ELECTRONIC CONTROL UNIT FOR A VEHICLE COMPRISING A TRANSACTIONAL BLACK BOX, AND METHOD FOR OPERATING SUCH AN ELECTRONIC CONTROL UNIT

The electronic control unit for vehicles addresses the diagnostic challenge by using a transactional black box with a security coprocessor to verify code integrity, download a rescue code, and enable communication for diagnosis, thus improving diagnostic efficiency and reducing costs.

FR3143146B1Active Publication Date: 2025-06-06VITESCO TECHNOLOGIES GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022012981
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-08
Publication Date
2025-06-06
Estimated Expiration
2042-12-08

AI Technical Summary

Technical Problem

Existing electronic control units for vehicles lack means for users to diagnose why the boot loader and application code are no longer executing, making it difficult to distinguish between hardware issues and malicious attacks.

Method used

Incorporating a transactional black box with a security coprocessor that verifies the integrity and authenticity of the boot loader and application code, and downloads a rescue computer code to diagnose and communicate with the outside when the boot loader is unauthenticated.

Benefits of technology

Enables users to understand the reason for boot loader and application code failure, allowing the electronic control unit to continue operating in a dedicated mode for communication and diagnosis, thereby reducing diagnostic costs and time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000015_0000
    Figure 00000015_0000
Patent Text Reader

Abstract

The invention relates to an electronic control unit (2) for a vehicle, the electronic control unit (2) comprising a main processor (4), memory means (6), a transactional black box (8) and a plurality of application cores (10), the memory means (6) storing a boot loader (18) and application code (13), the transactional black box (8) comprising a security coprocessor (20) and a memory (22), the memory (22) of the transactional black box (8) storing rescue computer code (24) configured to implement at least one diagnostic function of the electronic control unit (2) when executed by the main processor (4), and the security coprocessor (20) being configured to verify the integrity and authenticate the boot loader (18) within the plurality of application cores (10). Abstract Figure: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: ELECTRONIC CONTROL UNIT FOR A VEHICLE COMPRISING A TRANSACTIONAL BLACK BOX, AND METHOD FOR OPERATING SUCH AN ELECTRONIC CONTROL UNIT

[0001] The invention relates to an electronic control unit for a vehicle, in particular an automobile, comprising a main processor, memory means, a transactional black box and a plurality of application cores. The invention lies in the field of electronic and computer security, and more specifically the secure start-up of an electronic control unit embedded in a vehicle and the execution of authentic application code on such an electronic control unit. The invention also relates to a method for operating such an electronic control unit, as well as to a computer program product for implementing certain steps of this method. The electronic control unit is for example a microcontroller, without this being limiting within the scope of the present invention.

[0002] Electronic control units for vehicles, particularly automobiles, are known from the state of the art, typically comprising a main processor, memory means, a transactional black box and several application cores. Such an electronic control unit (called ECU in English for "Electronic Command Unit") is for example a microcontroller. The memory means are connected to the main processor via a data communication bus and store a boot loader and application code intended to be executed by the main processor (such application code being for example intended to allow the control of software bricks of the vehicle such as those belonging in particular to the engine control or even to the electric storage battery). The boot loader (also called "Boot Loader" in English) corresponds to a software layer other than the application code and comprises several launch sequences.The boot loader is configured, when executed by the main processor, to require integrity verification and authentication of the application code stored in the memory means and to execute this application code on the application cores when the application code has been authenticated. The transactional black box (also called HSM, from English "Hardware Security Module") includes a security coprocessor and a memory. The security coprocessor (also called "Trust Anchor" in English) is the only element of the electronic control unit that the latter trusts immutably. The security coprocessor is connected to the . main processor via the data communication bus and is configured to verify the integrity and authenticate the application code stored in the memory means, as well as to authorize the execution of the application code on the application cores. The security coprocessor is thus responsible for providing security functions within the electronic control unit, and is more generally part of a so-called "Secure Boot" mechanism which comprises a series of levels, each level involving the execution of a new part of computer code after necessary checks of the integrity of the code and optional decryption of the protected content, the security coprocessor corresponding to the first level. Indeed, users and vehicle manufacturers now require assurance that the application code executed by a dedicated electronic control unit in the vehicle is sufficiently secure to be executed.By "safe enough" we mean that the unit is in a safe mode to be executed but also in a state where it is guaranteed that no one has been able to modify the contents of the unit's internal non-volatile memory, dedicated to storing the software allowing an operational system to be run. The transactional black box, and therefore the security coprocessor, is the first module executed by the electronic control unit and is responsible for authorizing the execution, by the boot loader, of the application code on the application cores.

