Authentication method of a diagnostic tool connectable to the on-board telematic network of a transport vehicle
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- PIAGGIO & C SPA
- Filing Date
- 2024-07-01
- Publication Date
- 2026-06-03
AI Technical Summary
Existing authentication methods for diagnostic tools connected to the on-board telematic network of transport vehicles are costly due to the need for software authentication libraries and frequent updates, and they do not adequately address the need for secure access and traceability.
An authentication method that uses a secure gateway on the transport vehicle to authenticate diagnostic tools by inputting binary codes through control devices, with remote authentication server verification, eliminating the need for software updates on the diagnostic tools.
This solution provides a cost-effective and secure authentication method that ensures only authorized access to the on-board telematic network, while also enabling traceability of access attempts, thus enhancing cybersecurity and compliance with emerging standards.
Smart Images

Figure IB2024056425_30012025_PF_FP_ABST
Abstract
Description
Authentication method of a diagnostic tool connectable to the on-board telematic network of a transport vehicle***TECHNICAL FIELD OF THE INVENTION
[0001] The present invention relates to the technical sector of on-board diagnostics in the field of transportation, and in particular relates to an authentication method of a diagnostic tool operatively connectable to the on-board telematic network of a transport vehicle. The present invention also relates to a transport vehicle comprising an on-board telematic network comprising an on-board diagnostic connector.BACKGROUND OF THE INVENTION
[0002] Diagnostic methods and systems according to which a diagnostic tool is operatively connected to the on-board telematic network of a transport vehicle, such as a motor vehicle or a motorcycle, for example, have been known for a long time. Such an operating connection allows, for example, a maintenance operator or law enforcement authorities to check, by means of the diagnostic tool, the correct operation of the transport vehicle and / or to detect any breakdowns of the transport vehicle and / or to acquire information on the state of the vehicle by accessing vehicle data made available on the on-board telematic network.
[0003] The aforesaid operating connection generally occurs by means of an on-board diagnostic connector, also referred to as an OBD (On-Board Diagnostics) connector provided on board the transport vehicle. The OBD connector is adapted to be operatively connected to a complementary connector with which the diagnostic tool is provided. The on-board diagnostic connector of the transport vehicle allows the diagnostic tool to access an on-board data communication bus of the transport vehicle, such as a CAN bus, for example, to allow the diagnostic tool to transmit and / or receive data transiting on the on-board telematic network. Generally, the data relating to the state and / or operation of the transport vehicle are transmitted to the on-board data communication bus by one or more electronic control units of the transport vehicle.
[0004] More recently, in particular with the implementation of the standard called OBD 2, for reasons associated with cybernetic security and the need to control accesses made to the onboard telematic network by means of the diagnostic tools, the need has arisen to define and implement authentication routines to the on-board telematic network.
[0005] The authentication relates to checking the identity of the user and tracing the accesses to the on-board telematic network by the diagnostic tool for statistical purposes and / or controlling undue intrusions.
[0006] The issue is allowing access both to the on-board telematic network and to diagnostic tools of independent maintenance operators, i.e., not belonging to the official network of the maintenance operators authorized by vehicle manufacturers, and to vehicle manufacturers toidentify when accesses are made to the on-board telematic network by means of the diagnostic tools to detect if skilled attempts to electronically tamper with the electronic control units of the transport vehicles were made simultaneously to the accesses.
[0007] Cybersecurity will be one of the next standards on newly type-approved transport vehicles to respond to the increasingly widespread connectivity of vehicles. Increasingly, transport vehicles may receive OTA (Over The Air) updates, provide remote access to the owner or the virtual key holder and be remotely controlled. A technological revolution that the UNECE (United Nations Economic Commission for Europe) has regulated with two international standards focusing on cybersecurity and software updates.
[0008] The new regulations - which implement ISO Standards 21434 - obligate vehicle manufacturers to ensure computer security and the security of the software updates in vehicles prior to making them available on public roads. The regulation on cybersecurity in automobiles is divided into two main parts:- a computer security management system (CSMS);- the requirements of the type of transport vehicle.
[0009] The CSMS requirements concern the processes during the entire lifecycle of the transport vehicle, including design, development, production, post-production monitoring and disposal.
[0010] The standards include defining roles and responsibilities, managing security risks, determining the necessary controls, corrective interventions, etc. All these processes are to be documented and made available to the type-approval authorities during the check.
[0011] As for the requirements of the type of transport vehicle, there will be provided the validation that the documented processes be correctly applied to each type of vehicle for which the required type-approval is provided.
