System and method for securing a diagnostic request to an automotive computer

A dual-key system with a common key for manufacturer-controlled environments and a unique key for post-delivery scenarios, integrated with remote server verification, addresses security gaps in vehicle diagnostic access, ensuring robust protection from manufacturing to end-user ownership.

FR3099603B1Active Publication Date: 2025-10-31STELLANTIS AUTO SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2019008637
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2019-07-30
Publication Date
2025-10-31
Estimated Expiration
2039-07-30

AI Technical Summary

Technical Problem

Existing communication protocols for vehicle control units lack robust security measures to ensure secure access and authorization of diagnostic tools, particularly after the vehicle is delivered to an end user, exposing vehicles to potential security risks.

Method used

Implementing a dual-key system with a first common key for manufacturer-controlled environments and a unique key for post-delivery scenarios, requiring verification against a remote server to authorize diagnostic requests, and irreversibly disabling the common key post-manufacturing to enhance security.

Benefits of technology

Enhances security by ensuring secure access to vehicle control units throughout the vehicle's lifecycle, from manufacturing to end-user ownership, reducing vulnerabilities during distribution and post-delivery phases.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000010_0000
    Figure 00000010_0000
Patent Text Reader

Abstract

The invention relates to a system for securing a diagnostic request for a vehicle control unit (1), comprising a control unit (1) including a diagnostic connector, a storage memory (10), a diagnostic tool (2) including a first storage memory (20) on which a computer program is installed to modify at least one parameter of the control unit, a communication device to a remote server (3), a second storage memory (30) installed on a remote server (3), characterized in that the on-board storage memory (10) includes a first locking key (11) and a second locking key (12), the first storage memory (20) of the diagnostic tool includes the first storage key (21), the second storage memory (30) of the remote server (3) includes the second storage key (32), so that the control unit can control access by the diagnostic tool. Figure for the abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: System and method for securing a diagnostic request to a motor vehicle computer.

[0001] The present invention relates generally to a system and a method for securing a diagnostic request to a motor vehicle computer.

[0002] Communication between a vehicle control unit (ECU) and a remote diagnostic tool uses a communication protocol, Unified Diagnostic Services (UDS), specified in ISO 14229-1 and derived from ISO 14230-3 and ISO 15765-3. This is an international standard and not a manufacturer-specific standard. This communication protocol is used in almost all new ECUs manufactured by suppliers to original equipment manufacturers (OEMs). Vehicle ECUs control a wide range of vehicle functions, including electronic fuel injection, engine control, transmission, anti-lock braking system (ABS), door locking, braking, etc. Access to the ECU must therefore be secure.

[0003] The diagnostic tool can communicate with all control units installed in a vehicle with Unified Diagnostic Services (UDS) enabled. Modern vehicles have a diagnostic interface for off-the-shelf diagnostics, which allows a computer or diagnostic tool to be connected to the vehicle's bus system, to which all the vehicle's control units are connected. Thus, the messages defined in the Unified Diagnostic Services (UDS) standard can be sent to the controllers that are required to provide the predetermined Unified Diagnostic Services (UDS). This makes it possible to query the fault memory of the various control units or to update them using new operating system software (firmware).

[0004] Each car manufacturer is responsible for implementing a secure access mechanism according to the Unified Diagnostic Services (UDS) standard.

[0005] One object of the present invention is to propose a method of securing a diagnostic request to a motor vehicle computer allowing to meet the different levels of security required and use cases of diagnostic tools.

[0006] To this end, a first aspect of the invention relates to a system for securing a diagnostic request for a motor vehicle computer, the motor vehicle computer comprising a diagnostic connection element arranged to receive a connection with a diagnostic tool, an on-board storage memory, the diagnostic tool comprising a first storage memory on which is installed a computer program capable of accessing the computer to modify at least one operating parameter, once the diagnostic tool is connected to the diagnostic connector, a communication device capable of connecting to a remote server, a second storage memory installed on the remote server, characterized in that the on-board storage memory of the motor vehicle computer includes a first lock key and a second lock key, the first storage memory of the diagnostic tool includes a first storage key arranged to unlock the first lock key, the second storage memory of the remote server includes a second storage key arranged to unlock the second lock key, so that the computer can control access by the diagnostic tool during a diagnostic request.

