Method for controlling an on-board computer capable of controlling a critical system, computer and associated vehicle
A single microkernel with an isolated control unit architecture for embedded systems in vehicles addresses the detection of various vulnerabilities by controlling access to hardware components, enhancing security and reliability from development to deployment.
Patent Information
- Application Number
- FR2022014531
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-27
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-12-27
AI Technical Summary
Existing methods for embedded systems fail to detect a comprehensive range of vulnerabilities, such as buffer and integer overflows, which can compromise the security and functionality of critical systems in vehicles.
Implementing a single microkernel with isolated control unit architecture, including a memory management unit and control unit, to manage and control access to hardware components, analyzing binary sections, and generating access configurations to ensure minimal and secure interactions, thereby blocking unauthorized modifications.
Enhances security by detecting a broader spectrum of vulnerabilities and ensuring secure operation from development to deployment, preventing data leaks and unauthorized access, thus improving the reliability of critical systems in vehicles.
Smart Images

Figure 00000009_0000 
Figure 00000010_0000
Abstract
Description
Title of the invention: Method for controlling an on-board computer capable of controlling a critical system, associated computer and vehicle
[0001] The present invention relates to an on-board computer and a vehicle comprising such an on-board computer.
[0002] In the field of embedded systems, security is a crucial issue.
[0003] In particular, during the development of embedded systems, vulnerabilities may be introduced. Examples include the buffer overflow technique (more often referred to by the corresponding English term "buffer overflow"), or the integer overflow technique (more often referred to by the corresponding English term "Integer overflow").
[0004] These vulnerabilities can allow an attacker during the use phase of the developed embedded system to recover confidential data, to temporarily or permanently modify the behavior of the embedded system, or even to render the embedded system inoperable.
[0005] It is known to limit the presence of vulnerabilities by using several techniques including unit testing, random data testing (more often referred to by the corresponding English term "fuzzer"), static code analysis, dynamic code analysis or formal proof.
[0006] In addition to these limitation tools, it is also possible to use techniques to detect the exploitation of vulnerabilities.
[0007] Unexpected stack modification detection is an example of such a technique. Stack canaries and shadow stacks are two techniques for detecting buffer overflows in the stack.
[0008] However, none of these techniques can detect all vulnerabilities.
[0009] There is therefore a need for a method of controlling an on-board computer making it possible to detect a larger set of vulnerabilities.
[0010] For this purpose, the description describes a method for controlling an on-board computer capable of controlling a critical system, the on-board computer comprising:
[0011] - a single microkernel adapted to implement a set of operations,
[0012] - hardware components that the microkernel has access to implement the set of operations, and
[0013] - a control unit, the control unit being capable of controlling the accesses of the mi microkernel to hardware components, the control unit being isolated from the microkernel,
[0014] the control method comprising a step of control by the control unit of the accesses of the microkernel to the hardware components.
[0015] According to particular embodiments, the control method has one or more of the following characteristics, taken in isolation or in all technically possible combinations:
[0016] - the on-board computer further comprises a memory management unit, the control step including the control of the memory management unit.
[0017] - the method further comprises the steps of:
[0018] - analysis of sections of a binary obtained by compilation of the microkernel, and
[0019] - deduction of accesses to hardware components by the microkernel during a func normal operation of the microkernel, to obtain an access configuration,
[0020] the access control step taking into account the access configuration.
[0021] - the method comprises the generation of a binary, the steps of analysis and deduction being implemented using the generated binary.
[0022] - during the deduction step, the access configuration corresponds to the number minimal access to hardware components allowing normal operation of the microkernel.
[0023] - the control method also includes a step of blocking the modification of the micronucleus.
[0024] - the hardware components comprise a computing unit, the method being implemented works at the start of the computing unit.
[0025] - privilege levels for access to hardware components are defined, the level of privilege of the control unit being strictly superior to the privilege level of the microkernel.
[0026] The description also describes an on-board computer suitable for controlling a critical system, the on-board computer comprising:
[0027] - a single microkernel adapted to implement a set of operations,
[0028] - hardware components that the microkernel has access to implement the set of operations, and
[0029] - a control unit, the control unit being capable of controlling the accesses of the mi microkernel to hardware components, with the control unit being isolated from the microkernel.
[0030] The description also relates to a vehicle comprising an on-board computer as previously described.
[0031] In the present description, the expression “suitable for” means indifferently “adapted for”, “adapted to” or “configured for”.
[0032] Characteristics and advantages of the invention will appear on reading the description which follows, given solely by way of non-limiting example, and made with reference to the appended drawings, in which:
[0033] - [Fig.l] [Fig.l] is a schematic representation of an example vehicle comprising an on-board computer with several units, and
[0034] - [Fig.2] [Fig.2] is a schematic representation of the operation of the callus culator illustrating the interactions between the units represented in [Fig.l].
[0035] A vehicle 10 is schematically illustrated in [Fig.l].
