Securing a motor vehicle when providing remotely controllable functions
The method and device enhance vehicle security by detecting malicious acts during remotely controllable functions and immobilizing the vehicle, addressing the vulnerability of existing systems.
Patent Information
- Application Number
- FR2024001110
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-05
- Publication Date
- 2025-08-08
AI Technical Summary
Existing anti-theft systems for motor vehicles fail to secure the vehicle against theft when providing remotely controllable functionalities.
A method and device that utilize a first and second computer to determine if the vehicle is partially or fully unlocked and detect malicious acts, such as pressing the accelerator pedal, and activate an immobilization system to prevent any commands or functionalities, ensuring the vehicle remains secured.
Effectively secures the vehicle against theft by immobilizing it when malicious acts are detected during remotely controllable functionalities, enhancing anti-theft security.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Securing a motor vehicle when providing remotely controllable functions Technical field of the invention
[0001] The present invention relates to the field of anti-theft systems for motor vehicles. The invention relates in particular to a method for securing a motor vehicle comprising a first computer and a second computer. The invention also relates to a device implementing such a method, as well as a motor vehicle incorporating such a device. The invention applies to motor vehicles such as land motor vehicles, in particular cars. State of the prior art
[0002] All current motor vehicles are equipped with an immobilization system, also called an "anti-start system" or "immobilizer", which includes means for preventing the vehicle from starting when an identification device (e.g. ignition keys, hands-free devices, etc.) is not present in the passenger compartment of the vehicle.
[0003] It is also known from patent FR3089917 that certain vehicles can operate according to several partially unlocked operating modes in order to allow the provision of remotely controllable functionalities, for example a thermal pre-conditioning functionality of the passenger compartment (i.e. preheating of the passenger compartment of the vehicle when stationary with a view to its subsequent use) or remote diagnostics.
[0004] Also known from patent FR3089915 is a motor vehicle which implements a control method in which a periodic data exchange between a first computer and a second computer of the motor vehicle is implemented to allow a smooth transition from a partial unlocking mode to a total unlocking mode.
[0005] However, no known device or method can effectively secure a vehicle against a malicious act while a remotely controllable functionality is provided. Summary of the invention
[0006] The invention aims to overcome this shortcoming. In particular, it aims to provide a solution for securing a motor vehicle against theft in a situation where the vehicle provides a remotely controllable functionality. In this way, the invention aims to minimize vehicle thefts.
[0007] In order to achieve these aims, the invention relates, according to a first aspect, to a method for securing a motor vehicle comprising a first computer and a second computer, the method being implemented by a computer device on board the vehicle and comprising the steps of: i. determine whether the vehicle is partially or fully unlocked while providing remotely controllable functionality; and, where this is determined to be the case, ii. determine whether an event characteristic of a malicious act occurs; and, where it is established that this is the case, iii. cause the vehicle to operate in such a way that it no longer executes any commands or provides any functionality.
[0008] According to a variant, step ii) may comprise a step consisting of determining whether data characterizing a particular value of a parameter relating to a press on an accelerator pedal are generated in response to a signal transmitted by a sensor configured to detect a press on the accelerator pedal.
[0009] According to another variant, step iii) may consist of causing the activation of an immobilization system of the first computer.
[0010] According to yet another variant, step iii) may consist of causing the second computer to stop transmitting data characterizing an encrypted response in response to the first computer transmitting data characterizing a seed.
[0011] According to yet another variant, said remotely controllable functionality may be a functionality for thermal pre-conditioning of the passenger compartment of the vehicle or a functionality for remote diagnosis of the vehicle.
[0012] According to a second aspect, the invention relates to a device for securing a motor vehicle comprising a first computer and a second computer, the device comprising at least one information processing unit, comprising at least one processor, and a data storage medium, which are configured to implement a method as described above.
[0013] According to a third aspect, the invention relates to a computer program comprising program code instructions for executing the steps of a method as described above when said program is executed by at least one processor.
