A method for authenticating data between a control module and a lighting module for a powered vehicle.
Patent Information
- Application Number
- JP2026085171
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-02-22
- Filing Date
- 2026-05-20
- Publication Date
- 2026-09-01
Smart Images

Figure 2026139694000001_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a lighting module for a powered vehicle. In particular, the invention relates to such a module comprising a pixelated light source.
Summary of the Invention
[0002] A light emitting diode (LED) is a semiconductor electronic component capable of emitting light when a current at least equal to a threshold flows through it. In the automotive field, LED technology is increasingly being used in various light-emitting signal solutions. LED matrix arrays are particularly advantageous in the field of automotive lighting. Pixelated light sources or matrix array light sources can be used for leveling functions, that is, for adjusting the height of a light beam emitted according to the pitch angle of a vehicle and according to the profile of a road. Other applications include DBL ("digital bending light"), which corresponds to adjusting the direction of an emitted light beam to follow the road in the horizontal plane, ADB ("adaptive driving beam"), which corresponds to an anti-glare function that generates dark areas in the high beam emitted by a headlamp so as not to cause discomfort to other road users, and also includes a function for projecting a pattern onto the ground using a pixelated light beam.
[0003] Using light sources in various types of technologies for the aforementioned lighting applications is a known practice. For example, this might involve monolithic technology where numerous basic LED sources, corresponding to pixels, are etched onto a common semiconductor substrate. Integrated electrical connections allow these pixels to be activated independently of each other. Another known technology is that of micro-LEDs, which result in a matrix array of miniature LEDs (typically smaller than 150 μm). DMD modules (DMD stands for digital micro-mirror device) also exist, which involve projection techniques using intensity modulators in a uniform beam. Micromirrors, whose position is controlled by piezoelectric elements, are directed to selectively reflect incident light beams, and each micromirror corresponds to one basic source in a matrix array of thus generated pixels. Light from the source is guided by an optical system into the matrix array of micromirrors. Therefore, this light has a different distribution from module to module due to positional and manufacturing tolerances in the optical system and the light source. This results in the maximum intensity varying from module to module with respect to a given pixel. In this case, each pixel will have a different maximum intensity depending on the command sent to it. Such lighting devices are designed using mass production methods. There is inevitably some tolerance between the components of the lighting and / or signaling devices, which allows for easy assembly on the one hand, and on the other hand, because the parts are generally molded from plastic rather than machined, thus reducing manufacturing costs.
[0004] In particular, it is worth emphasizing the difficulty of perfectly aligning a micromirror matrix array with an optical projection unit that generally includes at least one lens. Due to the high numerical aperture of the objective lens used for the projection function, the projection quality of the image deteriorates significantly when the lateral offset from the optical axis reaches several microns. Therefore, in practice, projection image distortion is unavoidable when known prior art solutions are used. Any projection module of this type has its own optical properties, particularly geometric aberrations, including optical distortion and spherical aberration. Geometric aberrations can be introduced during the manufacturing of micromirrors. All of these factors result in the matrix array light source exhibiting non-uniform behavior.
[0005] All of the aforementioned modules have specific characteristics related to the combination of manufacturing tolerances of their components. Fluctuations in DC current are currently unavoidable during the manufacturing of semiconductor components such as multiple LEDs or LED matrix arrays. As a result, in a given LED matrix array, at equal load current, the LEDs emit a light beam of variable, non-uniform intensity. While it is possible to modify projection settings to account for the electronic and / or optical characteristics of the lighting module, it is important that, even if a lighting module fails, it can still project a default image that does not dazzle other road users.
[0006] When pairing a powered vehicle's control module with a lighting module, data describing the characteristics of one or the other module may be exchanged between the modules to allow for consideration during the operation of the powered vehicle. These parameters are specific to the lighting module in question and may differ between two lighting modules manufactured using the same manufacturing process. Therefore, it is important to ensure consistency between the parameters exchanged during pairing and the parameters used during the operation of the lighting modules, especially if the lighting modules may be modified.