[0012] Today, a transport vehicle is part of an ecosystem where, in addition to the driver and passengers, other elements interacting with it are involved, such as:- road infrastructure;- traffic and navigation messaging;- various software applications;- suppliers of components and the Cloud and loT world in general.
[0013] Each single part of this ecosystem must play an active role in cybersecurity, including the diagnostic tools for reading the error codes of the transport vehicles.
[0014] In general, the transport vehicle manufacturer is obligated to provide both the document information and the information obtainable by the OBD technology prepared for repair and maintenance, for each diagnostic tool configured to read the diagnostic tools. Conventionally, every maintenance operation begins by reading the codes that each electronic control unit provides to the diagnostic tools should there be a malfunction.
[0015] Therefore, any diagnostic tool connected to a vehicle network (conventionally, a CAN network) potentially must be able to be connected to the transport vehicle, and the vehicle itself must be protected from vulnerabilities due to cyber attacks.
[0016] Usually, the solution adopted in the prior art is the provision of software authentication libraries provided by the manufacturer and made available to the diagnostic tool producer to be loaded thereon so as to allow the authentication of the diagnostic tool with respect to the vehicle and the Internet.
[0017] In any case, the above solution is quite expensive for the diagnostic tool producer due to the need to upload and constantly update software libraries in the diagnostic tool.
[0018] It is a general object of the present invention to provide a relatively more affordable authentication solution which is capable of completely or at least partially resolving one or more of the drawbacks of the above-described authentication methods and systems of the prior art.
[0019] Such an object is achieved by an authentication method as generally defined in claim 1 . Preferred and advantageous embodiments of the aforementioned authentication method are defined in the appended dependent claims. Such an object is also achieved by a transport vehicle as defined in claim 13.
[0020] The invention will be better understood from the following detailed description of particular embodiments thereof, given by way of non-limiting example, with reference to the accompanying drawings briefly described in the following paragraph.BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In the accompanying drawings:Figure 1 is an isometric view of a non-limiting embodiment of a transport vehicle;Figure 2 is a simplified functional block diagram of an example of an authentication system by means of which the authentication method according to the present invention can be implemented;Figure 3 is a simplified flow diagram of a non-limiting embodiment of an authentication method according to the present invention;Figure 4 is a flow diagram showing further optional steps of the authentication method in Figure 3.DETAILED DESCRIPTION
[0022] The same or similar elements are indicated by the same reference numerals in the accompanying drawings.
[0023] Figure 1 shows an embodiment of a transport vehicle 1 , which in the particular example shown, without introducing any limitation, is a lightweight commercial transport vehicle equipped with a thermal or hybrid electric propulsion engine 7 (indicated by only one symbol in the block diagram in Figure 2).
[0024] The transport vehicle 1 comprises four wheels 2, only three of which are shown in Figure 1 . As known per se, the transport vehicle 1 comprises a driver’s compartment 3 and a loading portion 4. In alternative embodiments, the transport vehicle 1 could be a motor vehicle, a van, a mini car, a truck, a bus, etc. The transport vehicle 1 could also be a three-wheel truck or a two- or three-wheel motorcycle.
[0025] Hereinafter, in the present description, without however introducing any limitation, reference will be made to a general transport vehicle 1 , meaning that the following description may be generally applied to any type of road transport vehicle 1 comprising:- a thermal or hybrid electric propulsion engine 7;- at least two wheels 2.
[0026] Figure 2 shows an embodiment of an example of an authentication system 50 by means of which an authentication method 100 according to the present invention may be implemented.
[0027] The authentication system 50 comprises an on-board telematic network 10 of the transport vehicle 1 , i.e., a telematic network 10 comprised in the on-board equipment of the transport vehicle 1 , and a diagnostic tool 30 operatively connectable to the on-board telematic network 10 of the transport vehicle 1. Conveniently, the on-board telematic network 10 is a wired network.
[0028] The on-board telematic network 10 comprises a data communication bus 13, which is preferably a CAN bus. In an alternative embodiment, the data communication bus 13 is an Ethernet bus.
[0029] The on-board telematic network 10 comprises an on-board diagnostic connector 11 , which conveniently and as known per se, is a multipole electrical connector. The on-board diagnostic connector 11 allows connecting the diagnostic tool 30 to the on-board telematic network 10. Through the on-board diagnostic tool 30, a maintenance operator and / or law enforcement agencies can thus acquire diagnostic data relating the state and / or operation of the transport vehicle 1 , for example, in order to identify a breakdown in and / or an anomaly and / or tampering with the transport vehicle 1 . Preferably, the on-board diagnostic connector 1 1 is housed inside the driver’s compartment 3 of the transport vehicle 1 .
