Method for securing the authentication of a device using a microcontroller

FR3166720B1Active Publication Date: 2026-08-07VITESCO TECHNOLOGIES GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-09-24
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

Existing authentication methods for microcontrollers in vehicles are vulnerable to interception and manipulation due to the inability to generate truly random recognition signals, allowing unauthorized access and potential security breaches.

Method used

A method utilizing free pins on the microcontroller as passive antennas to generate highly noisy and variable recognition signals, which are encrypted and decrypted using corresponding keys, ensuring the random nature of the signal and enhancing security against hacking attempts.

Benefits of technology

The solution provides a robust and secure authentication process by generating recognition signals from inaccessible noise signals, making it difficult for attackers to replicate, thus protecting microcontrollers from unauthorized access and ensuring secure communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000013_0000
    Figure 00000013_0000
  • Figure 00000013_0001
    Figure 00000013_0001
  • Figure 00000014_0000
    Figure 00000014_0000
Patent Text Reader

Abstract

The invention relates to a method for securing the authentication of a device (2) by a microcontroller (11) comprising an electronic chip (111), including at least one pin (1111-A) said to be free, not connected to the pins (112) of the microcontroller (11) and generating a noise signal not accessible outside the microcontroller (11), said method comprising the steps of detection (E2), of a device (2), reception (E3), by a processing module (1112), of a noise signal via the free pin (111-A), generation of a recognition signal from the received noise signal, encryption (E4) of the recognition signal, sending (E5) of the encrypted recognition signal to the device (2), decryption (E6) of the recognition signal, sending (E7) of the decrypted recognition signal to the microcontroller (11),Comparison (E8) of the generated recognition signal and the decrypted recognition signal, and authentication (E9) of the device (2) when the decrypted recognition signal matches the generated recognition signal. Figure for the abbreviation: Fig 3,
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for securing the authentication of a device using a microcontroller. Technical field

[0001] The present invention relates to the field of authentication and more particularly concerns a method for securing authentication. Previous technique

[0002] With the electrification of vehicles and the increasing number of electronically controlled functions, more and more on-board vehicle equipment is controlled by electronic control units. These electronic control units include, in particular, an information processing unit, more commonly known as a "microcontroller," connected to an electronic circuit. The electronic control unit is often protected by a housing.

[0003] Microcontrollers are produced by specialized industries and must therefore be pre-programmed to perform the functions required by the manufacturer. These functions sometimes also need to be initialized after the microcontroller is installed in the vehicle. It may also be necessary to modify the microcontroller's programming during its lifecycle.

[0004] Therefore, it is necessary to be able to communicate with the microcontroller via a suitable device after its manufacture. However, this communication capability can be exploited for malicious purposes to access, retrieve, or modify parts of the program embedded in the microcontroller of the electronic chip, or to modify the chip itself, which represents a risk to the safety and integrity of the vehicle. Microcontroller maintenance services are also likely to be targeted by such attacks.

[0005] It is therefore necessary to secure the exchanges between the microcontrollers and the devices used for their maintenance.

[0006] This security is achieved through an authentication request based on cryptographic principles. The principle is that the microcontroller possesses a public key that enables encryption, and the device possesses a private key that enables decryption. The microcontroller generates a recognition signal, which is encrypted with the key and sent to the device. The device decrypts it with the key and sends this decrypted recognition signal back to the microcontroller. The microcontroller can then compare the recognition signal it generated with the decrypted recognition signal, and if the two match, the device is authenticated and has access to the microcontroller.

[0007] However, it is necessary that the recognition signal be generated randomly at each authentication, because otherwise the interception of the decrypted response could allow a third party to successfully gain fraudulent access to the microcontroller by subsequently intercepting the decrypted recognition signal emitted by a legitimate device.

[0008] Generating a random signal is therefore essential. The problem encountered is that the signal is ideally random, but cannot be totally random and must be based on a pre-existing signal which is used to generate a sufficiently large number.

[0009] If a third party manages to intercept the pre-existing signal or to learn part of the processing used to generate the number, it can, with significant computing power, send a large number of messages to the microcontroller in a short time until it succeeds in sending the expected signal for authentication. It can also exploit a weakness in the microcontroller to gain authentication.

[0010] One solution could be to generate the random number from a physical signal retrieved by the microcontroller, such as a temperature or an electric field. However, if the third party also has access to these physical signals, it can conduct the attack in the same way.