[0007] It has been proposed to drive pixelated light sources in voltage mode: a common voltage is applied to all the fundamental light sources forming a matrix array of pixelated light sources. The amplitude of the current passing through each fundamental light source is controlled by a pulse-width modulated signal. The duty cycle of the signal affects the average amplitude of the current, which in turn affects the amount of light emitted by each fundamental light source. To prevent thermal runaway, it is necessary to store an electrical-thermal calibration, which depends on the individual characteristics of each matrix array light source, in the control module, for example, between the pairing of the two modules in question. Thermal runaway occurs when the semiconductor junction of a fundamental light source becomes hot due to the current flowing through it, which leads to an increase in the amplitude of this current, continuing until the junction is damaged or destroyed. Incorrect calibration cannot prevent this situation.
[0008] The objective of the invention is to alleviate at least one of the problems of the prior art. More precisely, the objective of the invention is to provide a method for authenticating data exchanged between a control module for a powered vehicle and a lighting module controlled by it.
[0009] According to a first aspect of the invention, a method is provided for authenticating image data exchanged between a transmitting control module and a receiving illumination module for a powered vehicle. The two modules each include a unit for transmitting and receiving image data and are connected by a first channel for transmitting image data. The method is noteworthy in that it includes the following steps: a) Transmitting image data containing at least one authentication element from the control module to the lighting module; b) After receiving the image data by the lighting module, the processing unit verifies the authentication element; c) In the lighting module, if verification fails, communication with the control module should be cut off; otherwise, communication should continue.
[0010] Image data represents numerical values, at least a portion of which represent the image intended to be projected by the receiving illumination module; that is, they are data transmitted within a frame that forms an integral part of the image intended to be projected by the receiving illumination module. This is particularly advantageous when the channel for transmitting data between the transmitting control module and the receiving illumination module is not capable of transmitting authentication elements, and when the data rate provided for non-image data is very limited, such as a channel dedicated to video.
[0011] Preferably, the receiving illumination module includes a pixelated light source. In this case, the image data may include, for example, data organized into a matrix, where each element of the matrix constitutes a pixel associated with a numerical value in the image data. Each pixel may be used to form an image projected by the pixelated light source and / or to participate in forming an authentication element of the control module.
[0012] In one example, each pixel of the matrix forms part of the projected image, and a portion of the digital value is modified, thus forming the authentication element. For example, a group of pixels located in the image region corresponding to the region that is normally illuminated when a lighting function such as low beam is on is used. For example, this information may be inserted by changing the minimum effective bits (e.g., minimum effective 2 bits) of the pixel group.
[0013] In another example, not all pixels form part of the projected image, and the image's pixel matrix includes additional rows and / or columns containing authentication element data.
[0014] Preferably, the method may include the step of projecting the image data by the lighting module only if the received image data has been successfully verified.
[0015] Preferably, the authentication element may include data encrypted with encryption technology. The lighting module may include a memory element that stores verification data enabling the encrypted data to be verified.
[0016] The data encrypted with encryption technology may preferably include a hash that covers at least the image data transmitted in step a).
[0017] Preferably, the authentication element may include a date indicator or a counter indicating the exchange of data between the two modules.
[0018] The method may preferably include a preliminary step of exchanging a public encryption key between the two modules, the encryption key forming part of a public / private encryption pair associated with each of the two modules.
[0019] The authentication element may preferably include data encrypted or signed using the control module's private key. Preferably, it may include a hash covering at least part or all of the image data transmitted in step a), the hash being signed by the private encryption key associated with the control module.
[0020] Data representing at least one authentication factor may preferably be added to the image data before transmission.
[0021] Preferably, a bidirectional second channel for transmitting data may connect the control module and the lighting module. The method may preferably include the steps of the lighting module authenticating the control module and / or vice versa by exchanging data over the second channel for transmitting data. The second channel may preferably be a control channel associated with the first channel for transmitting image data.
