Anti-intrusion device for an on-board system, particularly integrated into a motor vehicle

The anti-intrusion device uses ultrasonic waves to detect physical breaches in on-board vehicle systems, effectively preventing unauthorized access and ensuring the integrity of the electronic control units.

FR3157309A1Pending Publication Date: 2025-06-27AMPERE SAS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023015221
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Existing anti-intrusion methods for on-board systems in vehicles, such as electronic control units, are inadequate in protecting against physical attacks that compromise the integrity of the system, allowing attackers to access confidential information and manipulate internal signals.

Method used

An anti-intrusion device that emits ultrasonic waves and uses a control unit to compare the emitted signal to a reference signal, detecting any breaches in the system's integrity through changes in the wave patterns caused by physical modifications.

Benefits of technology

The device effectively prevents physical intrusions into vehicle computers by detecting any mechanical modifications, such as drilling, and ensuring the integrity of the electronic card and interfaces between semiconductors, thereby protecting confidential information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Anti-intrusion device for an on-board system, in particular integrated in a motor vehicle Anti-intrusion device intended to be integrated in an on-board system, in particular in an electronic control unit, the on-board system being in particular integrated in a motor vehicle, the device comprising an element for emitting ultrasonic waves, the device comprising or being connected to a control unit configured to receive a signal resulting from the emission of ultrasonic waves by said element and to compare it with a reference signal in order to detect a possible breach of the integrity of the on-board system. Figure for the abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Anti-intrusion device for an on-board system, in particular integrated into a motor vehicle Technical field

[0001] The present invention relates to an anti-intrusion device intended to be integrated into an on-board system, in particular into an electronic control unit, the on-board system being in particular integrated into a motorized vehicle. Prior art

[0002] Modern vehicles include electronic control units (ECUs) containing increasingly complex and powerful computing processors, and memories storing increasingly confidential “DATA” information, such as user data under GDPR, advanced driving assistance algorithms and systems under intellectual property, security keys for diagnostics or remote updates.

[0003] Such an electronic control unit "A" is shown in [Fig.l]. It comprises printed circuits "CI", printed circuit connectors "CO", electronic components "B", internal buses "C", a housing "D" and an external interface "E". An attacker with physical access to the system, placed in the vehicle or extracted from the vehicle, can attack it in several ways. He can remove or cut the mechanical housing. He can gain access to confidential information stored on the electronic chip by using an invasive attack on the silicon. The attacker can listen to and / or tamper with the internal signals and buses. He can replace the genuine chip with a bad chip to trigger malicious behavior.

[0004] Vehicles already integrate mechanisms to protect them against attacks coming from the internal network, or from external elements, called "offboard", for example Gateway, Proxy mechanisms, or a "VLAN" type system, for virtual local area network. However, attackers with large financial resources can carry out physical attacks on electronic cards and their semiconductors, and succeed in recovering various data.

[0005] These attackers can directly recover confidential information, for example stored in memories containing a one-time password, the English acronym of which is "OTP" of the semiconductor, i.e. fuses, allowing the decryption of normally secure data (user data, firmware), or to amplify their attacks to an entire fleet of vehicles (recovery of a non-diversified MAC key used for updating, unlocking functions debugging and tamper-evident capabilities). They can also retrieve information that is not directly confidential, but which allows them to understand how the system works and improve the attacker's knowledge, then allow them to generalize their attack to all vehicles after dismantling a single ECU.

[0006] These attack modes are now partially resolved by semiconductors made more robust with complementary systems such as Secure Storage, RPMB, or integrated HSMs, but the problem is not completely resolved, attackers generally being able to reread OTP memories by physical attacks.

[0007] It is still possible for the attacker to remove or cut the mechanical box “D” to have physical access “AP”, so that he can access confidential information:

[0008] - using invasive “AI” attacks on the silicon stored on the chip of the electronic component “B”, and / or

[0009] - by intercepting or falsifying “IF” of internal “C” signals or buses, and / or

[0010] - replacing the genuine chip with a parasitic “PP” chip to trigger a malicious behavior.

