VEHICLE CYBERSECURITY LEVEL INSPECTION, EVALUATION AND DIAGNOSIS SYSTEM

ES3078331T1Undetermined Publication Date: 2026-09-10EUROCYBCAR SL (100 00)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
ES2019835310T
Authority / Receiving Office
ES · ES
Patent Type
Applications
Current Assignee / Owner
Filing Date
2019-11-08
Publication Date
2026-09-10

AI Technical Summary

Technical Problem

Vehicles with electronic systems are vulnerable to cyber attacks, posing risks to occupants' safety and privacy due to potential manipulation of devices like ECUs, GPS, Bluetooth, and digital keyless access systems, which can lead to unauthorized access and safety threats.

Method used

A system for inspecting, evaluating, and diagnosing the cybersecurity level of vehicles, comprising a control server with software and data communication means to assess vulnerabilities and generate a cybersecurity rating, using standards like OSSTMM and OWASP, and including a Faraday cage for interference-free testing.

Benefits of technology

The system effectively evaluates and improves vehicle cybersecurity, reducing risks of unauthorized access and enhancing safety and privacy by identifying vulnerabilities and providing recommendations for improvement, such as software updates, thereby ensuring physical safety and compliance with data protection regulations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000003_0000
    Figure 00000003_0000
Patent Text Reader