[0007] According to one embodiment, the first locking key is identical for all computers in a determined group of computers.

[0008] According to one embodiment, the second locking key is unique for each computer.

[0009] A second aspect of the invention relates to a method of securing a diagnostic request for a system according to the first aspect characterized in that it includes a step of comparing by the computer of the motor vehicle the first lock key stored in the storage memory of the computer with the first storage key stored in the storage memory of the diagnostic tool, a step of sending a request to modify or access at least one operating parameter of the computer by the diagnostic tool if the two first lock and storage keys are identical.

[0010] According to one embodiment, the security method includes a step of comparing by the vehicle computer the second locking key stored in the computer's storage memory with the second storage key stored in the remote server's storage memory, a step of sending a request to modify or access at least one operating parameter of the computer by the diagnostic tool if the two second locking and storage keys are identical.

[0011] According to one embodiment, the security method includes a step of prohibiting the step of comparison by the vehicle computer of the first locking key stored in the computer's storage memory with the first storage key stored in the diagnostic tool's storage memory, the prohibition step being triggered either when the diagnostic tool sends a determined diagnostic request, or when the vehicle has traveled a determined distance.

[0012] A third aspect of the invention relates to a computer system for securing a diagnostic request for a motor vehicle computer, characterized in that it includes means for implementing the steps of the process according to the second aspect.

[0013] A fourth aspect of the invention relates to a computer program comprising instructions for implementing the method of securing a diagnostic request for a motor vehicle computer according to the second aspect, when executed on one or more processors.

[0014] Other features and advantages of the present invention will become more apparent upon reading the following detailed description of an embodiment of the invention given by way of non-limiting example.

[0015] [Fig-1] represents a schematic view of the system for securing a request to diagnostic for a motor vehicle computer according to the invention.

[0016] In a manner known per se, a motor vehicle comprises several computers 1. These computers enable the operation of the vehicle in particular the control of the engine, the control of the devices in the passenger compartment such as the air conditioning and lighting, the driving of the vehicle such as the braking system, the active and passive safety systems etc... all of these computers are connected to a communication network or data bus.

[0017] Each computer 1 includes an on-board memory 10 for storing, in particular, software for operating the computer 1, data received by the computer and data relating to the vehicle or the computer 1. For example, when installed on a vehicle, the on-board memory 10 of a computer 1 may include the serial number 13 of the computer and / or the identification number 14 of the vehicle.

[0018] In order to verify the proper functioning of the control units, or to configure or update them, the communication network includes a diagnostic connector arranged to receive the connection of a diagnostic tool 2 so that the diagnostic tool 2 can transmit and receive data to / from the control unit 1. The diagnostic tool is essentially a computer comprising a storage memory 20 on which a computer program is stored, allowing access to the control unit 1 via the diagnostic connector. The diagnostic tool 2 includes, in a manner known per se, a human-machine interface (not shown).

[0019] The diagnostic tool 2 may also include a communication device capable of connecting to a remote server 3. The communication device is known per se. It may be a Wi-Fi or wired connection module. The remote server also has a second storage memory 30. The remote server 3 is a server owned by, or at least whose access is controlled by, the vehicle manufacturer. of the vehicle. It includes, in particular, information relating to the vehicle identification of the manufacturer, notably via the vehicle identification number.

[0020] As explained previously, since the control unit(s) 1 control several sensitive components of the vehicle, data exchange between the control unit(s) 1 and the diagnostic tool 2 must be secured using the Unified Diagnostic Services (UDS) standard. Indeed, access to the control unit is only possible via an authorized or verified diagnostic tool.

[0021] Furthermore, during vehicle assembly, the control unit(s) must, for example, be configured. This configuration is also carried out using a diagnostic tool 2. For the same reasons, access to the control unit 1 during vehicle manufacturing can only be achieved via an authorized or verified diagnostic tool. However, during manufacturing, access to the control unit is less risky since the vehicle is at a manufacturer's production site.