[0030] In order to connect the diagnostic tool 30 to the on-board telematic network 10, the diagnostic tool 30 comprises a complementary connector 31 which may be operatively removably connected to the on-board diagnostic connector 1 1 . Complementary connector 31 means a connector configured to be operatively connected (in this case therefore, mechanically coupled and electrically coupled) to the on-board diagnostic connector 11. According to an embodiment, the on-board diagnostic connector 11 and the complementary connector 31 are OBD connectors, OBD2 connectors in particular.
[0031] As known per se, the diagnostic tool 30 comprises a display 32 and a keyboard 34. Optionally, display 32 is a touchscreen display and in this case, keyboard 34 may be optional. Conveniently, the diagnostic tool 30 comprises an external electric cable 33 at a free end portion of which the complementary connector 31 is arranged. The diagnostic tool 30 is, for example, a dedicated device, i.e., a device specifically designed and sold to perform diagnostic analyses of transport vehicles 1. Alternatively, the diagnostic tool 30 could be a general- purpose computer, e.g., a personal computer, such as a desktop computer, a laptop or a PC tablet, for example, provided with hardware and software resources making it suitable for performing diagnostic analyses of transport vehicles 1 .
[0032] As known per se, the on-board telematic network 10 of the transport vehicle 1 comprises, or is connected to, one or more electronic control units 27, 28, 29 which are operatively connected to the data communication bus 13 to transmit and / or receive data through the data communication bus 13. Therefore, one or more control and / or processing units 27, 28, 29 intended to control the operation of the transport vehicle 1 belong to the onboard telematic network 10, or are connected thereto.
[0033] For example, the transport vehicle 1 comprises an electronic propulsion control unit 27 operatively connected to the propulsion engine 7, configured to control the propulsion engine 7 and to acquire state and / or operating data of the propulsion engine 7. The electronic propulsion control unit 27 is generally referred to as an Engine Control Unit (ECU). This electronic control unit 27 is connected to the data communication bus 13.
[0034] In addition to the electronic propulsion control unit 27, the transport vehicle 1 may comprise one or more further electronic control units 28, 29, for example, an electronic control unit 28 of an assisted driving system 8 and / or an electronic control unit 29 of the on-board infotainment system 9 of the transport vehicle 1 .
[0035] It goes without saying that the teachings of the present description leave aside the number and type of electronic control unit 27, 28, 29 of the transport vehicle 1 which are connected to the data communication bus 13 since they are notions well known to those skilled in the automotive field.
[0036] The on-board telematic network 10 further comprises a secure gateway 12 configured to take a locked state and an unlocked state, in which the secure gateway 12 prevents and allows, respectively, a data transmission through the on-board diagnostic connector 1 1. A secure gateway 12 in the automotive field is a processing unit, such as a processor, a microcontroller or an SOC (System On Chip), for example, on board which there is installed a software or firmware code intended to perform security functions when exchanging data on the on-board telematic network 10 and to control access from the outside of the on-board telematic network 10, for example, by means of encryption and / or authentication procedures.
[0037] In the particular example shown in Figure 2, the secure gateway 12 is operatively interposed between the on-board diagnostic connector 1 1 and the data communication bus 13.
[0038] According to an advantageous embodiment, the on-board telematic network 10 of the transport vehicle 1 comprises a short-range wireless communication interface 14, such as a Bluetooth or BLE (Bluetooth Low Energy) interface operatively connected to the secure gateway 12, for example.
[0039] Again with reference to Figure 2, the transport vehicle 1 comprises at least one control device 5a, 5b operatively connected to the on-board telematic network 10 and configured to be moved by a driver to control the transport vehicle 1 during the driving of the transport vehicle 1 . Preferably, said at least one control device 5a, 5b comprises at least one pedal control lever and / or at least one manual control lever. For example, said at least one control device 5a, 5b comprises at least one of: a brake lever, a clutch lever, a throttle grip, an accelerator lever.
[0040] According to a preferred embodiment, the aforesaid at least one control device 5a, 5b comprises at least two control devices 5a, 5b. The provision of at least two control devices 5a, 5b allows a user to input a binary code into the on-board telematic network 10, for example, where a 1 (or generally, a first logic level) is inputted by actuating one of said control devices and where a 0 (or generally, a second logic level) is inputted by actuating the other control device. For example, the aforesaid at least one control device 5a, 5b comprises two elements of: a pedal brake lever, a pedal accelerator lever, a pedal clutch lever. This is only an example which may be easily varied based on the type of control devices on board the transport vehicle 1 . For example, a clutch lever is not provided in a transport vehicle 1 with an automatic gear, while both a pedal brake lever and a pedal accelerator lever are provided. Moreover, the accelerator lever is replaced by a throttle grip in motorcycles.
