. The functional unit 10 can further comprise, for example, interior lighting for illuminating the vehicle interior, an entertainment system, a navigation system, a massage unit of a vehicle seat, and / or the like.
[0031] The vehicle 1 further comprises a control unit 21 for executing a method 100 according to the invention for authorization management for the at least one functional unit 10. The vehicle function 200 is deactivated for execution by a user of the vehicle 1, e.g., because the user has decided against subscribing to the vehicle function 200. Preferably, a computer program product can be provided that includes commands that, when executed by the control unit 21, cause the control unit 21 to execute the method 100. Figure 2 shows a sequence of the method 100.
[0032] The method 100 comprises capturing 101 authorization information 210 for executing the vehicle function 200. For this purpose, the authorization information 210 for detecting the deactivation of the vehicle function 200 can be obtained from a server 2, on which an authorization parameter 210.1 for a plurality of vehicle functions 200 of the vehicle 1 is stored, each with an assignment to the user for defining the authorization information 210. Such a user profile 211 with a plurality of authorization parameters 210.1 is shown in Figure 3. Authorization management can be simplified by centrally managing the authorization parameters 210.1 on the server 2.
[0033] Furthermore, in the method 100, a physical parameter 220 is detected 102, which is associated with the execution of the functional unit 10. The physical parameter 220 is, in particular, a current parameter of a power supply
[0034] 11 of the functional unit 10. The power supply 11 comprises in particular a vehicle battery 12 of the vehicle 1. To detect 102 the physical parameter 220, a measurement can therefore be carried out on an electrical fuse unit 20 for overcurrent protection, which fuse unit 20 connects the functional unit 10, in particular between the vehicle battery
[0035] 12 and the functional unit 10. Advantageously, the security unit 20 is formed by an electronic control element 22 of the control unit 21 of the vehicle 1. The control element 22 can comprise a measuring device for detecting the physical parameter 220 by the control element 22. Furthermore, the control element 22 can preferably have a processor and / or microprocessor for carrying out security processes.
[0036] In particular, the control element 22 can be controllable by the server 2. Based on the physical parameter 220 and the authorization information 210, an unauthorized execution of the vehicle function 200 is further identified 103. For this purpose, at least one target state 222 for the physical parameter 220 can be determined. The target state 222 is further compared with at least one actual state 221 of the physical parameter 220 in order to identify the unauthorized execution of the vehicle function 200. It can be provided that the authorization information 210 includes the target state 222. However, it is also conceivable that the target state 222 is calculated based on the authorization information 210 and / or further authorization parameters 210.1 of the user profile 211, in particular by the control unit 21.
[0037] Furthermore, a reaction measure 202 is carried out 104 depending on the identification 103 of the unauthorized execution. The reaction measure 202 comprises, in particular, outputting a notification to a user interface (3) and / or to an external control center 4. The server 2 can be part of the control center 4. By outputting the notification, the user and / or the control center 4 can be informed of the identified unauthorized execution of the vehicle function 200.
[0038] Advantageously, the acquisition 101 of the authorization information 210 and / or the acquisition 102 of the physical parameter 220 is repeated in a predefined diagnostic cycle. It can be provided that at least one repetition is taken into account when identifying 103 the unauthorized execution and / or when implementing 104 the response measure 202.
[0039] The above explanation of the embodiments describes the present invention exclusively by way of examples. Of course, individual features of the embodiments can be freely combined with one another, provided they are technically feasible, within the scope of protection defined by the patent claims, without departing from the scope of the present invention.
[0040] List of reference symbols
[0041] vehicle
[0042] server
[0043] User interface
[0044] Control center
[0045] functional unit
[0046] Power supply
[0047] vehicle battery
[0048] fuse unit
[0049] Control unit
[0050] Control element
[0051] Proceedings
[0052] Capturing 210
[0053] Capturing 221
[0054] Identifying unauthorized execution
[0055] Performing 202
[0056] Vehicle function
[0057] Response measure
[0058] Authorization information
[0059] Authorization parameters
[0060] User profile
[0061] parameter
[0062] It's on
[0063] Target state
Claims
Patent claims 1. A method (100) for authorization management for at least one functional unit (10) for executing a vehicle function (200) in a vehicle (1), wherein the vehicle function (200) is deactivated for execution by a user of the vehicle (1), the method (100) comprising: detecting (101) authorization information (210) for executing the vehicle function (200), detecting (102) a physical parameter (220) associated with the execution of the functional unit (10), Identifying (103) an unauthorized execution of the vehicle function (200) based on the physical parameter (220) and the authorization information (210), Carrying out (104) a reaction measure (202) in dependence on the identification (103) of the unauthorized execution.
2. Method (100) according to claim 1, characterized in that the physical parameter (220) is a current parameter of a power supply (11) of the functional unit (10).
3. Method (100) according to claim 1 or 2, characterized in that the detection (102) of the physical parameter (220) is carried out by a measurement on an electrical fuse unit (20) for overcurrent protection, which protects the functional unit (10).
4. Method (100) according to one of the preceding claims, characterized in that the security unit (20) is formed by an electronic control element (22) of a control unit (21) of the vehicle (1), wherein the physical parameter (220) is detected by the control element (22).
5. Method (100) according to one of the preceding claims, characterized in that that the authorization information (210) for detecting the deactivation of the vehicle function (200) is obtained from a server (2) on which an authorization parameter (210.1) for a plurality of vehicle functions (200) of the vehicle (1) is stored with an assignment to the user for defining the authorization information (210).
6. Method (100) according to one of the preceding claims, characterized in that at least one target state (222) for the physical parameter (220) is determined, wherein the target state (222) is compared with at least one actual state (221) of the physical parameter (220) in order to identify (103) the unauthorized execution of the vehicle function (200).
7. Method (100) according to one of the preceding claims, characterized in that the acquisition (101) of the authorization information (210) and / or the acquisition (102) of the physical parameter (220) is repeated in a predefined diagnostic cycle, wherein at least one repetition is taken into account when identifying (103) the unauthorized execution and / or when carrying out (104) the reaction measure (202).
8. Method (100) according to one of the preceding claims, characterized in that the reaction measure (202) comprises outputting a message to a user interface (3) and / or to an external control center (4).
9. A computer program product comprising instructions which, when executed by a control unit (21), cause the control unit (21) to execute a method (100) according to any one of the preceding claims.
10. Vehicle (1) comprising a functional unit (10) for executing a vehicle function (200), and a control unit (21) for executing a method (100) according to one of claims 1 to 8.