[0022] According to a second aspect of the invention, a lighting system for a powered vehicle is provided. The system includes a transmitting control module and a receiving lighting module, the two modules each including a unit for transmitting and receiving image data, and are connected by a first channel for communicating the image data. The lighting system is noteworthy in that the control module and the lighting module are configured to carry out steps of the method according to a prior aspect of the invention.
[0023] Preferably, the lighting module may include a secure memory element intended to store verification data that enables the received encrypted data to be verified. Preferably, the element may be integrated with the light source such that the secure memory element is encapsulated in a component of the pixelated source and cannot be separated from the light source without irreversibly damaging the light source. Preferably, the secure memory element is integrated into the ASIC chip forming the light source. It may be integrated in particular into the substrate of the monolithic pixelated source.
[0024] The control unit may preferably include a microcontroller element. The control unit may preferably include a field-programmable gate array (FPGA) type chip, an application-specific integrated circuit (ASIC), or a composite programmable logic device (CPLD). These elements are configured by a computer program suitable for performing the described functions.
[0025] The lighting module may preferably include a pixelated light source having a substrate on which the safety memory element is integrated.
[0026] Preferably, each of the two modules may comprise a clock, and the clocks of the two modules are synchronized. Preferably, the counter may be initialized to a common value during pairing of the lighting module and the control module. Preferably, the counter may be incremented each time a message is transmitted and / or received by each of the two modules.
[0027] Preferably, the data encrypted by the encryption technique may comprise a hash of a value indicative of date, or a hash of a counter of data exchanges between the two modules.
[0028] Preferably, the authentication element may comprise data encrypted or signed using the private key of the transmitting module.
[0029] Communication between the two modules may preferably be disconnected after a predetermined number of failures in verifying data describing the authentication element of the transmitting module.
[0030] The matrix array light source may preferably comprise a monolithic source, said monolithic source comprising a basic electroluminescent light source including semiconductor elements etched on a common substrate and activatable independently of each other.
[0031] The matrix array light source may preferably comprise a micro LED matrix array comprising a matrix array of basic sources, said basic sources being light emitting diodes (LEDs) of small dimensions, typically less than 150 µm, preferably assembled on a common substrate.
[0032] The matrix array light source may preferably comprise a DMD (representing digital micro-mirror device), in which DMD each basic source comprises one micro-mirror of the matrix array, said one micro-mirror of the matrix array selectively reflects an incident light beam depending on its position.
[0033] The lighting module may preferably include a control unit. The control unit may preferably be configured to control the matrix array light source.
[0034] Preferably, the lighting module and / or control module may include a processor programmed to encrypt and / or sign data using an encryption key stored in the memory element.
[0035] Preferably, a malfunction in the powered vehicle's lighting module and / or control module may be detected if data decoding fails or the signature cannot be verified.
[0036] The lighting module may preferably include a unit for receiving / transmitting data. The unit for receiving and transmitting data may preferably include a network interface that can receive and transmit data via a data bus inside the powered vehicle. For example, the bus may be an Ethernet bus, a GMSL bus (GMSL stands for gigabit multimedia serial link), or a bus using LVDS technology (LVDS stands for low-voltage differential signaling), such as an FPD-Link III bus.
[0037] According to yet another aspect of the invention, a computer program is provided, which includes a set of instructions, which, when executed by a processor, cause the processor to carry out a method according to one aspect of the invention.
[0038] According to yet another aspect of the invention, a non-temporary computer-readable storage medium is provided, which stores a computer program according to a prior aspect of the invention.
[0039] By using the measures provided by the present invention, it becomes possible to provide a method for authenticating image data exchanged between a power vehicle's control module and a lighting module controlled by it. This allows each of the two modules to automatically ensure, for example, via the power vehicle's video bus, that the module transmitting image data to it is precisely the module that was previously paired during the assembly of the power vehicle.