[0003] However, when one of the bootloader launch sequences is no longer trustworthy (and therefore no longer authenticatable), the latter cannot be executed by the main processor of the electronic control unit. The application code then in turn becomes inexecutable within the unit, the latter becoming inoperative in the vehicle without the end user of the vehicle understanding the reason. Indeed, in the systems currently used the electronic control unit does not offer any means for the user to communicate with it in order to understand the reason why the bootloader and the application code are no longer executing within the system and / or to try to perform an update of the application code within the unit.In particular, the user has no diagnostic means to distinguish between a hardware memory problem (especially on memory devices) or a malicious attack (intentional compromise type) on the unit.

[0004] The aim of the invention is to overcome the drawbacks of the prior art by proposing an electronic control unit for a vehicle, in particular an automobile, which offers the possibility to a user or a manufacturer of the vehicle to understand the reason why the boot loader and the application code are no longer running within the system, while allowing the electronic control unit to continue to run in a dedicated mode in order to offer a means of communication and diagnosis with the outside.

[0005] To this end, the invention thus relates, in its broadest sense, to an electronic control unit for a vehicle, the electronic control unit comprising a main processor, memory means, a transactional black box and a plurality of application cores, the memory means being connected to the main processor via a data communication bus and storing a boot loader and application code intended to be executed by the main processor, on the plurality of application cores, said boot loader comprising several launch sequences and being configured, when executed by the main processor, to require an integrity check and an authentication of the application code stored in the memory means and to execute said application code on the plurality of application cores when said application code has been authenticated,the transactional black box comprising a security coprocessor and a memory, the security coprocessor being connected to the main processor and to the memory means via the data communication bus and being configured to verify the integrity and authenticate the application code stored in the memory means and to authorize the execution of said application code on the plurality of application cores, the application cores being connected to the main processor via the data communication bus, the memory of the transactional black box storing a rescue computer code, said rescue computer code being intended to be executed by the main processor, on the plurality of application cores, and being configured to implement at least one diagnostic function of the electronic control unit when it is executed by the main processor,and in that the security coprocessor is further configured to verify the integrity and authenticate the boot loader within the plurality of application cores and, if the boot loader is not authenticated, to download the rescue computer code from the memory of the transactional black box to the memory means, to install said rescue computer code in place of a first boot loader launch sequence and to cause the main processor to execute said rescue computer code on the plurality of application cores.

[0006] Thanks to the presence in the memory of the transactional black box of the rescue computer code thus configured, the electronic control unit for a vehicle according to the invention offers the possibility to a user or a manufacturer of the vehicle to understand the reason why the boot loader and the application code no longer execute within the system, while allowing the electronic control unit to continue to execute in a dedicated mode in order to offer a means of communication and diagnosis with the outside. Such a means of diagnosis embedded directly in the electronic control unit allows advantageously This can significantly reduce costs and time spent diagnosing and handling possible hardware failure or malicious intrusion into the system, as well as avoiding the need to dispose of the unit when the cause of the boot loader failure is unknown.

[0007] According to a particular technical characteristic of the invention, the memory of the transactional black box is a non-volatile memory, preferably a flash memory. Such a non-volatile memory is accessible in reading and writing only by the security coprocessor, which makes it possible to improve the security of the electronic control unit, in particular concerning the use and authentication of the rescue computer code.

[0008] According to another particular technical characteristic of the invention, the memory means comprise a non-volatile memory, preferably a flash memory.

[0009] According to another particular technical characteristic of the invention, the data communication bus is a CAN bus (from the English “Controller Area Network”) or a bus conforming to the Ethernet protocol.

[0010] Advantageously, a compressed image of the rescue computer code is stored in the memory of the transactional black box. This makes it possible to optimize the consumption of memory resources within the transactional black box.

[0011] Advantageously, the rescue computer code is stored in an application portion of the memory of the transactional black box. This makes it easier to update the rescue computer code by an end user of the electronic control unit or by a manufacturer of the vehicle.