[0011] Known methods always focus on countermeasures at the semiconductor level, in particular on the metallization layers, with voltage or capacitive measurements, micro-mesh, but do not allow the protection of a complete electronic card, nor the interfaces between several semiconductors.

[0012] Other known methods implement techniques of the "anti-tamper switch" type (infrared, pressure sensors, capacitive sensors), or use infrared illumination when a housing is light-tight. These devices are less robust, an attacker being able to bypass them very simply after passing through X-rays of the protected system.

[0013] Techniques have also been developed in the field of radio frequencies, but consume a lot of electrical energy and require significant volumes and modifications to the systems, in particular by adding a Faraday cage, thus not allowing operation suitable for a system on board a vehicle. Statement of the invention

[0014] There is thus a need to further improve the means for ensuring the integrity of on-board systems, in particular electronic control units integrated into a motor vehicle. Summary of the invention Anti-intrusion device

[0015] The present invention meets this need thanks to, according to one of its aspects, an anti-intrusion device intended to be integrated into an on-board system, in particular into an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the device comprising an element for emitting ultrasonic waves,

[0016] the device comprising or being connected to a control unit configured to receive a signal resulting from the emission of ultrasonic waves by said element and to compare it to a reference signal in order to detect a possible break in the integrity of the on-board system.

[0017] Thanks to the invention, physical intrusions into the vehicle's computers can be prevented. The invention makes it possible to protect a complete electronic card, as well as the interfaces between several semiconductors.

[0018] When the attacker performs a drilling or any other mechanical modification, the transmitted waves are modified compared to their reference state, due to destructive or constructive interference, or reflection. The received signal is modified, cross-correlation or artificial intelligence techniques make it possible to detect this breach of integrity.

[0019] The invention allows the protection of a complete embedded system, that is to say an electronic card in its housing, with its semiconductors, against physical reverse engineering attacks, by an active mechanism capable of destroying confidential information if an intrusion is detected in the housing, or at least of being able to determine at a given moment whether the system has all its integrity or whether it could have been rendered non-integral in its life cycle, in particular by an attempt at dismantling.

[0020] Unlike known methods known as "anti-tampering", which can be easily circumvented as long as the attacker is aware of the mechanism, the invention cannot be circumvented by an attacker, because the mechanical properties of the materials and the non-deterministic nature of the signal do not allow the attacker to reproduce it. The invention leaves very little room for maneuver to the attacker, even if he has prior knowledge of an identical system. Emitting element

[0021] In a preferred embodiment, the ultrasonic wave emitting element is a transducer configured to emit ultrasonic waves, being in particular a piezoelectric transducer, in particular of the PZT ceramic type.

[0022] In a first embodiment, said transducer is configured to emit ultrasonic waves into at least a portion of the material that constitutes the housing of the device. The waves advantageously propagate in the form of surface waves, called “Lamb waves”, in the material.

[0023] This embodiment is based on mechanical transmission in the material of the device housing, for example ABS plastic or aluminum. It offers a more robust but more expensive solution, with more difficult coupling with the ultrasonic wave emitting element.

[0024] The device may be configured such that the reception frequency of the ultrasonic waves is determined as a function of at least said material and / or a predefined temperature range.

[0025] In this embodiment, said transducer is advantageously further configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit. In a variant, the device may further comprise a receiving element configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit, said receiving element being in particular a transducer

[0026] In a second embodiment, said transducer is configured to emit ultrasonic waves inside the space defined by the housing of the on-board system, the waves being emitted in particular into the air or gas present in said space.

[0027] In this embodiment, the device is configured so that the ultrasonic waves propagate at a frequency between 30 kHz and 50 kHz, being in particular equal to 40 kHz.

[0028] Said transducer is advantageously further configured to receive the ultrasonic waves after their propagation within the space defined by the housing of the on-board system and to emit said resulting signal received by the control unit.

[0029] This embodiment uses the propagation of waves by acoustic transmission in the air or gas enclosed in the system housing, and which contains the electronic card. This constitutes a lower cost solution, but not suitable for all mechanics, in particular due to the difficulty of integration in very compact housings, and less robust.