[0014] According to a fourth aspect, the invention relates to a medium usable in a computer on which a program as described above is recorded.
[0015] According to a fifth aspect, the invention relates to a motor vehicle comprising a device as described above. Brief description of the figures
[0016] Other characteristics and advantages of the invention will appear on examining the detailed description below, and the appended figures, in which:
[0017] [Fig-1] is a diagram of a motor vehicle according to the invention;
[0018] [Fig.2] is a functional diagram of a device according to the invention; and
[0019] [Fig.3] is a flowchart of the steps of a method according to the invention. Detailed description of the invention
[0020] In [Fig.l] a motor vehicle 1 according to the invention is schematically illustrated. This is conventionally equipped with a first computer 2 and a second computer 3 connected to each other by means of a wired communication network of the vehicle (eg CAN, Ethernet, MOST), which is illustrated by the bidirectional arrows.
[0021] Preferably, the first computer 2 is a master computer for the drive and / or mobility of the vehicle, such as a computer for controlling a thermal engine or an engine control computer, while the second computer 3 is an intelligent control unit or any other supervision module for an equivalent motor vehicle. Thus, it is preferably the first computer 2 which includes an immobilization system 4, i.e. a system capable of ensuring the blocking of the functionalities of the vehicle 1, in particular its starting and / or its mobility. The vehicle 1 according to the invention also comprises a sensor 5 which is configured to detect when the accelerator pedal of the vehicle 1 is pressed.
[0022] Advantageously, the vehicle 1 according to the invention also incorporates a device 100 for securing a motor vehicle comprising a first computer and a second computer, as described below, which implements a method for securing a motor vehicle comprising a first computer and a second computer, as briefly summarized below and described in detail further below.
[0023] When implementing the method, the device 100 according to the invention determines, when the vehicle 1 provides a remotely controllable functionality, for example a thermal pre-conditioning functionality of the passenger compartment, whether an event characteristic of a malicious act occurs. Such an event may for example be pressing the accelerator pedal of the vehicle when this is not expected or a broken window. And when it establishes that such an event occurs, the device 100 according to the invention then acts so as to cause the operation of the vehicle so that it no longer executes any command and no longer provides any functionality. To do this, it interacts directly with the immobilization system 4 of the first computer 2 or with the second computer 3. As will be seen below, it is and the device 100 according to the invention advantageously secures the vehicle 1 against malicious acts likely to occur when a remotely controllable functionality of the vehicle 1 is provided.
[0024] The device 100 according to the invention is illustrated in more detail in [Fig. 2]. It is essentially a computer device, which comprises at least one information processing unit 101, with one or more processors, a data storage medium 102, on which is recorded in particular a program which comprises program code instructions for the execution of the steps of the method according to the invention described below, and an input and output interface 103 allowing the reception and transmission of data.
[0025] The device 100 according to the invention is preferably integrated into an independent computer and it interacts via its input and output interface 103 and by means of a wired communication network of the vehicle (e.g. CAN, Ethernet, MOST) with the first computer 2, the second computer 3 and the sensor 5. Alternatively, the device 100 according to the invention is an integral part of the first computer 3 or the second computer 4. Thus, it can, in particular, determine whether the vehicle is partially or totally unlocked while it provides a remotely controllable functionality.It is also capable of determining whether an event characteristic of a malicious act occurs, in particular by interacting with the second computer 3 and / or with the sensor 5, and it is capable of causing the vehicle to operate in such a way that it no longer executes any commands and no longer provides any functionality, in particular by interacting with the first computer 2 and / or the second computer 3.
[0026] According to the invention, all the elements described above combine to enable the implementation of a method for securing a motor vehicle comprising a first computer and a second computer, as described below in connection with Figures 1 and 3.
[0027] [Fig. 3] illustrates in the form of a flowchart the steps of the method according to the invention.
[0028] According to a first step 301 of the method according to the invention, the device 100 according to the invention determines whether the vehicle is partially or totally unlocked while it provides a remotely controllable functionality.