[0012] Advantageously, the security coprocessor is further configured to verify the integrity and authenticate the rescue computer code. This makes it possible to further improve the security associated with the use of the rescue computer code within the electronic control unit.

[0013] According to a particular technical characteristic of the invention, the security coprocessor is further configured to execute an instruction to reset the electronic control unit.

[0014] Advantageously, the rescue computer code is further configured, when executed by the main processor, to implement a function for uploading the application code from the memory means to a memory of a third-party device connected to the electronic control unit. This allows a user of the third-party device to be able to recover the potentially compromised application code. The memory of such a third-party device is for example a block of RAM or a non-volatile storage device of the flash memory type. Advantageously, the rescue computer code is configured so as to be able to verify the integrity and authenticity of the application code uploaded to the memory of the device third party.

[0015] The invention also relates to a method of operating an electronic control unit for a vehicle as described above, the method comprising the following steps: - verification, by the security coprocessor, of the integrity of the boot loader within the plurality of application cores; - if the verification of the integrity of the boot loader within the plurality of application cores is positive, authentication, by the security coprocessor, of the boot loader and: • sending, by the boot loader to the security coprocessor, a request for verification of the integrity and authentication of the application code stored in the memory means; • verification of the integrity and authentication, by the security coprocessor, of the application code stored in the memory means; • authorization, by the security coprocessor, of the execution of said application code on the plurality of application cores; and • execution by the main processor, via the boot loader, of said application code on the plurality of application cores; - if the verification of the integrity of the boot loader within the plurality of application cores is negative: • downloading, by the security coprocessor, of the rescue computer code from the memory of the transactional black box to the memory means; • installation, by the security coprocessor, of said rescue computer code in place of a first boot loader launch sequence; and • execution, by the main processor, of said rescue computer code on the plurality of application cores.

[0016] Advantageously, if the verification of the integrity of the boot loader within the plurality of application cores is negative, the method further comprises a step of verification of the integrity and authentication, by the security coprocessor, of the rescue computer code. This makes it possible to further improve the security linked to the use of the rescue computer code within the electronic control unit.

[0017] According to a particular technical characteristic of the invention, if the verification of the integrity of the boot loader within the plurality of application cores is negative, the method further comprises a step of execution, by the coprocessor of security, of an instruction to reset the electronic control unit. After this reset, the electronic control unit is no longer able to communicate with the outside world, in order to offer a user or a manufacturer of the vehicle a means of communication and diagnosis through the execution of the rescue computer code.

[0018] According to a particular variant embodiment of the invention, the step of verification, by the security coprocessor, of the integrity of the boot loader within the plurality of application cores comprises a verification of the integrity of the first launch sequence of the boot loader within the plurality of application cores, and a verification of the integrity of a flash boot loader module within the plurality of application cores, the verification of the integrity of the boot loader within the plurality of application cores being positive if and only if the results of said two verifications are positive.

[0019] The invention also relates to a computer program product comprising a set of program code instructions which, when executed by a processor, configure the processor to implement one or more step(s) of the method as described above, said computer program product constituting the rescue computer code, said processor being the main processor.

[0020] Embodiments of the present invention will be described below, by way of non-limiting examples, with reference to the appended figures in which: - [Fig.l] is a schematic representation of an electronic control unit for a vehicle according to the present invention; and - [Fig.2] is a flowchart illustrating the operating method of the electronic control unit of [Fig.l].

[0021] With reference to [Fig.l] an electronic control unit 2 is illustrated according to an embodiment of the invention. The electronic control unit 2 is installed within a vehicle, in particular a motor vehicle (such a vehicle not being shown in the figures for reasons of clarity), and is for example intended to control certain physical elements of the vehicle such as in particular the engine control or even an electric storage battery. The electronic control unit 2 is for example a microcontroller installed on a single chip, without this being limiting within the scope of the present invention.

[0022] The electronic control unit 2 comprises a main processor 4, memory means 6, a transactional black box 8 and several application cores 10. The computer system 2 also comprises a data communication bus 12 connecting these different elements. The memory means 6 are connected to the main processor 4 via the data communication bus 12, and store application code 13 intended to be executed by the main processor 4, on the application cores 10, in order to allow in particular the control of certain software bricks belonging to the various physical elements of the vehicle mentioned above. The memory means 6 also store a boot loader 18, for example on an area or partition different from that used for storing the application code 13. The memory means 6 typically comprise a non-volatile memory, preferably a flash memory, in which the application code 13 and the boot loader 18 are stored (under different partitions and / or in different layers).

