Method and system for renovating a vehicle computer
The method for renovating vehicle computers by replacing and re-pairing cybersecurity modules allows for the reuse of functional vehicle computer components, addressing the issue of hardened modules and reducing repair costs while maintaining cybersecurity standards.
Patent Information
- Application Number
- FR2023014436
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-06-20
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method and system for renovating a vehicle calculator Technical field
[0001] The present invention relates to methods and systems for renovating a vehicle computer, in particular but not exclusively for a motor vehicle. More particularly, the present invention relates to a method and a system for renovating a vehicle computer. The present invention also relates to a method and an assembly system for a computer. Technological background
[0002] Contemporary vehicles have a number of computers on board, each performing one or more functions, such as, for example, the management of driving assistance, engine control, anti-skid, electronic brake distribution, the control of actuators to ensure optimal operation of an engine, the piloting and control of the infotainment system, also called IVI system (from the English "In-Vehicle Infotainment" or in French "Infodivertissement embargo") and / or other systems embedded in the vehicle such as, for example, the air conditioning system and the vehicle's navigation system.
[0003] These calculators are also called ECU ("Electronic Control Unit" or ECU in English). These calculators embed software that is executed to ensure the functions for which they are responsible. With the development of connected vehicles, i.e. vehicles configured to communicate data via one or more wireless links and / or one or more OBD (on-board diagnostic) or USB (Universal Serial Bus) type links for example, and autonomous vehicles, i.e. vehicles configured to travel with a variable level of autonomy up to an autonomous driving mode without driver supervision, the number of calculators and other communication components has increased in vehicles, with a parallel increase in embedded software.Contemporary vehicles are therefore more exposed to the risks of cyberattack.
[0004] Standards and regulations have been published to address these cybersecurity risks, including United Nations Regulation No. 155 (Cybersecurity Management System) and UN Regulation No. 156 (Software Update Management System). The ISO / SAE 21434 standard on motor vehicle cybersecurity was also published in August 2021.
[0005] The computers meeting the requirements of these regulations and / or standards are associated with a single vehicle, these computers being said to be hardened once they have been paired with the vehicle intended to carry them. An associated problem is that once such a computer has been hardened, it cannot be reused in another vehicle, which limits the ability to reuse components from damaged vehicles for example, even though these components are still functional. Summary of the present invention
[0006] An object of the present invention is to solve at least one of the problems of the technological background described above.
[0007] Another object of the present invention is to improve the renovation or reuse of a vehicle computer.
[0008] According to a first aspect, the present invention relates to a method for renovating a vehicle computer, the method comprising the following steps: - removing a first cybersecurity hardware module from an electronic circuit of the computer, the first cybersecurity hardware module being paired with a first vehicle; - assembling a second cybersecurity hardware module on the electronic circuit at a location of the first cybersecurity hardware module, the second cybersecurity hardware module being configured to be paired with a vehicle of a set of vehicles compatible with the computer; - pairing the second cybersecurity hardware module with a second vehicle belonging to the set of vehicles.
[0009] Removing the cybersecurity module paired with a first vehicle to replace it with a non-paired cybersecurity module, i.e. one paired with no vehicle, makes it possible to reuse the computer initially mounted in the first vehicle to mount it in another vehicle, with pairing of the new cybersecurity module with this other vehicle. This thus makes it possible to reuse all of the components of the computer recovered in the first vehicle, with the exception of the original cybersecurity module. This thus makes it possible to reduce the costs associated with repairing a vehicle having, for example, a defective computer to replace it with a compatible computer recovered from another vehicle, even if this compatible computer had been hardened.
[0010] According to a variant, the method further comprises a step of mounting the computer comprising the second cybersecurity hardware module in the second vehicle.
[0011] According to another variant, the pairing is implemented prior to assembly.
[0012] According to an additional variant, the pairing is implemented after the assembly.
[0013] According to an additional variant, the pairing comprises writing an identifier of the second vehicle in a non-rewritable memory of the second cybersecurity hardware module.
[0014] According to another variant, the identifier corresponds to at least one certificate and / or at least one cryptographic key.
[0015] According to another variant, the identifier corresponds to a vehicle identification number, known as VIN.
[0016] According to an additional variant, the second cybersecurity hardware module corresponds to a microcontroller.
[0017] According to another variant, the method further comprises the following steps: - calculator classification to determine a calculator type; - determination of a type of the second cybersecurity hardware module based on the type of the calculator.
[0018] According to a second aspect, the present invention relates to a vehicle computer renovation system, the system comprising means configured for implementing the steps of the method according to the first aspect of the present invention.