[0022] According to the invention and to take into account the different life cycles of the vehicle, the system for securing a diagnostic request to a vehicle computer according to the invention comprises a first locking key 11 and a second locking key 12 stored on the on-board memory 10 of the computer 1. A corresponding first storage key 21 is stored on the first storage memory 20 of the diagnostic tool 2. A corresponding second storage key 32 is stored on the second storage memory 30 of the remote server 3.

[0023] The first locking key 11 and the first storage key 21, referred to as the common key, are identical for a given group of control units. For example, the common key 11 is identical for all control units of the same type (e.g., engine control) and the same version (e.g., for a vehicle range for a given model year). It is understood that the first storage memory 20 of the diagnostic tool 2 can contain several different common keys 21, whereas the control unit 1 contains only one common key 11.

[0024] It is also understood that during the manufacturing phase, sending a diagnostic request to the diagnostic tool 2 is preceded by a comparison by the control unit 1 between the common keys 11, 21 present on the control unit 1 and on the diagnostic tool. If the common key 11 present on the control unit 1 corresponds to one of the common keys 21 present on the diagnostic tool, then the diagnostic request is authorized.

[0025] It is understood that access to the control unit 1 via the diagnostic tool 2 can be achieved without requiring access to the remote server 3. However, during vehicle assembly operations, the security of the control unit 1 is not significantly compromised. since it is located within the premises of the car manufacturer's factory. At the end of the manufacturing process, the vehicle identification number 14 is known. This is stored in the control unit 1, for example, via a diagnostic request from the diagnostic tool 2. Similarly, the vehicle identification number is linked on the one hand to the serial number of the control unit 13 and on the other hand to the second, so-called unique, locking key 12. The information concerning the association between the unique key 12, the vehicle identification number 14, and the serial number of the control unit 13 is stored in the second storage memory of the remote server 3.

[0026] After the vehicle is manufactured, it enters a distribution phase. During this phase, the vehicle is not yet assigned to an end user. It may be awaiting delivery or in the process of being delivered. Here again, the vehicle's environment is controlled by the manufacturer; therefore, the level of exposure to the computer's security is low. During this distribution phase, if a diagnostic request were to be sent by a diagnostic tool 2, a verification of the conformity of the common key 11 or the unique key 12 would be performed.

[0027] Verification of the unique key 12 requires access via the diagnostic tool 2 to the remote server 3. This verification is performed as follows. The diagnostic tool 2 first reads the serial number of the control unit 13 and the vehicle identification number 14 stored in the on-board memory of the vehicle's control unit 1. The serial number of the control unit 13 and the vehicle identification number 14 are then transmitted by the diagnostic tool 2 to the remote server to obtain the value of the corresponding unique key 32 stored in the remote server's second storage memory.

[0028] The value of the unique key 32 sent by the remote server 3 to the diagnostic tool is then compared by the computer 1 to the value of the unique key 12 stored on the on-board memory 10 of the computer 1. If the two values ​​are identical, the diagnostic request sent to the computer 1 by the diagnostic tool is authorized.

[0029] As soon as the vehicle is assigned and delivered to an end customer, the vehicle environment is no longer controlled by the manufacturer. It is therefore necessary to increase the security of the connection to the vehicle's computer 1. Consequently, after manufacturing and before delivery to the end customer, the use of the common key stored 11 on the computer is irreversibly disabled so that each diagnostic request transmitted by a diagnostic tool 2 is preceded only by a verification of the unique key's correspondence, thus requiring access to the remote server 3.

[0030] To achieve this, the computer 1 includes an area 15 of the on-board memory 10, modifiable only once. This memory area 15 is read by the calculator. 1. Depending on the value entered in this area 15, the calculator 1 will either proceed to the comparison of either the common key or the unique key, or only the unique key. In the initial state, i.e., during the manufacture of the computer 1, the value entered in zone 15 corresponds to a verification of the common key or the unique key.