[0011] There is therefore a need for a simple and effective solution to remedy at least some of these drawbacks. Description of the invention

[0012] To this end, the invention first relates to a method for securing the authentication of a device by a microcontroller, said microcontroller comprising:

[0013] -a casing,

[0014] - a plurality of legs, extending from the inside to the outside of the housing,

[0015] - and an electronic chip, placed inside said housing, said electronic chip including:

[0016] - a plurality of pins, some of the pins being electrically connected to the microcontroller pins, and at least one pin, called a free pin, with one pin and behaving like a passive antenna inside the package, generating a noise signal inaccessible outside the package,

[0017] - a processing module, being configured to generate a recognition signal at starting from a noise signal generated by said at least one free pin,

[0018] - an encryption module connected to the processing module, and configured to encrypt the recognition signal using an encryption key stored in a memory area of ​​the electronic chip,

[0019] - a communication module, connected to the encryption module, being configured to communicate with the device,

[0020] said device being configured to communicate with the communication module of the electronic chip and decrypt a signal received by the communication module using a decryption key corresponding to the encryption key of the encryption module of the electronic chip, said method comprising the steps of:

[0021] - detection, by the microcontroller, of the presence of the device,

[0022] - reception, by the processing module, of a noise signal inaccessible outside the housing via at least one free pin,

[0023] - generation, by the processing module, of a recognition signal from a processing of the received noise signal,

[0024] - encryption, by the encryption module, of the recognition signal using the encryption key,

[0025] - sending, by the electronic chip's communication module, of the signal encrypted recognition of the device

[0026] - reception, by the device, of the recognition signal,

[0027] - decryption, by the device using the decryption key, of the signal acknowledgement,

[0028] - sending, via the device, of the decrypted recognition signal to the microcontroller,

[0029] - comparison, by the electronic chip, of the generated recognition signal and the recognition signal deciphered,

[0030] - authentication, by the microcontroller, of the device when the signal of The decrypted recognition corresponds to the generated recognition signal.

[0031] By free pin is understood a pin of the electronic chip which is not electrically connected to one of the pins of the microcontroller.

[0032] By encryption key is understood a sequence of mathematical operations which make it possible to modify the recognition signal, in particular when it is in the form of a sequence of numbers, in order to encrypt and protect it.

[0033] The method according to the invention ensures the random nature of the recognition signal by generating it from the noisy signals emitted by at least one free pin. This at least one free pin, acting as a passive antenna, generates a highly noisy signal that is strongly dependent on disturbances in the physical parameters inside the microcontroller package. These disturbances are highly variable and inaccessible from the outside, as they depend on the physical parameters inside the sealed package. The high variability of these disturbances and their inaccessibility make them robust sources for generating a recognition signal that is as random as possible to protect the microcontroller.

[0034] The random nature of the recognition signal provided by the method according to the invention can also be used in other security applications, such as intrusion detection, detection of changes to the execution context of a program in the microcontroller, or personalization of a security key. Furthermore, random numbers are known to be the basis for generating symmetric secret keys, asymmetric private keys, initialization vectors (in the context of CBC encryption, for example), nonces (numbers used once), or one-time data. They also contribute to the creation of non-deterministic signatures and to the uniqueness of secure messages exchanged by computers, and the generation of the random signal according to the invention also makes it possible to generate signals for these applications in a more secure manner.

[0035] Preferably, the electronic chip comprises a plurality of free pins, and the noise signal reception step includes receiving the noise signals emitted by the plurality of free pins. The free pins, for example two in number, can generate signals that are very different from each other, thereby increasing the randomness and difficulty in reproducing the generated recognition signal and thus increasing the robustness of the solution.

[0036] In one operating mode of the process, the noise signal is measured continuously via at least one free pin. This operating mode allows for a speed increase since the processing module continuously measures the signals, while offering a solution with very high availability, including continuous operation.

[0037] In an alternative operating mode of the process, the noise signal measurement via at least one free pin is performed only after the device has been detected. This operating mode is more secure since the recognition signal generated by the processing module depends solely on when the process is executed and is also robust to an attack on the timing of the signal generation.

[0038] Advantageously, the recognition signal generation step is performed on a plurality of received signal processing steps, preferably sixteen. The recognition signal is thus sufficiently long with parts derived from different signals, which greatly increases the security of the recognition signal in accordance with NIST standards.

[0039] According to another aspect, the invention relates to a computer program product characterized in that it comprises a set of program code instructions which, when executed by one or more processors, configure the processor(s) to implement the process as described above.