[0041] The binary code is a code having N bits, where N is a positive integer, preferably greater than or equal to five, for example, equal to six or eight. It therefore can be deduced how said binary code may comprise a plurality of bits.
[0042] In the particular example shown in Figure 2, the on-board telematic network 10 comprises a data acquisition and transmission unit 15 operatively connected to the at least one control device 5a, 5b and operatively connected to the data communication bus 13. Such a data acquisition and transmission unit 15 allows a sequence of movements imparted to the control device 5a, 5b by a maintenance operator to be translated into a binary code, and such a binary code to be transmitted to the data communication bus 13. However, note that there is no need for such a function to be performed by a dedicated unit, such as the data acquisition and transmission unit 15, since such a function could be performed by any electronic controlunit 27, 28, 29 installed on board the transport vehicle 1 , or it could also be performed by the secure gateway 12 itself.
[0043] By way of example, suppose that the binary code is a six bit code, thus N = 6. If two control devices 5a, 5b are provided, such as a brake pedal 5a and an accelerator pedal 5b, for example, it is possible to establish that logic level 0 is associated each time the brake pedal 5a is pressed, and logic level 1 is associated each time the accelerator pedal 5b is pressed. Therefore, for example, in order to input the binary code 1101 10, it will be sufficient to perform the following sequence of movements:Press accelerator pedal 5b and release (“1 ”);Press accelerator pedal 5b and release (“1 ”);Press brake pedal 5a and release (“0”);Press accelerator pedal 5b and release (“1 );Press accelerator pedal 5b and release (“1 ”);Press brake pedal 5a and release (“0”).
[0044] Note that although it is more practical to provide two, or at least two, control devices 5a, 5b, it is possible to also use only one control device, for example if the binary code is a Morse code.
[0045] Again with reference to Figure 2, the authentication system 50 further comprises a remote authentication server 40 and a telecommunications network 41 , preferably a mobile radio network, such as a 4G or 5G network, for example. Preferably, the remote authentication server 40 is a server managed directly or indirectly by the manufacturer of the transport vehicle 1.
[0046] According to an advantageous embodiment, the authentication system 50 further comprises a personal mobile communication terminal 42, such as a smartphone or a tablet or a smartwatch, for example. Preferably, an authentication application program (in other words, an APP) is installed on the personal mobile communication terminal 42, the authentication application program being configured to allow the authentication of the diagnostic device 30 to on-board telematic networks 10 of transport devices 1 .
[0047] Referring now to Figures 3 and 4, non-limiting embodiments of an authentication method 100 will be described. In particular, Figure 3 shows the flow diagram of a relatively more simplified embodiment of the authentication method 100. Figure 4 instead shows the flow diagram of some additional steps which allow a relatively more complex and more secure embodiment of the authentication method 100 of the diagnostic tool 30 to the on-board telematic network 10 of the transport vehicle 1 , to be obtained.
[0048] The authentication method 100 comprises a step 101 “OBD ent” of operatively connecting the complementary connector 31 of the diagnostic tool 30 to the on-board diagnostic connector 11 of the transport vehicle 1 under a condition in which, i.e., when, thesecure gateway 12 is in the locked state. When the secure gateway 12 is in the locked state, the diagnostic tool 30 cannot communicate with the on-board telematic network 10, and in particular it cannot access the data communication bus 13, also when the connectors 1 1 and 31 are operatively connected to each other. In other words, when the secure gateway 12 is in the locked state, the diagnostic tool 30 cannot receive data by means of the data communication bus 13 and cannot transmit data on such a data communication bus 13. The authentication method 100 thus aims to bring the secure gateway 12 to the unlocked state in order to allow data transmission between the diagnostic tool 30 and the on-board telematic network 10, for example, between the diagnostic tool 30 and at least one electronic control unit 27, 28, 29.
[0049] According to a preferred embodiment, the secure gateway 12 is configured to automatically detect the connection of the complementary connector 31 to the on-board diagnostic connector 11 . When such a detection occurs, the secure gateway 12 remains in the locked state but takes a first standby state.
[0050] The authentication method 100 comprises a step 103 “RX oldcod” of receiving a first binary unlocking code from the remote authentication server 40 through the telecommunications network 41. According to an advantageous embodiment, prior to said receiving step 103, the authentication method 100 comprises a step 102 “Req oldcod” of requesting the first binary unlocking code to the remote authentication server 40 through the telecommunications network 41 .