[0023] The boot loader 18 is in the form of a program code, in other words a sequence of computer instructions intended to be executed by the main processor 4. More precisely, the boot loader 18 corresponds to a software layer other than the application code 13, comprises several launch sequences and is configured, when executed by the main processor 4, to require an integrity check and an authentication of the application code 13, and to execute the application code 13 on the application cores 10 when the application code 13 has been authenticated.

[0024] The transactional black box 8 comprises a security coprocessor 20 and a memory 22 which stores a rescue computer code 24. The security coprocessor 20 is connected to the main processor 4 and to the memory means 6 via the data communication bus 12. The security coprocessor 20 is configured to verify the integrity and authenticate the application code 13 stored in the memory means 6, and to authorize the execution of the application code 13 on the application cores 10.As will be detailed later, the security coprocessor 20 is further configured to verify the integrity and authenticate the boot loader 18 within the application cores 10 and, if the boot loader 18 is not authenticated, to download the rescue computer code 24 from the memory 22 of the transactional black box 8 to the memory means 6, to install the rescue computer code 24 in place of a first launch sequence of the boot loader 18 and to have the main processor 4 execute the rescue computer code 24 on the application cores 10. Preferably, the security coprocessor 20 is also configured to verify the integrity and authenticate the rescue computer code 24. More preferably, the security coprocessor 20 is also configured to execute a reset instruction of the electronic control unit 2.

[0025] The memory 22 of the transactional black box 8 is typically a non-volatile memory, preferably a flash memory. The rescue computer code 24 is intended to be executed by the main processor 4, on the application cores 10, and is configured to implement at least one diagnostic function of the unit of electronic control 2 when executed by the main processor 4. Preferably, in addition to the diagnostic function of the electronic control unit 2, the rescue computer code 24 is further configured, when executed by the main processor 4, to implement a function of uploading the application code 13 from the memory means 6 to a memory of a third-party device connected to the computer system 2 (such a third-party device not being shown in [Fig.l] for reasons of clarity). More preferably, a compressed image of the rescue computer code 24 is stored in the memory 22 of the transactional black box 8. More preferably, the rescue computer code 24 is stored in an application portion of the memory 22 of the transactional black box 8.

[0026] The data communication bus 12 is typically a CAN bus (from the English “Controller Area Network”) or a bus conforming to the Ethernet protocol, without this being limiting within the scope of the present invention.

[0027] The method of operation of the electronic control unit 2 according to one embodiment of the invention will now be described with reference to [Fig.2].

[0028] The method comprises an initial step 30 during which the transactional black box 8 is initialized by the main processor 4.

[0029] The method comprises a following step 32 during which the security coprocessor 20 verifies the integrity of the boot loader 18 within the application cores 10. Preferably, the verification 32 of the integrity of the boot loader 18 within the application cores 10 comprises a verification of the integrity of a first launch sequence of the boot loader 18 within the application cores 10, and a verification of the integrity of a flash boot loader module within the application cores 10.

[0030] If the verification 32 of the integrity of the boot loader 18 within the application cores 10 is positive (in other words if and only if the results of the two aforementioned verifications are positive), the security coprocessor 20 authenticates the boot loader 18 and the method moves on to a next step 34. Otherwise (in other words if at least one of the two aforementioned verifications is negative), the security coprocessor 20 does not authenticate the boot loader 18 and the method moves on to a next step 36.

[0031] During step 34, the main processor 4 initializes the boot loader 18. The method then comprises a following step 38 during which the boot loader 18 sends to the security coprocessor 20 a request for verification of the integrity and authentication of the application code 13 stored in the memory means 6.

[0032] During a step 40 following step 38, the security coprocessor 20 verifies the integrity of the application code 13 stored in the memory means 6. In the example of particular embodiment of [Fig.2], the application code 13 is divided into a high-level application code and an application code for reprogramming the high-level application code. According to this particular embodiment, step 40 therefore begins with a phase 41 of verifying the integrity of the high-level application code stored in the memory means 6.