[0040] According to another aspect, the invention also relates to a microcontroller comprising:

[0041] -a casing,

[0042] - a plurality of legs, extending from the inside to the outside of the housing,

[0043] - and an electronic chip, placed inside said housing, said electronic chip including:

[0044] - a plurality of pins, some of the pins being electrically connected to microcontroller pins, at least one pin, called "free", being unconnected to the microcontroller pins and behaving like a passive antenna inside the package, generating a noise signal inaccessible outside the package,

[0045] - a processing module, being configured to generate a recognition signal at starting from a noise signal generated by said at least one free pin,

[0046] - an encryption module connected to the processing module, and configured to encrypt the recognition signal using an encryption key stored in a memory area of ​​the electronic chip,

[0047] - a communication module, connected to the encryption module, being configured to communicate with the device,

[0048] said microcontroller being configured to implement the process as previously described.

[0049] According to another aspect, the invention also relates to an electronic control unit comprising a microcontroller as shown. Such an electronic control unit is thus better protected against hacking attempts by the method according to the invention implemented by the microcontroller.

[0050] The invention also relates to a vehicle, in particular a motor vehicle, comprising at least one electronic control unit as shown. Brief description of the drawings

[0051] Other features and advantages of the invention will become apparent from the following description. This description is purely illustrative and should be read in conjunction with the accompanying drawings, in which:

[0052] [Fig-1] Fig. 1 schematically illustrates a vehicle comprising a microcontroller enabling the implementation of the authentication process of a device according to the invention.

[0053] [Fig.2] Fig.2 schematically illustrates a microcontroller configured to implement the method according to the invention.

[0054] [Fig.3] Fig.3 schematically illustrates one embodiment of the process according to the invention. Description of the implementation methods

[0055] As shown in [Fig.1], the method according to the invention takes place when a user seeks to authenticate a device 2 in order to gain access to the programming of a microcontroller 11 of an electronic control unit 10 of a vehicle 1.

[0056] Vehicle 1

[0057] Vehicle 1 includes the electronic control unit 10, which allows control of one of the functions of vehicle 1.

[0058] In the example shown in [Fig. 1], vehicle 1 is a motor vehicle. This example is not limiting and vehicle 1 could be any type of vehicle, for example a motorized two-wheeler.

[0059] Electronic control unit 10

[0060] The electronic control unit 10 includes a microcontroller 11 and a transceiver 12.

[0061] The electronic control unit 10 also includes an electrical circuit not shown in the figures for clarity. The circuit connects the microcontroller 11 and the transceiver 12.

[0062] The electronic control unit 10 is configured to support the control of one of the functions of the vehicle 1, such as opening the doors, measuring the speed, etc.

[0063] The transceiver 12 is configured to communicate with the microcontroller 11 via the circuit and with the device 2 by a communication link, preferably a wireless communication link.

[0064] Microcontroller 11

[0065] As shown in [Fig.2], the microcontroller 11 comprises an electronic chip 111, a set of pins 112 and a housing 113.

[0066] The electronic chip 111 is located inside the housing 113, and the set of pins 112 are connected to the electronic chip 111 and extend from the inside to the outside of the housing 113.

[0067] The pin assembly 112 is connected to the electrical circuit of the electronic control unit 10, in particular to connect the microcontroller 11 to the transceiver 12.

[0068] The housing 113 is preferably sealed, for example by being cast onto the electronic chip 111 and the pin assembly 112. The inside of the housing 113 of the microcontroller 11 is thus not accessible.

[0069] Electronic chip 111

[0070] The electronic chip 111 comprises a set of pins 1111, a processing module 1112, an encryption module 1113, a communication module 1114.

[0071] The electronic chip 111 includes the programming of the microcontroller 11.

[0072] The electronic chip 111 is configured to allow or not allow the device 2 to have access to the programming of the microcontroller 11.

[0073] Each leg of the leg assembly 112 is connected to a pin 1111 of the pin assembly 1111, but some pins, called free pins 1111-A, are not connected to a leg of the leg assembly 112.

[0074] In [Fig.2], only one free pin 1111-A has been shown for clarity, but the electronic chip 111 may include several.

[0075] Each free pin 1111-A captures variations in physical parameters (temperature, electric field, magnetic field etc.) inside the housing 113. Each free pin 1111-A thus behaves like a passive antenna and the signals emitted by these passive antennas are very noisy.

[0076] The processing module 1112 is configured to receive the noisy signals emitted by the free pin 1111-A and process them to produce a recognition signal.

[0077] Preferably, the recognition signal is a sequence of numbers.