[0029] To do this, it interacts directly with the first computer 2, which itself determines a state of unlocking of the vehicle 1, partial or total, and this in accordance with the teachings described in the patent FR3089917 mentioned in the preamble. It further interacts with the first computer 2 or with the second computer 3 to determine whether, at the current time, a remotely controllable functionality is provided, for example a thermal preconditioning functionality of the passenger compartment of the vehicle 1. Thus, thanks to this first step 301 of the method, the device 100 according to the invention determines these situations in which the vehicle 1 is particularly vulnerable since it is at least partially unlocked, that is to say that some of these functionalities can be provided, while the owner of the vehicle 1 is not necessarily present. And if it establishes that one is indeed in such a situation, the device 100 according to the invention carries out the following step of the method according to the invention described below.
[0030] According to a second step 302 of the method according to the invention, the device 100 according to the invention determines whether an event characteristic of a malicious act occurs, for example pressing the accelerator pedal while a thermal pre-conditioning functionality of the passenger compartment of the vehicle is provided or a broken window.
[0031] For this, according to a first embodiment, the device 100 according to the invention determines whether data characterizing a particular value of a parameter relating to pressing an accelerator pedal are generated in response to a signal transmitted by the sensor 5. Indeed, according to this first embodiment, it is the first computer 2 which interacts with the sensor 5 and which generates data characterizing a particular value of a parameter relating to pressing the accelerator pedal of the vehicle when it establishes that the sensor 5 generates a signal. Thus, the device 100 according to the invention constantly monitors the activity of the second computer 2 to determine whether the latter generates particular data in connection with pressing an accelerator pedal of the vehicle.
[0032] According to a second embodiment, the device 100 according to the invention interacts with the second computer 3. Indeed, unlike the first computer 2 which is adapted to manage only the operation of the powertrain of the vehicle 1, the second computer 3, given its role of overall supervision of the vehicle, is able to establish more completely whether a malicious act occurs. It can in particular, like the first computer 2, interact with the sensor 5 to establish whether the accelerator pedal is pressed, for example when a thermal pre-conditioning functionality of the passenger compartment is provided. It can also interact with an alarm system of the vehicle 1 in order to establish whether a window of the vehicle has been broken.Thus, in the case where it is a thermal preconditioning functionality of the passenger compartment which is provided, the device 100 according to the invention interacts directly with the sensor 5 and, like the first computer 2, it establishes that a malicious act occurs when it determines that the sensor 5 generates a signal characteristic of a press on the accelerator pedal of the vehicle 1.
[0033] Thanks to this embodiment, the securing of the vehicle 1 according to the invention against theft is all the more complete. Indeed, taking into account the roles of the first cal calculator 2 and the second calculator 3 as explained above, it is entirely possible that certain malicious acts can only be detected by the second calculator 3 due to its role of overall supervision of the vehicle while that of the first calculator 2 concerns only the management of the powertrain.
[0034] Thus, at the end of this second step 302 of the method, the device 100 according to the invention has established in different ways whether a malicious act occurs. And when this is the case, it proceeds by carrying out the following step of the method according to the invention described below.
[0035] According to a third step 303 of the method according to the invention, the device 100 according to the invention causes the vehicle to operate so that it no longer executes any commands and no longer provides any functionality.
[0036] To do this, according to the first embodiment, it interacts with the first computer 2 to cause the activation of its immobilization system 4. Thus, when the first computer 2 operates according to the teachings of the patents mentioned in the preamble, it is in particular configured to operate according to a so-called “locked” operating mode in which it activates the immobilization system 4 so that no command is executed and no functionality is provided. Thus, according to the first embodiment, the device 100 according to the invention causes the first computer 2 to switch over so that it operates according to such a “locked” operating mode, and this thus causes the activation of the immobilization system 4.