[0031] At the end of the manufacturing process and before delivery of the vehicle to the final customer, the value of zone 15 is irreversibly modified in the on-board memory 10 of the computer 1. The new value written in zone 15 then corresponds to a verification of the unique key only before the execution of a diagnostic request sent by a diagnostic tool.

[0032] It is understood that the modification of the specific area 15 of the embedded memory 10 of the computer 1 permanently prohibits the use of the common key to authorize the execution of a diagnostic request transmitted by a diagnostic tool 2.

[0033] The modification of the specific area 15 of the embedded memory can be carried out in 2 ways: either via a specific diagnostic request sent, after authentication for example of the common key, by a diagnostic tool, or by the computer program of the computer itself after the latter has detected that the vehicle has travelled a determined distance for example on the order of a few kilometers to a thousand kilometers.

Claims

1. Demands System for securing a diagnostic request for a motor vehicle computer (1): • the vehicle computer (1) motor vehicle comprising: - a diagnostic connection element arranged to receive a connection with a diagnostic tool (2), - an embedded storage memory (10), • the diagnostic tool (2) comprising: - a first storage memory (20) on which is installed a computer program capable of accessing the computer (1) to modify at least one operating parameter, once the diagnostic tool (2) is connected to the diagnostic connector, • a communication device capable of connecting to a remote server (3), • a second storage memory (30) installed on the remote server (3) characterized in that: the on-board storage memory (10) of the motor vehicle computer includes a first locking key (11) and a second locking key (12), the first storage memory (20) of the diagnostic tool includes a first storage key (21) arranged to unlock the first locking key (11), the second storage memory (30) of the remote server (3) includes a second storage key (32) arranged to unlock the second locking key (12), so that the computer can control access by the diagnostic tool during a diagnostic request, said system being arranged to: - compare, using the vehicle's computer (1), the first locking key (11) stored in the computer's (1) storage memory (10) with the first storage key (21) stored in the diagnostic tool's storage memory (20) - send a request to modify or access at least one operating parameter of the computer via the diagnostic tool if the first two lock and storage keys are identical, - prohibit the comparison by the computer (1) of the motor vehicle of the first lock key stored (11) in the storage memory (10) of the computer (1) with the first storage key (21) stored in the storage memory (20) of the diagnostic tool (2) - the prohibition being triggered either when the diagnostic tool sends a determined diagnostic request, or when the motor vehicle has travelled a determined distance.

2. A system for securing a diagnostic request for a motor vehicle computer according to claim 1 wherein the first locking key (11) is identical for all computers in a determined group of computers.

3. A system for securing a diagnostic request for a motor vehicle computer according to one of claims 1 or 2 wherein the second locking key (12) is unique for each computer.

4. A method for securing a diagnostic request for a system according to any one of claims 1 to 3, characterized in that it comprises: - a step of comparing by the vehicle's computer (1) the first locking key (11) stored in the storage memory (10) of the computer (1) with the first storage key (21) stored in the storage memory (20) of the diagnostic tool; - a step of sending a request to modify or access at least one operating parameter of the computer by the diagnostic tool if the first two locking and storage keys are identical.- a step prohibiting the comparison by the vehicle's computer (1) of the first lock key stored (11) in the storage memory (10) of the computer (1) with the first storage key (21) stored in the storage memory (20) of the diagnostic tool (2) - the prohibition step being triggered either when the diagnostic tool sends a specific diagnostic request, or when the vehicle has traveled a specific distance.

5. A method for securing a diagnostic request according to claim 4, characterized in that it comprises - a step of comparison by the computer (1) of the motor vehicle of the second locking key (12) stored in the computer's storage memory with the second storage key (32) stored in the storage memory (30) of the remote server (3) - a step of sending a request to modify at least one operating parameter of the computer by the diagnostic tool if the two second locking and storage keys are identical.

6. Computer system for securing a diagnostic request for a motor vehicle computer, characterized in that it includes means for implementing the steps of the process according to any one of claims 4 to 5.

7. A computer program comprising instructions for implementing the method of securing a diagnostic request for a motor vehicle computer according to any one of claims 4 to 5, when executed on one or more processors.