[0078] Preferably, the recognition signal is a sequence of numbers generated by several successive processing of the signals received by the processing module 1112, preferably sixteen successive processing.

[0079] The processing module 1112 can generate the recognition signal continuously or generate it only after receiving a specific signal.

[0080] The processing module 1112 is configured to record the recognition signal in a memory area of ​​the electronic chip 111.

[0081] In a manner known per se, the processing module may include an ADC (Analog-to-Digital Converter) circuit to transform the received noise signal into a digital signal, a filtering module to filter out part of the noisy signal, and a random number generation module that generates the sequence of numbers from the filtered digital signal.

[0082] The encryption module 1113 contains an encryption key and is configured to encrypt a recognition signal using said encryption key.

[0083] The communication module 1114 is configured to communicate with the transceiver 12 via the pins 112 of the microcontroller 11 and the circuit of the electronic control unit 10. More specifically, the communication module 1114 is configured to retrieve the recognition signal encrypted by the encryption module 1113 and send said encrypted recognition signal to the device 2 via the transceiver 12.

[0084] The communication module 1114 is configured to record an acknowledgment signal in a memory area of ​​the electronic chip 111.

[0085] The electronic chip 111 is configured to compare the recognition signal recorded by the processing module 1112 and that recorded by the communication module 1114.

[0086] Device 2

[0087] Device 2 is a user-operated device. It is configured to communicate with the communication module 1114 of the electronic control unit 10 via the transceiver 12.

[0088] Device 2 contains a decryption key corresponding to the encryption key of the encryption module 1113 and is configured to decrypt an encrypted recognition signal using this decryption key.

[0089] Device 2 is configured to send the decrypted recognition signal to the microcontroller 11 via the transceiver 12.

[0090] Example of implementation

[0091] Each free pin 1111-A in the microcontroller 11 behaves like a passive antenna, that is, it constantly picks up fluctuations in physical parameters inside the package 113. This passive antenna behavior causes each free pin 1111-A to emit highly noisy signals.

[0092] Due to the highly noisy nature of these fluctuations, two free pins 1111-A emit different signals from each other.

[0093] When a user wishes to access the programming of the microcontroller 11 of the vehicle 1 via a device 2, the method according to the invention is implemented.

[0094] In a first step El, the device 2 sends a detection signal to the microcontroller 11 via the transceiver 12 of the electronic control unit 10.

[0095] In this step, the device 2 generates for example a radio frequency signal which is received by the transceiver 12, which then sends this signal to the microcontroller 11 via the circuit of the electronic control unit 10.

[0096] In another embodiment, the device 2 is connected to the electronic control unit 10 and the generated signal is sent to the transceiver 12 by the circuit.

[0097] In a second step E2, the microcontroller 11 receives the detection signal and the electronic chip 111 triggers the generation of the recognition signal.

[0098] In a third step E3, the processing module 1112 receives a noisy signal from at least one free pin 1111-A and processes this noisy signal to generate a recognition signal in the form of a sequence of numbers.

[0099] In another mode of operation, the processing module 1112 continuously receives the noisy signals from the free pins 1111-A but only generates the recognition signal after receiving the detection signal.

[0100] In this step, the recognition signal is generated from several sequences of numbers, each generated by different noisy signals and coming from different free pins 1111 - A.

[0101] Thus, the recognition signal, being generated from noisy signals different from each other, can be considered random and is more secure compared to attempts to reproduce the recognition signal for hacking purposes.

[0102] In step E4, the recognition signal is encrypted by the encryption module 1113 using the encryption key. This step protects the recognition signal because if a third party does not possess the encryption key, they cannot access the recognition signal.

[0103] However, if the third party manages to recover the recognition signal by other methods, it can use it to access the microcontroller 11. The random nature of the recognition signal, reinforced by the passive antenna operation of the free pins 1111-A, is then essential to counter this kind of attempt.

[0104] In a step E5, the encrypted recognition signal is sent by the communication module 1114 to the device 2 via the transceiver 12. The encryption of the recognition signal makes it possible to protect it if a third party intercepts this communication.

[0105] After receiving the encrypted recognition signal, device 2 decrypts it with the decryption key in memory in a step E6. This decryption key corresponding to the encryption key stored in the encryption module 1113, the device can regenerate the generated recognition signal.

[0106] In a step E7, device 2 sends the decrypted recognition signal to the microcontroller 11, via the transceiver 12.