[0037] Therefore, when a thermal preconditioning functionality of the vehicle 1 is provided, which makes the vehicle 1 vulnerable insofar as it is partially unlocked while its owner is potentially distant from it, the fact that a malicious third party presses the accelerator pedal at this moment when this is not expected given the functionality that is provided is advantageously detected by the device 100 according to the invention, which causes the immediate immobilization of the vehicle when such an event occurs. This is how the theft of the vehicle 1 according to the invention in the aforementioned context is prevented. Furthermore, this makes it possible to secure the vehicle even more effectively against theft.Indeed, while it is relatively easy for an attacker to corrupt data relating to pressing the accelerator pedal which is transmitted over a CAN-type network which is by definition unsecured, it is more complex to corrupt an analog signal transmitted by a sensor.
[0038] According to the second embodiment, which is based on the teachings of patent FR3089915 mentioned in the preamble, the device 100 according to the invention causes the transmission by the second computer 3 of data characterizing an encrypted response in response to the transmission by the first computer 2 of data characterizing a seed. Indeed, we know from this patent that the first computer 2 is configured to periodically communicate with the second computer 3, in particular in a manner which consists of the first computer 2 transmitting what is called a “seed”, a seed that the second computer 3 uses to determine an encrypted response that it transmits in return to the first computer 2. And when the latter does not receive the expected response, it then switches to “locked” operating mode, which triggers the activation of the immobilization system 4.
[0039] It is therefore at this level that the device 100 according to the invention acts according to the second embodiment by causing the second computer 3 to stop transmitting an encrypted response upon receiving a seed transmitted by the first computer 2. This is how it causes the first computer 2 to switch to “locked” mode, which triggers the activation of the immobilization system 4.
[0040] Therefore, by means of the method and device according to the invention described above, a solution is provided for securing a motor vehicle against theft in a situation where it provides a remotely controllable functionality. By these means, the invention improves the anti-theft security of vehicles.
Claims
Claims
1. Method for securing a motor vehicle (1) comprising a first computer (2) and a second computer (3), the method being implemented by a computer device (100) on board the vehicle, characterized in that the method comprises the steps of: i. determining whether the vehicle is partially or totally unlocked while it provides a remotely controllable functionality; and, when it is established that this is the case, ii. determining whether an event characteristic of a malicious act occurs; and, when it is established that this is the case, iii. causing the vehicle to operate so that it no longer executes any commands and no longer provides any functionality.
2. Method according to claim 1, characterized in that step ii) comprises a step consisting of determining whether data characterizing a particular value of a parameter relating to a press on an accelerator pedal are generated in response to a signal transmitted by a sensor (5) configured to detect a press on the accelerator pedal.
3. Method according to claim 2, characterized in that step iii) consists of causing the activation of an immobilization system (4) of the first computer (2).
4. Method according to claim 1, characterized in that step iii) consists of causing the transmission by the second computer (3) of data characterizing an encrypted response to be stopped in response to the transmission by the first computer (2) of data characterizing a seed.
5. Method according to one of the preceding claims, characterized in that said remotely controllable functionality is a functionality for thermal pre-conditioning of the passenger compartment of the vehicle (1) or a functionality for remote diagnosis of the vehicle (1).
6. Device (100) for securing a motor vehicle (1) comprising a first computer (2) and a second computer (3), characterized in that the device comprises at least one information processing unit (101), comprising at least one processor, and a data storage medium (102), which are configured to implementing a method according to any one of the preceding claims.
7. A computer program comprising program code instructions for executing the steps of a method according to any one of claims 1 to 5 when said program is executed by at least one processor.
8. Support usable in a computer, characterized in that a program according to claim 7 is recorded therein.
9. Motor vehicle (1), characterized in that it comprises a device (100) according to claim 6.
Citation Information
Patent Citations
METHOD FOR CONTROLLING A VEHICLE WITH MULTIPLE OPERATING MODES
FR3089915A1
METHOD FOR CONTROLLING THE OPERATING STATE OF A VEHICLE
FR3089917A1
Method and System for Remote Starting of Vehicle using Mobile Communication Station
KR1020160056714A
Auto security and auto safety system
US20190061687A1
Mitigation of a manipulation of software of a vehicle
US20230267205A1