[0019] According to a third aspect, the present invention relates to a vehicle carrying the computer obtained by implementing the steps of the method according to the first aspect of the present invention. Brief description of the figures
[0020] Other characteristics and advantages of the present invention will emerge from the description of the particular and non-limiting exemplary embodiments of the present invention below, with reference to the appended figures 1 to 3, in which:
[0021] [Fig-1] schematically illustrates a process of removing a computer from a first vehicle, according to a first exemplary embodiment of the prior art.
[0022] [Fig.2] schematically illustrates a process for mounting the computer of [Fig.l] in a second vehicle, according to a second exemplary embodiment of the prior art.
[0023] [Fig.3] schematically illustrates a method of renovating the computer of figures 1 and 2, according to a particular and non-limiting exemplary embodiment of the present invention. Description of examples of implementation
[0024] A method and a system for renovating a vehicle computer will now be described in the following with joint reference to FIGS. 1 to 3. The same elements are identified with the same reference signs throughout the description which follows.
[0025] The terms “first(s)”, “second(s)” (or “first(s)”, “second(s)”), etc. are used in this document by arbitrary convention to identify and distinguish different elements (such as operations, means, etc.) implemented in the embodiments described below. Such elements may be distinct or correspond to a single element, depending on the embodiment.
[0026] According to a particular and non-limiting example of embodiment of the present invention, the renovation of a computer obtained from a first vehicle comprises the removal of a first cybersecurity hardware module from an electronic circuit forming the computer, the first cybersecurity hardware module being paired with the first vehicle. Such a computer is said to be hardened in that its cybersecurity module has been associated or paired with the first vehicle, preventing the reuse of this first cybersecurity hardware module from being reused in any other vehicle. A second cybersecurity hardware module is then assembled on the electronic circuit in the location freed by the first cybersecurity hardware module on the electronic circuit, the second cybersecurity hardware module being unhardened, i.e. configured to be paired with a vehicle other than the first vehicle, this other vehicle being compatible with the computer.Finally, the second security hardware module is paired with a second vehicle compatible with the computer and designed to receive the computer, the computer and its second cybersecurity hardware module becoming hardened again.
[0027] [Fig. 1] schematically illustrates a process for removing or dismantling a computer 12 from a first vehicle 10, according to a particular and non-limiting exemplary embodiment of the present invention.
[0028] The first vehicle 10 corresponds for example to a vehicle with a thermal engine, with electric motor(s) or even a hybrid vehicle with a thermal engine and one or more electric motors. The vehicle thus corresponds for example to a land vehicle, for example an automobile, a truck, a bus, a motorcycle.
[0029] The first vehicle 10 carries a set of computers including the computer 12, these computers connected together forming a multiplexed architecture to communicate and exchange data between them (and / or with communication devices external to the first vehicle 10 via a computer forming a TCU (Telematic Control Unit)) via one or more computer buses, for example a communication bus of the CAN (Controller Area Network) type, CAN FD (Controller Area Network Flexible Data-Rate), FlexRay (according to the ISO 17458 standard) or Ethernet (according to the ISO / IEC 802-3 standard). According to a variant, the computers, or part of the computers, communicate via a wireless link, for example via a Bluetooth® or Wifi® type connection.
[0030] In a first operation of the removal process, the computer 12 is removed from the first vehicle 10. The computer 12 is for example removed from the first vehicle 10 following an accident of the first vehicle 10, the removal of the computer 12 being part of a broader operation of removing parts, organs and components of the first vehicle 10 that can be reused second-hand in a set of compatible vehicles that can receive at least one part, organ and / or component of the first vehicle 10. According to another example, the computer 12 is removed or dismantled from the first vehicle 10 following the detection of a failure or an anomaly of the computer 12, for example due to a faulty component of the computer 12.
[0031] The computer 12 is removed from the first vehicle 10 using tools suitable for this purpose, for example using a key and / or a screwdriver to remove in particular the fixing elements provided for fixing the computer 12 to the first vehicle 10.
[0032] In a second operation of the removal process, the first cybersecurity hardware module 11 of the computer 12 is removed from the electronic circuit of the computer 12, for example using a manual extractor of the extraction pliers type or an automatic component extraction machine.
[0033] Once the first cybersecurity hardware module 11 has been removed from the computer 12, the location 120 of this first cybersecurity hardware module 11 on the electronic circuit of the computer 12 is available to receive another cybersecurity hardware module, as described below with reference to [Fig.2].
[0034] The first cybersecurity hardware module 11 corresponds to a single hardware component or to a plurality of hardware components.