[0107] In a step E8, the electronic chip 111 compares the recognition signal generated in step E3 and the decrypted recognition signal sent by the device 2.

[0108] If the two recognition signals match, device 2 is authenticated in a step E9 and the user can access the programming of the microcontroller 11 via device 2.

[0109] If the two recognition signals do not match, device 2 is not authenticated in an E9* step and the user does not have access to the programming of the microcontroller 11 via device 2, thus protecting the microcontroller 11 from hacking attempts.

[0110] The process according to the invention thus makes it possible to generate a signal whose random character is ensured by a noise not accessible from the outside and which does not require modification compared to the components currently used.

Claims

1. Demands Method for securing the authentication of a device (2) by a microcontroller (11), said microcontroller (11) comprising: - a housing (113), - a plurality of legs (112), extending from the inside to the outside of the housing (113), - and an electronic chip (111), placed inside said housing (113), said electronic chip (111) comprising: - a plurality of pins (1111), some of the pins (1111) being electrically connected to the pins (112) of the microcontroller (11), at least one pin (1111-A), called "free", being not connected to a pin (112) and behaving as a passive antenna inside the package (113), generating a noise signal not accessible outside the package (113), - a processing module (1112), being configured to generate a recognition signal from a noise signal generated by said at least one free pin (1111-A), - an encryption module (1113) connected to the processing module (1112), and configured to encrypt the recognition signal using an encryption key stored in a memory area of ​​the electronic chip (111), - a communication module (1114), connected to the encryption module (1113), being configured to communicate with the device (2), said device (2) being configured for: - communicate with the communication module (1114) of the electronic chip (111), - decrypt a signal received by the communication module (1114) using a decryption key corresponding to the encryption key of the encryption module (1113) of the electronic chip (111), said process includes the steps of: - detection (E2), by the microcontroller (11), of the presence of the device (2), - reception (E3), by the processing module (1112), of a noise signal not accessible outside the housing (113) via the au minus one free pin (1111-A), and generation, of a recognition signal from a processing of the received noise signal, - encryption (E4), by the encryption module (1113), of the recognition signal using the encryption key, - sending (E5), by the communication module (1114), of the encrypted recognition signal to the device (2), - reception (E6), by the device (2), of the recognition signal and decryption, using the decryption key, of the recognition signal, - sending (E7), by the device (2), of the decrypted recognition signal to the microcontroller (11), - comparison (E8), by the electronic chip (111), of the generated recognition signal and the decrypted recognition signal, - authentication (E9), by the microcontroller (11), of the device (2) when the decrypted recognition signal corresponds to the generated recognition signal.

2. Method according to claim 1, wherein the electronic chip (111) comprises a plurality of free pins (1111-A) and the noise signal reception step (E3) is carried out by receiving the noise signal emitted by the plurality of free pins (1111-A).

3. A method according to any one of the preceding claims, wherein the step of receiving the noise signal (E3) via at least one free pin (1111-A) to one pin is carried out continuously.

4. A method according to any one of claims 1 and 2, wherein the noise signal reception step (E3) via at least one free pin (1111-A) is carried out only following detection of the device (2).

5. A method according to any one of the preceding claims, wherein the noise signal recognition signal generation step is carried out on a plurality of received signal processing, preferably sixteen.

6. A computer program product characterized in that it comprises a set of program code instructions which, when executed by one or more processors, configure the processors to implement a method according to any one of the preceding claims.

7. Microcontroller (11) comprising: - a housing (113), - a plurality of pins (112) extending from the inside to the outside of the housing (113), - and an electronic chip (111) located inside said housing (113), said electronic chip (111) comprising: - a plurality of pins (1111), a portion of the pins (1111) being electrically connected to the pins (112) of the microcontroller (11), and at least one pin (1111-A), referred to as "free", not connected to the pins (112) of the microcontroller (11) and behaving as a passive antenna inside the housing (113), generating a noise signal inaccessible outside the housing (113), - a processing module (1112) being configured to generate a recognition signal from a noise signal generated by said at least one free pin (1111-A), - an encryption module (1113), connected to the processing module (1112),and being configured to encrypt the recognition signal from an encryption key stored in a memory area of ​​the electronic chip (111), - a communication module (1114), connected to the encryption module (1113), being configured to communicate with the device (2), said microcontroller (11) being configured to implement the method according to any one of claims 1 to 5.

8. Electronic control unit (10) comprising a microcontroller (11) according to the preceding claim.

9. Vehicle (1), in particular motor vehicle, comprising at least one electronic control unit (10) according to the preceding claim.