[0030] The ultrasonic waves are advantageously reflected on the walls of the housing, the printed circuits, the connectors, the fasteners, interact with each other in the form of constructive or destructive interference, then return to their starting point at the transducer. The signal received at the transducer thus depends on the geometry of the elements inside the housing, and on the geometry of the housing itself. As soon as an intrusion is carried out, for example by drilling the housing, removing a cover, inserting a probe, this geometry is modified, and a break in the mechanical integrity is therefore detected by processing the signal which returns to the transducer. Command and control units

[0031] The ultrasonic wave emitting element may comprise or be connected to a unit control system configured to send a train of waves, including Gaussian pulses, including pulses of a predefined duration, including at predefined or randomly defined intervals. This significantly reduces the amount of energy required by the device. The pulses can be modulated by random information. This increases the robustness of the anti-intrusion device.

[0032] Said control unit may be self-powered by an autonomous energy source internal to the device, in particular a battery. In a variant, the device is configured to erase any confidential information if the external power source is removed.

[0033] The control unit is advantageously configured to compare the signal resulting from the emission of the ultrasonic waves to a reference signal by implementing signal processing techniques, in particular cross-correlation, time correlation techniques, robust statistics or artificial intelligence. This makes it possible to detect differences in the signal, which mean that there has been a breach of integrity of the control medium, i.e. the housing which surrounds the embedded system in the first embodiment, or the air or gas which surrounds the electronic cards in the second embodiment. This means that an attacker has opened the housing, or inserted a probe through a small orifice, or has considerably deformed the housing to access the electronics.

[0034] The control unit may comprise a field programmable gate array (FPGA), a complex programmable logic controller (CPLD), a semiconductor, in particular an application-specific integrated circuit (ASIC), a microcontroller, or a DSP or signal processing microcontroller.

[0035] The control unit may be configured to transmit to at least one external system connected to the device the detection information of the possible breach of the integrity of the embedded system. These external systems may trigger actions, such as in particular sending a notification, recording an error code, deleting security keys or confidential information.

[0036] The control unit may be configured to receive reference signals resulting from the emission of ultrasonic waves by said emission element in order to carry out the calibration of the device, said reference signals being in particular stored in a non-volatile memory of the device. The device advantageously requires calibration at its start-up, as well as regular recalibration, for example if the material behaves very differently when the temperatures go towards extremes.

[0037] Calibration can be done in a controlled environment, particularly in a factory, or at predefined intervals during the device's life cycle, including every 24 hours.

[0038] When an integrity breach is detected, various actions can be performed. If the system is powered from outside, confidential information can be erased as soon as the power supply is lost, or an integrity breach is detected by the anti-intrusion device.

[0039] If the system is powered autonomously, in particular by battery or cell, the breach of integrity can trigger various actions: switching to a specific mode of the system, in particular locking, erasure of confidential information, replacement of confidential information by a honeypot, self-protection of the system inputs / outputs, in particular the deactivation of all the interfaces of the electronic chips. The system can also record information to later report an incident, in particular an attempt to dismantle the embedded system to a security operations center, called "Security Operations Center" in English.

[0040] The control unit of the device that performs the signal processing can be the "root of trust" for integrity in the complete system, for example by having the control unit itself store confidential information rather than storing it in the other processors in the system. If the control unit includes a so-called "secure element", in particular a microcontroller with additional security guarantees, such as CC EAL7 certification, the robustness of the device is thus improved. Detection method

[0041] According to another of its aspects, the invention relates to a method for detecting the breakdown of the integrity of an on-board system, in particular an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the method using an anti-intrusion device according to any one of the preceding claims and comprising at least the following steps: - receive a signal resulting from the emission of ultrasonic waves by the emitting element of the device, and - compare said signal to a reference signal in order to detect a possible breakdown in the integrity of the on-board system.

[0042] The characteristics stated in relation to the device apply to the method and vice versa. Motor vehicle

[0043] According to another of its aspects, the invention relates to a motor vehicle comprising a powertrain and at least one electronic control unit comprising an anti-intrusion device according to the invention.