[0051] According to a particularly advantageous embodiment, the first binary unlocking code is received by means of the authentication application program installed on board the personal mobile communication device 42 and, for example, displayed on a display of the latter. Preferably, it is possible to perform the step 103 of requesting the first unlocked code to the remote authentication server 40 by means of the same application program. Conveniently, to receive 103 and possibly request 102 the aforesaid binary unlocking code, it is necessary for a user to have been previously registered on the remote authentication server 40.
[0052] According to a particularly advantageous embodiment, in the step 102 of requesting the first binary unlocking code, at least one unique identification data item of the transport vehicle 1 is sent to the remote authentication server 40, such as the serial number and / or the series number and / or the license plate number of the transport vehicle 1 , for example.
[0053] Note that it is not strictly necessary for the requesting step 102 and the receiving step 103 to be performed by the personal mobile communication device 42 because, for example, such steps could be performed using a PC connected to the Internet or using the diagnostic tool 30 itself if it is provided with network connectivity.
[0054] After receiving 103 the first binary unlocking code, the authentication method 100 comprises a step 104 “IN oldcod” of inputting the first binary unlocking code into the on-boardtelematic network 10 by moving said at least one control device 5a, 5b. Paragraphs
[0039] -
[0044] already explained in detail how a user may input a binary unlocking code into the onboard telematic network 10 by means of the at least one control device 5a, 5b.
[0055] After inputting the first binary unlocking code into the on-board telematic network 10, the authentication method 100 comprises a step 105 “CK oldcod” of checking the first inputted binary unlocking code with the secure gateway 12. This is possible because, after the aforesaid inputting, the secure gateway 12 may read and / or receive the first binary unlocking code, for example, by means of the data communication bus 13. The aforesaid checking step 105 allows checking whether the first inputted binary code is correct or not. For example, in the aforesaid checking step 105, the secure gateway 12 performs an identity check with a binary code stored in the secure gateway 12 or obtainable, e.g., to be calculated, by means of a code, e.g., a binary code, stored in the secure gateway 12.
[0056] If, by means of the checking step 105, the secure gateway 12 determines that the first inputted binary code is not correct, the authentication method 100 comprises a step 106 “Stay LKD” of causing the secure gateway 12 to remain in the locked state. If instead, by means of said checking step 105, the secure gateway 12 determines that the first inputted binary code is correct, the authentication method 100 comprises a step 107 “UNLK” of bringing the secure gateway 12 to the unlocked state 107. In this state, it therefore is possible to access the onboard telematic network 10 by means of the diagnostic tool 30.
[0057] The embodiment of the authentication method 100 described above is a relatively simpler and, although more advantageous, intrinsically less secure embodiment.
[0058] In an alternative embodiment, in order to make the authentication method 100 more robust and secure, alternatively to executing step 107 of bringing the secure gateway 12 to the unlocked state immediately after the checking step 105, it is possible to carry out further steps 108, an example of which will be described below with reference to Figure 4. Briefly, in this alternative embodiment, after checking 105 the correctness of method 100 described above with reference to Figure 3 and the successful results of such a check, the secure gateway 12 remains in the locked state but also takes a second standby state in which, in practice, the secure gateway 12 remains in standby for a second binary unlocking code provided by the remote authentication server 40. The execution of the further steps 108 in the authentication method 100 presumes that the on-board telematic network 10 comprises a first short-range wireless communication interface 14 operatively connected to the secure gateway 12.
[0059] If, after the checking step 105, method 100 comprises the further steps 108, the authentication method 100 comprises a step 109 “RX pwA” of receiving an authentication password from the remote authentication server 40 by means of the telecommunications network 41 and a step 110 “FW pwA” of forwarding the authentication password to the securegateway 12 through the first short-range wireless communication interface 14. According to a particularly advantageous embodiment:- in the aforesaid step 109 of receiving the authentication password, the authentication password is received by the personal mobile communication terminal 42;- in the aforesaid step 110 of forwarding the authentication password to the secure gateway 12, the personal mobile communication terminal 42 forwards the authentication password to the secure gateway 12 through the second short-range wireless communication interface.
[0060] For example, the aforesaid receiving step 109 and forwarding step 1 10 are managed or performed by means of the authentication application program installed on board the personal mobile communication terminal 42 and, for example, forwarding occurs by means of Bluetooth or BLE protocol after coupling between the personal mobile communication terminal 42 and the on-board telematic network 10.