Abstract

A system for inspecting, evaluating, and diagnosing the cybersecurity level of a vehicle, particularly for electronically managed devices and / or systems, comprising a control server equipped with software and data communication means configured for data exchange between the software and the electronic devices present in the vehicle, such that the control server determines the existence or absence of data manipulation situations based on data from the electronic devices.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle cybersecurity level inspection, evaluation and diagnostic system DESCRIPTIVE MEMORANDUM OBJECT OF THE INVENTION The purpose of this application is to register a system for the inspection, evaluation and diagnosis of the cybersecurity level of a vehicle. More specifically, the invention proposes the development of an inspection, evaluation and diagnosis system for the cybersecurity level of a vehicle, such as a car, which allows the assessment of the degree of security against a possible attack on the electronic systems installed in a vehicle that could put the privacy -the data- and the life of its occupants or even other users at risk. BACKGROUND OF THE INVENTION Today, vehicles on the road include a large number of electronically operated and managed devices such as, for example, electronic control units (ECUs), airbags, central door locking, windows, etc., which can be managed by wired connections or remotely, for example, for maintenance, repair and / or control tasks to ensure their proper functioning. Likewise, modern vehicles have a large number of other electronic devices with different applications for their users, such as: GPS (locating the vehicle's position), Bluetooth (making phone conversations while driving), USB ports (connecting electronic devices), Wi-Fi ports (enabling internet connection), etc. Both the devices that are operated and managed electronically and those other electronic devices that the vehicle has are subject to being manipulated or "hacked" by third parties, with the consequent risk or danger that their manipulation may pose to the occupants inside the vehicle. Thus, for example, in relation to a vehicle's ECU, there is a risk that a third party could remotely access it and order the vehicle's airbags to open when there is no such need, putting at risk the physical integrity of the users of the road on which said vehicle is traveling. In the case of a GPS device, there may also be the danger that a third party could access the exact stored positions of the vehicle, thus obtaining the movement routines executed by the vehicle user in order to try to blackmail or even kidnap him. A similar problem would exist with a vehicle's Bluetooth or Wi-Fi ports, which could be a source of access to phone conversations or personal data of vehicle users by a third party. Another source of danger would be that which would derive from current digital vehicle opening systems ("Keyless Access") through which it is not necessary for the user to insert the vehicle key into the lock or the electrical contact since with the simple approach of said key to the vehicle or the electrical contact the door opens or the engine starts, respectively. For this type of system, the main associated risk is that a third party can access the vehicle through digital duplicates. Furthermore, it is vital that the applications or programs that a vehicle user downloads to access information or even to remotely activate functions in the vehicle are able to prevent or hinder unauthorized access by third parties to the vehicle or the user's private information. Consequently, it is absolutely necessary to be able to reduce and mitigate these dangers and risks, especially because they can sometimes affect people's lives. DESCRIPTION OF THE INVENTION The present invention has been developed in order to provide a system for inspection, evaluation and diagnosis of the cybersecurity level of a vehicle, which is configured as a novelty within the field of application. It is therefore an object of the present invention to provide a system for inspection, evaluation and diagnosis of the cybersecurity level of a vehicle, in particular for devices, systems and applications that have software or hardware susceptible to being intervened by a third party. This system preferably comprises a control server equipped with software and data communication means configured for data exchange between the software and electronic devices present in the vehicle, such that the control server determines the existence or not of data manipulation situations based on the data from the electronic devices. This inspection, evaluation, and diagnostic system is intended, as mentioned, to assess the level of cybersecurity of The electronically managed devices, systems and / or applications of a vehicle, specifically those that correspond to a physical access (for example: "can bus", ECU, USB, EDR, etc.) ? Those that correspond to remote access (keyless system, WIFI ports, Bluetooth devices, ECALL calling devices, NFC devices, RDS, TPMS systems, GPS, etc.) as well as computer applications (APP), any other multimedia content or any driving assistance system incorporated in the vehicle. Consequently, the purpose of this system is to be able to evaluate the cybersecurity level of any of the electronic devices that a vehicle has, as well as the digital applications it has. It should be noted that the term vehicle refers to any device, manned or unmanned, configured to transport people and / or goods, including within this definition, but not limited to, the following: bicycles, scooters, mopeds, cars, motorcycles, trucks, tractors, coaches, trains, trams, drones, aircraft, ships, etc. Regarding the software, this software comprises a series of executable instructions to assess the vulnerability of an electronic device to third-party attacks—whether direct or indirect. Preferably, these instructions are adapted to security standards, protocols, or auditing frameworks such as OSSTMM, OWASP, CVSS, etc. Specifically, this software interacts with the electronic devices and / or digital applications existing in the vehicle, and their cybersecurity level must be assessed in order to determine their level of protection against third-party attacks. In a preferred embodiment, the data communication media are of the wired type via a physical connection socket. Alternatively, the aforementioned data communication media can be wireless or a combination of wireless and wired media. An additional object of the invention is a procedure for inspecting, evaluating, and diagnosing the cybersecurity level of electronically managed devices and / or systems present in a vehicle, comprising the following steps: - obtaining and analyzing data from electronically managed devices and / or systems; - generation of parameters associated with the degree of cybersecurity from data from electronically managed devices and / or systems; - evaluation of the related cybersecurity level based on the parameters obtained; and - Establishment of a cyberrating based on the overall results of the evaluation. In a preferred embodiment, the generation of parameters associated with the degree of cybersecurity from data from electronically managed devices and / or systems is carried out by software hosted on a control server. Ideally, to assess the level of cybersecurity, in addition to evaluating the aforementioned parameters, a series of consequences can be associated with those parameters. For example, regarding the parameter of ECU vulnerability, if a series of errors are detected in essential communications, it can be associated as a consequence that there is a risk of remote manipulation of the airbags by a third party. In another preferred implementation, to assess the level of cybersecurity, a series of associated recommendations can also be established for each of the analyzed parameters. For example, continuing with the parameter of ECU vulnerability, if a series of errors are detected in essential communications, the recommendation could be to update the ECU software. To assess the level of cybersecurity, a series of positive points can also be established for each parameter. For example, continuing with the parameter of ECU vulnerability, the fast execution of instructions could be cited as a positive point. Based on each of these variables, evaluation of parameters and / or consequences associated with the parameters and / or recommendations and / or positive points, the