[0044] The characteristics stated in relation to the device apply to the vehicle and vice versa. Brief description of the drawings

[0045] The invention may be better understood by reading the detailed description which follows, a non-limiting example of its implementation, and by examining the attached drawing, in which

[0046] [Fig-1] [Fig.l], already described, represents an embedded system according to the prior art,

[0047] [Fig.2] [Fig.2], already described, represents an embedded system according to the prior art who is under attack,

[0048] [Fig.3] [Fig.3] represents a first embodiment of the device according to the invention,

[0049] [Fig.4] [Fig.4] represents the device of [Fig.3] in the event of an attack,

[0050] [Fig.5] [Fig.5] represents a second embodiment of the device according to the invention, and

[0051] [Fig.6] [Fig.6] represents the device of [Fig.5] in the event of an attack. Detailed description

[0052] [Fig. 3] shows an anti-intrusion device according to a first embodiment of the invention, integrated in an electronic control unit, itself integrated in a motorized vehicle. The device 1 comprises an ultrasonic wave emission element 2, a transducer in the example considered, in particular a piezoelectric transducer, in particular of the PZT ceramic type. The device 1 comprises or is connected to a control unit 3 configured to receive a resulting signal “SRE” from the emission of the ultrasonic waves by the transducer and to compare it to a reference signal “SRF” in order to detect a possible breach of the integrity of the on-board system.

[0053] In the example considered, the transducer 2 comprises or is connected to a control unit configured to send a wave train, in particular Gaussian pulses. The control unit is configured to compare the signal resulting from the emission of the ultrasonic waves to a reference signal by implementing signal processing techniques, in particular cross-correlation, time correlation techniques, robust statistics or artificial intelligence.

[0054] In this first embodiment, as visible in [Fig. 3], the transducer 2 is configured to emit ultrasonic waves in at least part of the material which constitutes the housing 4 of the device 1.

[0055] The device 1 according to the invention is configured so that the reception frequency of the ultrasonic waves is determined as a function of at least said material and / or a preset temperature range.

[0056] In the illustrated example, the transducer 2 is further configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit 3. In a variant not shown, the device 1 may further comprise a reception element configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit, said reception element being for example a transducer.

[0057] As visible in [Fig.4], as soon as an intrusion “INT” is carried out, for example by drilling the housing 4, removing a cover, inserting a probe, the geometry of the ultrasonic waves is modified, and a rupture “RUPT” of the mechanical integrity is therefore detected by processing the signal “SREm” which returns to the transducer 2.

[0058] The control unit 3 is advantageously configured to transmit to at least one external system connected to the device 1 the information detecting the possible breakdown of the integrity of the on-board system.

[0059] In the second embodiment illustrated in [Fig.5], the transducer 2 is configured to emit ultrasonic waves “WAVES” inside the space 5 defined by the housing 4 of the on-board system, the waves being emitted into the air or gas present in said space 5.

[0060] In this example, the device is configured so that the ultrasonic waves propagate at a frequency between 30 kHz and 50 kHz, being in particular equal to 40 kHz. The transducer 2 is further configured to receive the ultrasonic waves after their propagation inside the space 5 defined by the housing 4 of the on-board system and to emit said resulting signal received by the control unit 3.

[0061] The ultrasonic waves are reflected on the walls of the housing 4, the printed circuits, the connectors, the fasteners, interact with each other in the form of constructive or destructive interference, then return to their starting point at the level of the transducer 2. The signal received at the transducer 2 thus depends on the geometry of the elements inside the housing 4, and on the geometry of the housing itself. In the case of an attack, as shown in [Fig. 6], as soon as an intrusion “INT” is carried out, for example by drilling the housing 4, removing a cover, inserting a probe, this geometry is modified, and a break in the mechanical integrity is therefore detected by processing the signal which returns to the transducer 2.

[0062] The invention is not limited to the examples which have just been described.

[0063] In particular, other ultrasonic wave emitting elements may be used.

[0064] The invention can be implemented in embedded systems not integrated into a motor vehicle, in so-called “offboard” solutions.