[0036] The vehicle 10 is any type of vehicle and in particular, can be a land, air or sea vehicle.
[0037] The vehicle 10 comprises a set 12 of systems including non-critical systems 14 and critical systems 16.
[0038] A system is considered a critical system when a failure of this system jeopardizes the operation of the vehicle 10.
[0039] For example, the propulsion system or the detection systems are critical systems 16.
[0040] The vehicle 10 also comprises an on-board computer 18 adapted to control the critical systems 16.
[0041] In the following, the on-board computer 18 is simply called computer 18 to simplify reading.
[0042] Due to such control, the computer 18 is a critical system.
[0043] In this respect, the calculator 18 respects a relatively high level of security by compared to a standard processor that does not meet security needs.
[0044] As shown schematically in [Fig.l], the computer 18 comprises a single microkernel 20, hardware components 22, a memory management unit 24 and a control unit 26.
[0045] The microkernel 20 is unique but serves to manage several tasks. This is represented very schematically in [Fig.2] by a set of superimposed sheets with the reference sign 21.
[0046] In this respect, the microkernel 20 is adapted to implement a set of operations.
[0047] Thus, in the following, the tasks or operations that the microkernel 20 is capable of implement are associated with reference sign 21.
[0048] The microkernel 20 is an element retaining a small number of fundamental functions. All of the functionalities usually offered by monolithic kernels are then provided by elements external to the microkernel 20.
[0049] This allows for a small kernel with better security, which is required for embedded applications.
[0050] Typically a microkernel corresponds to less than 50,000 lines of code while a kernel corresponds to several million lines of code.
[0051] The hardware components 22 are components to which the microkernel 20 has access to implement the set of operations 21.
[0052] For purely illustrative purposes, in the case of [Fig. 1], it is assumed that the hardware components 22 are a memory 28 and a computing unit 30.
[0053] The functionalities of the memory 28 and of the calculation unit 30 are here standard functionalities for the embedded domain, namely respectively storing data and carrying out operations 21.
[0054] The microkernel 20 can access the memory 28 in three ways: • read only (mode more often designated by the corresponding English term “read only”), or • reading and writing (a modality more often referred to by the corresponding English term “read / write”), or • execution (modality more often designated by the corresponding English term “execute” and which uses the presence of a register giving the position of the next instruction to be executed).
[0055] The memory management unit 24 is used to control memory accesses.
[0056] The memory management unit 24 is more often referred to by the abbreviation MMU referring to the corresponding English name of “Memory Management Unit”.
[0057] The control unit 26 is capable of controlling the accesses of the microkernel 20 to the hardware components 22.
[0058] As will be described later, in the example described, the control unit 26 controls the accesses by controlling the memory management unit 24.
[0059] The control unit 26 is isolated from the microkernel 20 and from the tasks 21 that the microkernel 20 performs.
[0060] By isolation is meant here the fact that the control unit 26 operates completely independently of the microkernel 20.
[0061] Furthermore, the control unit 26 has a level of access privilege to the hardware components 22 which is strictly higher than the level of privilege of the microkernel 20.
[0062] Preferably, the control unit 26 has the highest privilege level.
[0063] This ensures good control of the microkernel 20 by the control unit 26.
[0064] Conversely, the lower privilege level of the microkernel ensures that the microkernel 20 cannot modify the control unit 26.
[0065] The control unit 26 here corresponds to a small code, typically less than 1000 lines.
[0066] The operation of the computer 18 is now described with reference to the schematic representation of [Fig.2] corresponding to the implementation of a method for controlling the computer 18.
[0067] The control method comprises a first phase implemented by a unit analysis 32, schematized by a square in [Fig.2].
[0068] It is assumed here that the microkernel 20 is in the process of being produced, i.e. the first phase corresponds to the development / fine-tuning phase of the microkernel 20 before its deployment in the field.
[0069] When the microkernel 20 is compiled (see element Cl in [Fig.2]), a binary 34 of the program is generated.
[0070] Such a binary is more often referred to by the corresponding English term "binary". The binary is a file organized into predefined sections, the sections gathering, for example, instructions or read-only data (constants).
[0071] Binary 34 describes, for microkernel 20, the interactions between microkernel 20 and the exterior of microkernel 20.
[0072] The analysis unit 32 uses the binary 34 to analyze the different sections of the binary 34 to generate the access rights associated with the different memory areas depending on the data stored there (constants, executable or the stack)
[0073] According to the embodiment described, the analysis unit 32 calculates the minimum number of accesses to the different memory areas allowing the normal operation of the microkernel 20 and the tasks 21 that it performs.
[0074] This makes it possible in particular to restrict the quantity of usable memory to just what is necessary. Such a restriction makes it possible to limit the risks of confidential data leaking into memory and the associated tests or erasure.
[0075] This operation is schematized by element 36 in [Fig.2].