overall cybersecurity level of the vehicle -cyberrating- is determined, which allows a comparison to be made between the cybersecurity level of the evaluated vehicle and the rest of the vehicles. As mentioned above, the purpose of this procedure is to achieve a global level of vehicle cybersecurity that will allow us to influence, at least, the physical safety of the vehicle's occupants and other road users, the privacy of the occupants' personal data, the fulfillment of the vehicle's functions, compliance with the corresponding legal regulations (for example: at the level of data protection) and the correct adaptation of the vehicle to the needs of the driver and its users. It is also another object of the invention to provide an installation for applying the inspection, evaluation, and diagnostic system described above, comprising at least one Faraday cage structure with dimensions suitable for Place a vehicle inside. This allows testing of the vehicle's wireless communication systems without external interference that could disrupt the test results. In a preferred embodiment, the Faraday cage installation and / or structure has a polygonal, and more preferably rectangular, floor plan. Preferably, in the case of a rectangular floor plan, its dimensions are approximately 500 cm long and 350 cm wide. In another preferred embodiment, the installation can be configured to receive more than one vehicle and have more than one inspection, evaluation and diagnostic system according to the invention, so that the cybersecurity level of the electronic devices of more than one vehicle can be checked at the same time. Thanks to these features, it is possible to detect the level of security against improper manipulation by third parties of electronic or telematic systems that operate in a vehicle, identifying vulnerabilities, thus allowing the cybersecurity level of the vehicle to be increased or improved. The system described thus represents an innovative structure with structural and constitutive characteristics previously unknown for the purpose for which it is intended, reasons which, together with its practical utility - even when establishing a comparison between vehicles - provide it with sufficient grounds to obtain the privilege of exclusivity that is requested. Other features and advantages of the inspection, evaluation, and diagnosis system for the cybersecurity level of a vehicle, which is the subject of the present invention, will become evident from the description of a preferred, but not exclusive, embodiment. This is illustrated by way of non-limiting example in the accompanying drawings, in which: BRIEF DESCRIPTION OF THE DRAWINGS Figure 1.- It is a schematic view of an installation intended to apply the system according to the invention. DESCRIPTION OF A PREFERRED EMBODIMENT In view of the aforementioned figures and in accordance with the numbering adopted, an example of a preferred embodiment of the invention can be observed, which comprises the parts and elements indicated and described in detail below. The system for inspecting, evaluating, and diagnosing the cybersecurity level of a vehicle, particularly for devices, applications, and / or systems susceptible to being intervened by a third party, comprises a control server provided with software and data communication means configured for the exchange of data between the software and the devices, applications, and / or systems susceptible to being intervened by a third party, such that the control server determines the existence or not of data manipulation situations based on the data coming from the devices, applications, and / or systems susceptible to being intervened by a third party. Regarding data communication media, they can be of the wired type through a physical connection socket and / or of the wireless type. This system involves a procedure for inspecting, evaluating, and diagnosing the cybersecurity level of devices, applications, and / or systems that may be compromised by a third party and are present in the vehicle, comprising the following stages: - obtaining and analyzing data from devices, applications and / or systems that may be accessed by third parties; - generation of parameters associated with the degree of cybersecurity from data from devices, applications and / or systems susceptible to being intervened by third parties; - evaluation of the related cybersecurity level based on the parameters obtained, in which different cybersecurity levels are previously established to evaluate the vehicle's security level; and -establishment of a cyberrating based on the overall results of the evaluation. In a preferred embodiment of the invention, the generation of the parameters associated with the degree of cybersecurity is carried out by means of software hosted on a control server. Among other reference elements for establishing the score - cyberrating -, the final assessment will take into account five established levels of cybersecurity: - Low risk level (maximum safety level): this level would be assigned for cases where minor errors are detected that do not pose a danger to passengers, their privacy and / or the car; - Low risk level (high security level): This level implies that a third party could have access to personal information stored on electronic devices or multimedia systems, but this does not entail a risk to passengers; - Medium risk level (medium security level): this level would be assigned to those cases in which the devices Electronic or multimedia systems can be subject to minor remote attacks or major attacks after gaining access to the interior of the vehicle; - High risk level (low security level): This level would correspond to cases in which a third party could easily open the doors of a car, with subsequent access to the ECU to start the engine, and / or manipulate parameters and elements that may endanger the safety of the driver and passengers; and - Critical risk level (critical security level): this level would be assigned when it is detected that a third party can carry out attacks remotely, which can affect the safety of the driver and passengers (for example: access to the ECU through WIFI or attacks from the Internet in the case that the car has a SIM). Along with the levels described above, other vehicle safety parameters obtained through vehicle testing systems and mechanisms and / or through artificial intelligence-based software may also be taken into account to verify regulatory compliance of any of the aforementioned parameters. The system described above can be carried out in facilities that have different rooms or chambers, where there can be at least one room for the vehicles (1) and a Faraday cage structure (2) with dimensions suitable for placing a vehicle inside, as shown schematically in Figure 1.

Claims

CLAIMS 1. A system for inspecting, evaluating, and diagnosing the cybersecurity level of a vehicle, particularly for electronically managed devices and / or systems, comprising a control server provided with software and data communication means configured for data exchange between the software and the electronic devices present in the vehicle, such that the control server determines the existence or absence of data manipulation situations based on data from the electronic devices.

2. System according to claim 1, wherein the data communication means are of the wired type via a physical connection socket.

3. System according to claim 1, wherein the data communication means are of a wireless type.

4. Procedure for inspection, evaluation and diagnosis of the cybersecurity level of electronically managed devices and / or systems present in a vehicle, comprising the following stages: - obtaining and analyzing data from electronically managed devices and / or systems; - generation of parameters associated with the degree of cybersecurity from data originating from electronically managed devices and / or systems; and - evaluation of the degree of cybersecurity related to the parameters obtained.

5. Method according to the previous claim in which the generation of parameters associated with the degree of cybersecurity is carried out by means of software hosted on a control server.

6. A method according to any of claims 4 or 5, further comprising an evaluation step based on the combined results of all tests performed.

7. An installation for an inspection, evaluation, and diagnostic system according to any of claims 1 to 3, comprising a Faraday cage structure of suitable dimensions for housing a vehicle.