[0065] The invention can be used in the aeronautical or railway industry, for very different applications, in particular for non-destructive testing. ("Non-Destructive Testing") of structures, such as aircraft wings or railway tracks, in order to detect defects in materials, which can cause damage or accidents.

Claims

Claims

1. Anti-intrusion device (1) intended to be integrated into an on-board system, in particular into an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the device comprising an ultrasonic wave emission element (2), the device being characterized in that it comprises or is connected to a control unit (3) configured to receive a signal resulting from the emission of ultrasonic waves by said element (2) and to compare it with a reference signal in order to detect a possible breach of the integrity of the on-board system.

2. Device according to claim 1, in which the ultrasonic wave emitting element (2) is a transducer configured to emit ultrasonic waves, being in particular a piezoelectric transducer, in particular of the PZT ceramic type.

3. Device according to claim 2, wherein said transducer (2) is configured to emit ultrasonic waves into at least a portion of the material which constitutes the housing (4) of the device (1).

4. Device according to the preceding claim, configured so that the reception frequency of the ultrasonic waves is determined as a function of at least said material and / or a predefined temperature range.

5. Device according to any one of claims 3 or 4, wherein said transducer (2) is further configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit (3).

6. Device according to any one of claims 3 or 4, further comprising a receiving element configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit (3), said receiving element being in particular a transducer.

7. Device according to claim 2, wherein said transducer (2) is configured to emit ultrasonic waves inside the space (5) defined by the housing (4) of the on-board system, the waves being emitted in particular into the air or gas present in said space (4).

8. Device according to the preceding claim, configured so that the ultrasonic waves propagate at a frequency between 30 kHz and 50 kHz, being in particular equal to 40 kHz.

9. Device according to any one of claims 7 or 8, wherein said transducer (2) is further configured to receive the ultrasonic waves after their propagation inside the space (5) defined by the housing (4) of the on-board system and to emit said resulting signal received by the control unit (3).

10. Device according to any one of the preceding claims, wherein the ultrasonic wave emitting element (2) comprises or is connected to a control unit configured to send a wave train, in particular Gaussian pulses, in particular pulses of a predefined duration, in particular at predefined or randomly defined intervals.

11. Device according to the preceding claim, in which said control unit is self-powered by an autonomous energy source internal to the device (1), in particular a battery.

12. Device according to any one of the preceding claims, wherein the control unit (3) is configured to compare the signal resulting from the emission of the ultrasonic waves to a reference signal by implementing signal processing techniques, in particular cross-correlation, temporal correlation techniques, robust statistics or artificial intelligence.

13. Device according to any one of the preceding claims, in which the control unit (3) comprises a programmable pre-broadcast circuit, a programmable complex circuit, a semiconductor, in particular an integrated circuit specific to an application, a microcontroller, or a signal processing microcontroller.

14. Device according to any one of the preceding claims, in which the control unit (3) is configured to transmit to at least one external system connected to the device (1), the information detecting the possible breakdown of the integrity of the on-board system.

15. Device according to any one of the preceding claims, wherein the control unit (3) is configured to receive reference signals resulting from the emission of ultrasonic waves by said emission element (2) in order to carry out the calibration of the device (1), said reference signals being in particular stored in a non-volatile memory of the device (1).

16. Method for detecting the breakdown of the integrity of an on-board system, in particular an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the method using

17. an anti-intrusion device (1) according to any one of the preceding claims and being characterized in that it comprises at least the following steps: - receiving a signal resulting from the emission of ultrasonic waves by the emission element (2) of the device (1), and - compare said signal to a reference signal in order to detect a possible breakdown in the integrity of the on-board system. Motor vehicle comprising a powertrain and at least one electronic control unit comprising an anti-intrusion device (1) according to any one of claims 1 to 15.

Citation Information

Patent Citations

  • Methodology and application of acoustic detection of optical integrity

    EP4102220A1

  • System and method for seal tamper detection for intelligent electronic devices

    US20050039040A1

  • Detection of a physical intrusion into a protective receptacle

    WO2015090714A1