[0061] After the aforesaid forwarding step 1 10, the authentication method 100 comprises a step 1 11 “CK pwA” of checking the authentication password with the secure gateway 12. For example, in the aforesaid checking step 11 1 , the secure gateway 12 performs an identity check with a password stored in the secure gateway 12 or obtainable, e.g., to be calculated, by means of a password or a key stored in the secure gateway 12.
[0062] If the secure gateway 12 determines from the aforesaid check 11 1 that the authentication password is not correct, the authentication method 100 comprises a step 112 of causing the secure gateway 12 to remain in the locked state. At this point, the authentication application program on board the personal mobile communication terminal 42 will be capable of signaling an error authentication message and the repetition of steps 109, 100 and 111 possibly could be provided for a limited number of times, e.g., two or three times.
[0063] Otherwise, if the secure gateway 12 determines from the aforesaid checking step 1 11 that the authentication password is correct, the authentication method 100 comprises a step 1 13 “TX seed” of transmitting a cryptographic seed code from the secure gateway 12 to the remote authentication server 40. Conveniently, in such a transmitting step 1 13, the secure gateway 12 transmits the cryptographic seed code to the remote authentication server 40 by means of the personal mobile communication terminal 42, therefore by means of the first short- range wireless communication interface 14.
[0064] According to a particularly advantageous embodiment, the cryptographic seed code is a pseudo-random code obtained by means of a Mersenne Twister generator. A Mersenne Twister generator is an algorithm for generating pseudo-random numbers of linear congruential type developed in 1997 by Makoto Matsumoto and Takuji Nishimura. This type of generator has the advantage of having increased security.
[0065] The authentication method 100 further comprises a step 114 “Gen newcod” of generating a second binary unlocking code at the remote authentication server 40 from thecryptographic seed code, and the step 115 “RX newcod” of receiving the second binary unlocking code from the remote authentication server 40 by means of the telecommunications network 41. According to a particularly advantageous embodiment, in the aforesaid receiving step 115, the second binary unlocking code generated by the remote authentication server 40 is received by means of the authentication application program installed on board the personal mobile communication device 32 and, for example, is displayed on a display of the latter.
[0066] After the step 115 of receiving the second binary unlocking code, the authentication method 100 comprises a step 1 16 “IN newcod” of inputting the second binary unlocking code into the on-board telematic network 10 by moving said at least one control device 5a, 5b. Paragraphs
[0039] -
[0044] already explained in detail how a user may input a binary unlocking code into the on-board telematic network 10 by means of the at least one control device 5a, 5b.
[0067] After inputting the second binary unlocking code into the on-board telematic network 10, the authentication method 100 comprises a step 117 “CK newcod” of checking the second inputted binary unlocking code with the secure gateway 12. This is possible because after the aforesaid inputting, the secure gateway 12 may read and / or receive the second binary unlocking code, for example, by means of the data communication bus 13. The aforesaid checking step 117 allows checking whether the second inputted binary code is correct or not. For example, in the aforesaid checking step 105, the secure gateway 12 performs an identity check with a binary code stored in the secure gateway 12 or obtainable, e.g., to be calculated, by means of a code, e.g., a binary code, stored in the secure gateway 12 or, for example, by means of the aforesaid cryptographic seed code.
[0068] If, by means of the aforesaid checking step 1 17, the secure gateway 12 determines that the second inputted binary code is not correct, the authentication method 100 comprises a step 118 “Stay LKD” of causing the secure gateway 12 to remain in the locked state. If instead, by means of said checking step 117, the secure gateway 12 determines that the second inputted binary code is correct, the authentication method 100 comprises a step 119 “UNLK” of bringing the secure gateway 12 to the unlocked state. In this state, it therefore is possible to access the on-board telematic network 10 by means of the diagnostic tool 30.
[0069] According to a particularly advantageous embodiment, if the secure gateway 12 has taken the unlocked state, the authentication method 100 comprises:- A step 120 “Stor newcod” of storing the second binary unlocking code in the on-board telematic network 10, for example in the secure gateway 12;A step 121 “Inf RS” of informing the remote authentication server 40 that the secure gateway 12 has taken the unlocked state and conveniently also a step of storing the second binary unlocking code at the remote authentication server 40.
[0070] It is thus possible to trace, at the remote authentication server 40, all the accesses to the on-board telematic network 10 with diagnostic tools 30. Moreover, it is particularly advantageous that the second binary unlocking code forms the first binary unlocking code which will be received in step 104 the next time when access to the on-board telematic network 10 by means of a diagnostic tool 30 is desired.