[0076] The analysis unit 32 is thus a tool for generating automatic security policy configuration. As such, it is capable of analyzing the binary 34 to identify the security properties associated with each standard section of the binary 34.
[0077] From this identification, the analysis unit 32 is capable of generating an access configuration 36.
[0078] The access configuration 36 can be used in a standard format to possibly allow for additional manual configuration.
[0079] In particular, a manual configuration addition may consist of defining the security properties associated with non-standard sections.
[0080] This access configuration 36 is then converted into a configuration file 40 interpretable by a compiler.
[0081] The configuration file 40 gathers the authorized accesses to the memory 28.
[0082] The method then comprises a second compilation step (element C2 in [Fig.2]) corresponding to the compilation of the control unit, the binary-program interface and the access configuration.
[0083] Knowledge of authorized accesses to hardware components 22 by the unit of control 26 allows it to control the memory management unit 24.
[0084] More precisely, the control unit 26 will require the memory management unit 24 to operate according to rules corresponding to the authorized accesses of the generated configuration.
[0085] To increase security, the control method also includes a step of blocking the modification of the microkernel 20.
[0086] This means that the control unit 26 makes it possible to make the code zones corresponding to the microkernel 20 non-modifiable.
[0087] A computer 18 is thus obtained for which the control unit 26 is thus capable of detecting any abnormal access request at the level of the memory management unit 24 during the second phase corresponding to the operation of the computer 18.
[0088] This allows for the detection of buffer overflow or integer overflow techniques.
[0089] The control method described thus makes it possible to obtain better security for the computer 18.
[0090] This control has the specific feature of being carried out during all phases of obtaining the computer 18 and not only in the operational phase.
[0091] Indeed, control is ensured as soon as it is possible to compile the microkernel 20.
[0092] This is therefore already the case during the development phase of microkernel 20.
[0093] Furthermore, it is the same control unit 26 which is used both during the development development and use, which limits the ability of an attacker to exploit a vulnerability in a microkernel 20.
[0094] The presence of the control unit 26 makes it possible to obtain a computer 18 compatible with the constraints of the on-board system.
[0095] Other embodiments of the method can be considered while guaranteeing this good level of security.
[0096] In particular, the method may include a step of creating a log recording all unauthorized accesses.
[0097] This improves the monitoring of the proper functioning of the computer 18.
[0098] It is also essential that the control step be implemented at the start of the calculation unit 30 to ensure that the control is always effective.
[0099] When the hardware components 22 include components other than the components of [Fig.l], the access configuration 36 also includes elements to prevent these components from being able to make modifications or bypass the checks carried out by the memory management unit 24.
Claims
Claims
1. Method for controlling an on-board computer (18) capable of controlling a critical system (16), the on-board computer (18) comprising: - a single microkernel (20) adapted to implement a set of operations (21), - hardware components (22, 28, 30) to which the microkernel (20) has access to implement the set of operations (21), and - a control unit (26), the control unit (26) being capable of controlling the accesses of the microkernel (20) to the hardware components (22, 28, 30), the control unit (26) being isolated from the microkernel (20), the control method comprising a step of controlling by the control unit (26) the accesses of the microkernel (20) to the hardware components (22, 28, 30).
2. A control method according to claim 1, wherein the on-board computer (18) further comprises a memory management unit (24), the control step comprising controlling the memory management unit (24).
3. Control method according to claim 1 or 2, wherein the method further comprises the steps of: - analyzing the sections of a binary (34) obtained by compiling the microkernel (20), and - deducing accesses to the hardware components (22, 28, 30) by the microkernel (20) during normal operation of the microkernel (20), to obtain an access configuration, the step of controlling the accesses taking into account the access configuration.
4. A control method according to claim 3, wherein the method comprises generating a binary (34), the analysis and deduction steps being implemented using the generated binary.
5. Control method according to claim 3 or 4, wherein, during the deduction step, the access configuration corresponds to the minimum number of accesses to the hardware components (22, 28, 30) allowing normal operation of the microkernel (20).
6. Control method according to any one of claims 1 to 5, in which the control method also comprises a step of blocking the modification of the microkernel (20).
7. A control method according to any one of claims 1 to 6, wherein the hardware components (22, 28, 30) comprise a computing unit (30), the method being implemented upon startup of the computing unit (30).
8. Control method according to any one of claims 1 to 7, in which access privilege levels to the hardware components (22, 28, 30) are defined, the privilege level of the control unit (26) being strictly higher than the privilege level of the microkernel (20).
9. An on-board computer (18) capable of controlling a critical system (16), the on-board computer (18) comprising: - a single microkernel (20) adapted to implement a set of operations (21), - hardware components (22, 28, 30) to which the microkernel (20) has access to implement the set of operations (21), and - a control unit (26), the control unit (26) being capable of controlling the accesses of the microkernel (20) to the hardware components (22, 28, 30), the control unit (26) being isolated from the microkernel (20).
10. Vehicle (10) comprising an on-board computer (18) according to claim 9.