[0035] A cybersecurity hardware module includes a set of cryptographic hardware of the software type or parameters (certificates or cryptographic keys) configured to offer one or more cybersecurity services such as generating, storing, protecting one or more cryptographic keys (for example public key, private key or secret key) and / or ensuring encrypted data communications.
[0036] The first cybersecurity hardware module 11 corresponds to a component or set of components that has been associated with the first vehicle 10 during a pairing operation. The pairing operation comprises, for example, writing a unique identifier of the first vehicle 10 into a non-rewritable memory of the first cybersecurity hardware module 11, such that this first cybersecurity hardware module 11 can only be used with the first vehicle 10. The unique identifier corresponds, for example, to one or more certificates and / or one or more cryptographic keys or even to the vehicle identification number (VIN) of the English “Vehicle Identification Number”).
[0037] In a third optional operation of the withdrawal process, the calculator 12 from which the first cybersecurity hardware module 11 was removed is shipped to a vehicle spare parts distribution network or to an authorized vehicle repairer of a manufacturer of vehicles compatible with the computer 12.
[0038] According to an alternative embodiment, the process further comprises an operation of classifying the computer 12, such a classification operation corresponding to a sorting of the computer 12 according to its type, the type of the computer comprising a set of information such as for example: - the type of vehicle compatible with the calculator (for example the make, model or even serial number of the vehicle that can work with the calculator); and / or - the category of the calculator (engine control calculator, TCU type calculator, IVI type calculator, BSI type calculator (Intelligent Servitude Box), etc.).
[0039] [Fig.2] schematically illustrates a process for mounting or renovating the computer 12 on a second vehicle 20, according to a particular and non-limiting exemplary embodiment of the present invention.
[0040] The second vehicle 20 corresponds for example to a vehicle with a thermal engine, with electric motor(s) or even a hybrid vehicle with a thermal engine and one or more electric motors. The second vehicle 20 thus corresponds for example to a land vehicle, for example an automobile, a truck, a bus, a motorcycle.
[0041] The second vehicle 20 advantageously belongs to a set of vehicles with which the computer 12 is compatible, that is to say that each vehicle of the set of vehicles is designed to operate with the computer 12.
[0042] The second vehicle 20 is for example of the same type as the first vehicle 10, the first vehicle 10 and the second vehicle 20 being two different vehicles.
[0043] The computer 12 is for example selected from a set of reconditioned computers according to its type obtained from the classification operation described previously.
[0044] In a first operation of the process, a second cybersecurity hardware module 21 is mounted or assembled on the electronic circuit at the location 120 left vacant by the first cybersecurity hardware module 11 following the operation of removing the first cybersecurity hardware module 11.
[0045] The second cybersecurity hardware module 21 is configured to be paired with any vehicle in the set of vehicles compatible with the computer 12.
[0046] The second cybersecurity hardware module 21 is for example received or obtained from a manufacturer or supplier of such security components which is for example different from the supplier implementing the process of removing the first module. cybersecurity hardware 11 and / or the process of renovating or assembling the second cybersecurity hardware module 21.
[0047] The second cybersecurity hardware module 21 has characteristics similar or identical to those of the first cybersecurity hardware module 11, for example in terms of hardware characteristics (for example the pins or connections provided for connecting the second cybersecurity hardware module 21 to the electronic circuit of the computer 12) and / or in terms of immaterial characteristics (for example software or parameters stored in the memory of the second module 21).
[0048] The second cybersecurity hardware module 21 has, for example, the same references as the first cybersecurity hardware module 11.
[0049] The type or references of the second cybersecurity hardware module 21 are for example determined according to the type of the computer 12 obtained as a result of the classification described previously.
[0050] The second cybersecurity hardware module 21 corresponds to a single hardware component or to a plurality of hardware components. According to a particular exemplary embodiment, the second cybersecurity hardware module 21 corresponds to a microcontroller.
[0051] The second cybersecurity hardware module 21 is mounted or assembled on the electronic circuit via one or more tools provided for this purpose, for example a soldering iron or an automatic renovation machine, such as a BGA (ball grid array) renovation machine.
[0052] In a second operation of the renovation process, the computer 12 is paired with the second vehicle 20. The pairing comprises a pairing of the second cybersecurity hardware module 21 with the second vehicle 20, for example following the assembly of the second cybersecurity hardware module 21 on the electronic circuit of the computer 12.
[0053] The pairing of the second cybersecurity hardware module 21 to the second vehicle 20 comprises the writing of an identifier of the second vehicle 20 in a non-rewritable memory of the second cybersecurity hardware module 21. Such pairing corresponds for example to an update (from the English "flash") of the microprogram (from the English "firmware") of the second cybersecurity hardware module 21 via a "flashing" device.