[0071] Note that the aforesaid informing step 121 can also be performed by the secure gateway 12 by means of the first short-range wireless communication interface 14 by passing through the personal mobile communication terminal 42, possibly by managing the authentication application program.
[0072] The present invention also relates to a transport vehicle 1 comprising an on-board telematic network 10 comprising an on-board diagnostic connector 1 1 and at least one secure gateway 12. The secure gateway 12 is configured to take a locked state and an unlocked state, in which the secure gateway 12 prevents and allows, respectively, a data transmission on the on-board telematic network 10 through the on-board diagnostic connector 1 1 .
[0073] The transport vehicle 1 comprises at least one control device 5a, 5b operatively connected to the on-board telematic network 10 and configured to be moved by a user to control the transport vehicle 1 and to input binary codes into the on-board telematic network 10.
[0074] The secure gateway 12, from the locked state, is configured to check the binary unlocking code generated by a remote authentication server 40 and inputted into the on-board telematic network 10 by means of said at least one control element 5a, 5b. When, through said checking, the secure gateway 12 determines that the binary code is correct, the secure gateway 12 is configured to take the unlocked state. When instead, through the aforesaid checking, the secure gateway 12 determines that the binary unlocking code is not correct, the secure gateway 12 is configured to remain in the locked state.
[0075] According to an advantageous embodiment, the on-board telematic network 10 comprises a first short-range wireless communication interface 14 operatively connected to the secure gateway 12. The first short-range wireless communication interface 14 allows the secure gateway 12 to communicate with the remote authentication server 40 by means of an authentication application program installed on board a personal mobile communication device 42.
[0076] According to a particularly advantageous embodiment, said at least one control device 5a, 5b comprises at least one of: a brake lever, a clutch lever, a throttle grip, an accelerator lever.
[0077] Further features of the transport vehicle 1 are apparent directly from the detailed description provided above with reference to the transport vehicle 1 and the authentication method 100.
[0078] Therefore, based on the above explanation, it is possible to understand how an authentication method 100 and a transport vehicle 1 of the type described above allow achieving the aforesaid objects with reference to the prior art. Indeed, the invention does not require loading and updating authentication libraries on board the authentication devices 30. Despite this, the invention allows ensuring the security and traceability of the accesses made to the telematic networks on board transport vehicles.
[0079] Without prejudice to the principle of the invention, the embodiments and the constructional details may widely vary with respect to the above description, disclosed merely by way of non-limiting example, without departing from the scope of the invention as defined in the appended claims.
Claims
CLAIMS1. An authentication method (100) of a diagnostic tool (30) connectable to an on-board telematic network (10) of a transport vehicle (1 ), wherein:- the on-board telematic network (10) comprises an on-board diagnostic connector (1 1) and at least one secure gateway (12);- the secure gateway (12) is configured to take a locked state and an unlocked state, in which the secure gateway (12) prevents and allows, respectively, a data transmission on the on-board telematic network through the on-board diagnostic connector (1 1 );- the diagnostic tool (30) comprises a complementary connector (31 ) operatively connectable to the on-board diagnostic connector (1 1 );- the transport vehicle (1 ) comprises at least one control device (5a, 5b) operatively connected to the on-board telematic network (10) and configured to be moved by a user to control the transport vehicle (1 ) and to input binary codes into the on-board telematic network (10); the authentication method (100) comprising the steps of:- operatively connecting (101 ) the complementary connector (31 ) to the on-board diagnostic connector (1 1 ) when the secure gateway (12) is in the locked state;- receiving (103) a first binary unlocking code from a remote authentication server (40) through a telecommunications network (41 );- inputting (104) the first binary unlocking code into the on-board telematic network (10) by moving said at least one control device (5a, 5b);- checking (105) the first inputted binary unlocking code with the secure gateway (12);- if the first binary unlocking code is not correct, causing (106) the secure gateway (12) to remain in the locked state;- if the first binary unlocking code is correct, bringing (107) the secure gateway (12) to the unlocked state or carrying out further steps (108) of the authentication method (100) configured to cause the secure gateway (12) to take the unlocked state.
2. An authentication method (100) according to claim 1 , wherein in the checking step (105), the secure gateway (12) checks if the first binary unlocking code coincides with a binary code previously stored in the secure gateway (12) or with a code obtainable by the secure gateway (12) from a code stored in the secure gateway (12).
3. An authentication method (100) according to claim 1 or 2, further comprising, prior to said receiving step (103), a step (102) of requesting the first binary unlocking code to the remote authentication server (40) through the telecommunications network (41 ).