[0033] If the phase 41 of verifying the integrity of the high-level application code is positive, the security coprocessor 20 authenticates the high-level application code and authorizes the execution of the high-level application code on the application cores 10, and the method moves on to a next step 42. Otherwise, the security coprocessor 20 does not authenticate the high-level application code and the method moves on to a next phase 44.

[0034] During step 42 the main processor 4 executes, via the boot loader 18, the high-level application code on the application cores 10.

[0035] During phase 44, the boot loader 18 sends to the security coprocessor 20 a request for verification of the integrity and authentication of the reprogramming application code stored in the memory means 6.

[0036] During a phase 46 following phase 44, the security coprocessor 20 verifies the integrity of the reprogramming application code stored in the memory means 6.

[0037] If the verification 46 of the integrity of the reprogramming application code is positive, the security coprocessor 20 authenticates the reprogramming application code and authorizes the execution of the reprogramming application code on the application cores 10, and the method moves on to a next step 48. Otherwise, the security coprocessor 20 does not authenticate the reprogramming application code and does not authorize the execution of the reprogramming application code on the application cores 10. During step 48, the main processor 4 executes, via the boot loader 18, the reprogramming application code on the application cores 10.

[0038] During step 36, the security coprocessor 20 downloads the rescue computer code 24 from the memory 22 of the transactional black box 8 to the memory means 6.

[0039] Preferably, during a step 50 following step 36, the security coprocessor 20 verifies the integrity of the rescue computer code 24, and authenticates the rescue computer code 24 if necessary.

[0040] During a step 52 following step 50, the security coprocessor 20 installs the rescue computer code 24 in place of a first launch sequence of the boot loader 18.

[0041] Preferably, during a step 54 following step 52, the security coprocessor 20 executes an instruction to reset the electronic control unit 2.

[0042] During a step 56 following step 54, the main processor 4 restarts under an authenticity session and executes the rescue computer code 24 on the application cores 10. The execution of the rescue computer code 24 on the application cores 10 then makes it possible to implement at least one diagnostic function, in order to be able to communicate with the outside of the electronic control unit 2 and to allow a user of the unit 2 or a manufacturer of the vehicle to understand the reason why the boot loader 18 and the application code 13 are no longer running within the system and / or to try to perform an update of the application code 13 within the unit 2.According to a particular embodiment of the invention, the execution of the rescue computer code 24 on the application cores 10 can also make it possible to upload the application code 13 from the memory means 6 to a memory of a third-party device connected to the electronic control unit 2 (such a third-party device not being shown in the figures for reasons of clarity). According to this particular embodiment, the third-party device is for example a block of RAM or a non-volatile storage device of the flash memory type. The rescue computer code 24 can for example be configured to be able to verify the integrity and authenticate the application code 13 uploaded to the memory of the third-party device.

[0043] The electronic control unit 2 for a vehicle according to the invention offers the possibility to a user or a manufacturer of the vehicle to understand the reason why the boot loader and the application code are no longer executing within the system, while allowing the electronic control unit to continue to execute in a dedicated mode in order to offer a means of communication and diagnosis with the outside.

Claims

1. Claims An electronic control unit (2) for a vehicle, the electronic control unit (2) comprising a main processor (4), memory means (6), a transactional black box (8) and a plurality of application cores (10), the memory means (6) being connected to the main processor (4) via a data communication bus (12) and storing a boot loader (18) and application code (13) intended to be executed by the main processor (4), on the plurality of application cores (10), said boot loader (18) comprising several launch sequences and being configured, when executed by the main processor (4), to require an integrity check and an authentication of the application code (13) stored in the memory means (6) and to execute said application code (13) on the plurality of application cores (10) when said application code (13) has been authenticated,the transactional black box (8) comprising a security coprocessor (20) and a memory (22), the security coprocessor (20) being connected to the main processor (4) and to the memory means (6) via the data communication bus (12) and being configured to verify the integrity and authenticate the application code (13) stored in the memory means (6) and to authorize the execution of said application code (13) on the plurality of application cores (10), the application cores (10) being connected to the main processor (4) via the data communication bus (12), characterized in that the memory (22) of the transactional black box (8) stores a rescue computer code (24), said rescue computer code (24) being intended to be executed by the main processor (4), on the plurality of application cores (10),and being configured to implement at least one diagnostic function of the electronic control unit (2) when executed by the main processor (4), and in that the security coprocessor (20) is further configured to verify the integrity and authenticate the boot loader (18) within the plurality of application cores (10) and, if the boot loader (18) is not authenticated, to download the rescue computer code (24) from the memory (22) of the transactional black box (8) to the memory means (6), to install said rescue computer code (24) in place of a first launch sequence of the boot loader (18) and to cause the main processor (4) to execute said rescue computer code, rescue (24) on the plurality of application cores (10).