[0054] The identifier of the second vehicle 20 corresponds for example to one or more certificates, one or more cryptography keys or even to the VIN of the second vehicle 20.
[0055] The pairing of the second cybersecurity hardware module 21 is for example implemented following the assembly of the second cybersecurity hardware module 21 on the electronic circuit of the calculator 12.
[0056] In a third operation of the renovation process, the computer 12 including the second cybersecurity hardware module 21 is mounted in the second vehicle 20 via one or more suitable tools such as a screwdriver or a key to fix the computer 12 to its location or in its housing provided for this purpose in the second vehicle 20.
[0057] The mounting of the computer 12 comprises for example a connection of the computer to one or more connectors of the second vehicle 12 configured to connect or link the computer 12 to the on-board network of the second vehicle 12, i.e. to one or more data buses of the wired and / or wireless communication network of the second vehicle 20.
[0058] The pairing of the second cybersecurity hardware module 21 is implemented prior to (i.e. before) the installation of the computer 12 in the second vehicle 20 or, according to another example, after the installation of the computer 12 in the second vehicle 20, i.e. once the computer 12 is connected to the on-board network of the second vehicle 20.
[0059] Such a process makes it possible to reduce the cost of replacing a computer (for example a defective or out-of-service computer of the second vehicle 20) by using a reconditioned computer, i.e. a computer 12 for which only part of the components has been replaced (i.e. the second cybersecurity hardware module 21).
[0060] [Fig. 3] illustrates a flowchart of the different steps of a method for renovating a vehicle computer, according to a particular and non-limiting exemplary embodiment of the present invention. The method is for example implemented by a renovation system comprising means for implementing the steps of the method.
[0061] In a first step 31, a first cybersecurity hardware module is removed from an electronic circuit of the computer, the first cybersecurity hardware module being paired with a first vehicle.
[0062] In a second step 32, the second cybersecurity hardware module is assembled or mounted on the electronic circuit at the location of the first cybersecurity hardware module previously removed, the second cybersecurity hardware module being configured to be paired with a vehicle from a set of vehicles compatible with the computer.
[0063] In a third step 33, the second cybersecurity hardware module is paired with a second vehicle belonging to the set of vehicles.
[0064] According to a variant, the variants and examples of the operations described in relation to figures 1 and 2 apply to the steps of the method of [Fig.3].
[0065] Of course, the present invention is not limited to the exemplary embodiments described above but extends to a method of repairing or reconditioning a computer which would include secondary steps without thereby departing from the scope of the present invention. The same would apply to a device configured for implementing such a method.
[0066] The present invention also relates to a system for renovating a computer, such as computer 12, in a vehicle.
Claims
Claims
1. A method for renovating a vehicle computer, said method comprising the following steps: - removing (31) a first cybersecurity hardware module (11) from an electronic circuit of the computer (12), said first cybersecurity hardware module (11) being paired with a first vehicle (10); - assembling (32) a second cybersecurity hardware module (21) on said electronic circuit at a location (120) of said first cybersecurity hardware module (11), said second cybersecurity hardware module (21) being configured to be paired with a vehicle of a set of vehicles compatible with said computer; - pairing (33) said second cybersecurity hardware module (21) with a second vehicle (20) belonging to said set of vehicles.
2. The method of claim 1, further comprising a step of mounting said computer (12) comprising said second cybersecurity hardware module (21) in said second vehicle (20).
3. A method according to claim 2, wherein said pairing is carried out prior to said assembly.
4. Method according to claim 2, for which said pairing is implemented after said assembly.
5. Method according to one of claims 1 to 4, for which said pairing (33) comprises writing an identifier of said second vehicle (20) in a non-rewritable memory of said second cybersecurity hardware module (21).
6. Method according to claim 5, for which said identifier corresponds to at least one certificate and / or at least one cryptographic key.
7. Method according to claim 5, for which said identifier corresponds to a vehicle identification number, called VIN.
8. Method according to one of claims 1 to 7, for which said second cybersecurity hardware module (21) corresponds to a microcontroller.
9. Method according to one of claims 1 to 8, further comprising the following steps: - classifying said computer (12) to determine a type of said computer; - determining a type of said second cybersecurity hardware module (21) as a function of the type of said computer.
10. Vehicle computer refurbishment system, said system comprising means configured for implementing the steps of the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Reuse system, key creating device, data security device, on-vehicle computer, reuse method, and computer program
EP3541006A1