4. An authentication method (100) according to any one of the preceding claims, wherein the on-board telematic network (10) comprises a first short-range wirelesscommunication interface (14) operatively connected to the secure gateway (12), and wherein said further steps (108) comprise:- receiving (109) an authentication password from the remote authentication server (40) through the telecommunications network (41 );- forwarding (110) the authentication password to the secure gateway (40) through the first short-range wireless communication interface (14);- checking (11 1 ) the authentication password with the secure gateway (12);- if the authentication password is not correct, causing (1 12) the secure gateway (12) to remain in the locked state; if instead the authentication password is correct, transmitting (113) a cryptographic seed code from the secure gateway (12) to the remote authentication server (40);- generating (114) a second binary unlocking code at the remote authentication server (40) from the cryptographic seed code; receiving (1 15) the second binary unlocking code from the remote authentication server (40) through the telecommunications network (41 );- inputting (1 16) the second binary unlocking code into the on-board telematic network (10) by moving said at least one control device (5a, 5b);- checking (117) the second inputted binary unlocking code with the secure gateway (12);- if the second binary unlocking code is not correct, causing (118) the secure gateway (12) to remain in the locked state;- if the second binary unlocking code is correct, bringing (119) the secure gateway (12) to the unlocked state.
5. An authentication method (100) according to claim 4, wherein said first short-range wireless communication interface (14) is a Bluetooth or BLE interface.
6. An authentication method (100) according to claim 4 or 5, wherein if the second binary unlocking code is correct, the authentication method (100) also comprises a step (120) of storing the second binary unlocking code in the on-board telematic network (10).
7. An authentication method (100) according to any one of claims 4 to 6, wherein the cryptographic seed code is a pseudo-random code obtained by means of a Mersenne Twister generator.
8. An authentication method (100) according to any one of the preceding claims, wherein said at least one control device (5a, 5b) comprises at least one pedal control lever and / or at least one manual control lever.
9. An authentication method (100) according to any one of the preceding claims, wherein said control device (5a, 5b) comprises at least one of: a brake lever, a clutch lever, a throttle grip, an accelerator lever.
10. An authentication method (100) according to any one of the preceding claims, wherein in said step (103) of receiving the first binary unlocking code and / or in said step (115) of receiving the second binary unlocking code, said binary unlocking codes are received by a personal mobile communication terminal (42) operatively connectable to the telecommunications network (41 ).1 1 . An authentication method (100) according to claims 4 and 10, wherein:- the personal mobile communication terminal (42) comprises a second short-range wireless communication interface adapted to communicate with the first short-range wireless communication interface (14);- in said step (109) of receiving the authentication password, the authentication password is received by the personal mobile communication terminal (42);- in said step (1 10) of forwarding the authentication password, the personal mobile communication terminal (42) forwards the authentication password to the secure gateway (12) through the second short-range wireless communication interface.
12. An authentication method according to claim 4 or 10 or 1 1 , wherein in said step (113) of transmitting the cryptographic seed code, the secure gateway (12) transmits the cryptographic seed code to the remote authentication server (40) by means of the personal mobile communication terminal (42).
13. A transport vehicle (1 ) comprising:- an on-board telematic network (10) comprising an on-board diagnostic connector (1 1 ) and at least one secure gateway (12), wherein the secure gateway (12) is configured to take a locked state and an unlocked state, in which the secure gateway (12) prevents and allows, respectively, a data transmission on the on-board telematic network (10) through the on-board diagnostic connector (11 );- at least one control device (5a, 5b) operatively connected to the on-board telematic network (10) and configured to be moved by a user to control the transport vehicle (1 ) and to input binary codes into the on-board telematic network (10); wherein the secure gateway (12), from the locked state, is configured to:- check the binary unlocking code generated by a remote authentication server (40) and inputted into the on-board telematic network (10) by means of said at least one control element (5a, 5b);- when, through said checking, the secure gateway (12) determines that the binary code is correct, the secure gateway (12) is configured to take the unlocked state;- when, through the aforesaid checking, the secure gateway (12) determines that the binary code is not correct, the secure gateway (12) is configured to remain in the locked state.
14. A transport vehicle according to claim 13, wherein the on-board telematic network (10) comprises a first short-range wireless communication interface (14) operatively connected to the secure gateway (12), wherein said first short-range wireless communication interface (14) allows the secure gateway (12) to communicate with the remote authentication server (40) by means of an authentication application program installed on board a personnel mobile communication device (42).
15. A transport vehicle (1 ) according to claim 13 or 14, wherein said at least one control device (5a, 5b) comprises at least one of: a brake lever, a clutch lever, a throttle grip, an accelerator lever.