2. Electronic control unit (2) according to claim 1, characterized in that the memory (22) of the transactional black box (8) is a non-volatile memory, preferably a flash memory.

3. Electronic control unit (2) according to claim 1 or 2, characterized in that a compressed image of the rescue computer code (24) is stored in the memory (22) of the transactional black box (8).

4. Electronic control unit (2) according to any one of claims 1 to 3, characterized in that the rescue computer code (24) is stored in an application portion of the memory (22) of the transactional black box (8).

5. Electronic control unit (2) according to any one of claims 1 to 4, characterized in that the security coprocessor (20) is further configured to verify the integrity and authenticate the rescue computer code (24).

6. Electronic control unit (2) according to any one of claims 1 to 5, characterized in that the safety coprocessor (20) is further configured to execute a reset instruction of the electronic control unit (2).

7. Electronic control unit (2) according to any one of claims 1 to 6, characterized in that the rescue computer code (24) is further configured, when executed by the main processor (4), to implement a function of uploading the application code (13) from the memory means (6) to a memory of a third-party device connected to the electronic control unit (2).

8. Method for operating an electronic control unit (2) for a vehicle according to any one of claims 1 to 7, characterized in that the method comprises the following steps: - verification (32), by the security coprocessor (20), of the integrity of the boot loader (18) within the plurality of application cores (10); - if the verification (32) of the integrity of the boot loader (18) within the plurality of application cores (10) is positive, authentication, by the security coprocessor, of the boot loader and: • sending (38), by the boot loader (18) to des- termination of the security coprocessor (20), of a request for verification of the integrity and authentication of the application code (13) stored in the memory means (6); • verification of the integrity (40, 41, 44, 46) and authentication, by the security coprocessor (20), of the application code (13) stored in the memory means (6); • authorization, by the security coprocessor (20), of the execution of said application code (13) on the plurality of application cores (10); and • execution (42, 48) by the main processor (4), via the boot loader (18), of said application code (13) on the plurality of application cores (10); - if the verification (32) of the integrity of the boot loader (18) within the plurality of application cores (10) is negative: • downloading (36), by the security coprocessor (20), of the rescue computer code (24) from the memory (22) of the transactional black box (8) to the memory means (6);• installation (52), by the security coprocessor (20), of said rescue computer code (24) in place of a first launch sequence of the boot loader (18); and • execution (56), by the main processor (4), of said rescue computer code (24) on the plurality of application cores (10).;

9. Method according to claim 8, characterized in that, if the verification (32) of the integrity of the boot loader (18) within the plurality of application cores (10) is negative, the method further comprises a step (50) of verification of the integrity and authentication, by the security coprocessor (20), of the rescue computer code (24).

10. Method according to claim 8 or 9, characterized in that, if the verification (32) of the integrity of the boot loader (18) within the plurality of application cores (10) is negative, the method further comprises a step (54) of execution, by the security coprocessor (20), of a reset instruction of the electronic control unit (2).

11. Method according to any one of claims 8 to 10, characterized in that the step of verification (32), by the security coprocessor (20), of the integrity of the boot loader (18) within the plurality of application cores (10) comprises a verification of the integrity of the first launch sequence of the boot loader (18) within the plurality of application cores (10), and a verification of the integrity of a flash boot loader module within the plurality of application cores (10), the verification (32) of the integrity of the boot loader (18) within the plurality of application cores (10) being positive if and only if the results of said two verifications are positive.

12. A computer program product (24) characterized in that it comprises a set of program code instructions which, when executed by a processor (4), configure the processor to implement one or more step(s) of the method according to any one of claims 8 to 11, said computer program product constituting the rescue computer code (24), said processor being the main processor (4).