[0040] Furthermore, the method allows for verification of the integrity of the received data. When parameters describing the vehicle's pitch angle, the position of the lighting module within the powered vehicle, or the calibration data (whether thermoelectric or not) of the lighting module's light source are exchanged during pairing, it is important for the module to be able to assure that the parameters initially exchanged remain valid. This is made possible through the use of the data authentication method according to aspects of the invention. Successful authentication may mean, for example, that the modules were correctly paired beforehand, while failed authentication may mean that one or the other module has been changed in the meantime, that new pairing is required, or that one or the other module is in a failure mode.
[0041] By integrating authentication data into the image stream transmitted via the video bus, the provided solution enables rapid detection of authentication issues without requiring a dedicated connection for this purpose. Using hashes of the transmitted command images further allows for controlled and limited bandwidth requirements for this authentication method. [Brief explanation of the drawing]
[0042] Other features and advantages of the present invention will be better understood by reading the example description and drawings, which are shown in the drawings: [Figure 1] Figure 1 shows a sequence of the main steps of a method according to a preferred embodiment of the invention. [Figure 2] Figure 2 is an explanatory diagram of a lighting system according to a preferred embodiment of the invention. [Modes for carrying out the invention]
[0043] Unless otherwise specified, technical features described in detail with respect to a given embodiment may be combined with technical features described in relation to other embodiments, which are described non-limitingly, for example.
[0044] The description focuses on the elements of a lighting module for a powered vehicle necessary to understand the invention. Other elements that form part of such a module in known ways are not mentioned or described in detail. For example, the existence and operation of converter circuits involved in supplying power to a matrix array light source, which is known in itself, are not described in detail. The same applies to optical elements such as lenses.
[0045] Figure 1 shows the main steps of a certification method according to a preferred embodiment of the invention. The method involves a lighting system 100 as shown in Figure 2.
[0046] The control module 110 and the lighting module 120 each comprise units 114 and 124 for transmitting and receiving image data, respectively, and they are connected by a channel 140 for data communication, which enables the transmission of image data intended for the lighting module 120. The communication channel includes, for example, a video data bus or a high-throughput data transmission channel. It enables the transmission of digital image data, in which the value of each pixel corresponds typically to a light emission setpoint performed by one of the basic light sources 124 of the pixelated light sources 122 of the lighting module, and the transmission of digital image data is made possible by appropriately driving it as is known in the art.
[0047] In the first step a), image data 130, F1 including at least one authentication element F1 is transmitted from the control module to the lighting module. In step b), the lighting module 120 receives the image data and verifies the authentication element F1 using the arithmetic unit 126. Next, in step c), if the verification fails, the method cuts off communication with the control module 110. If the verification is successful, communication continues and the image data 130 is projected, preferably via appropriate control of a pixelated light source.
[0048] Preferably, the module in question enters failure mode, and a corresponding message is sent to the central unit of the powered vehicle.
[0049] The authentication function includes, for example, a preliminary exchange of public encryption keys between the two modules 110 and 120 in question, thereby enabling mutual verification of the authentication of data signed by the corresponding private encryption keys. The keys are preferably stored in memory elements 118 and 128 of the two modules 110 and 120. According to one preferred embodiment, the keys may be exchanged via a bidirectional second channel 150 connecting the two modules. This may be, for example, a control channel of a video bus or a relatively low-throughput data bus, such as a CAN bus.
[0050] To perform the authentication function, the lighting module 120 and control module 110 of the powered vehicle are equipped with calculation means 126 and 116, respectively, for generating and verifying the authentication element F1. Preferably, - For example, time or date that can be expressed in any unit such as milliseconds, or - A counter that counts the interaction or computation cycle, or - Another element that changes depending on the number of interactions, and which can be reset if it exceeds a predetermined size. Authentication factors are generated accordingly.
[0051] According to one particular embodiment, the authentication element F1 includes a hash calculated using a cryptographic hash function, with the image data 130 as input. This hash may optionally be cryptographically signed with a private encryption key associated with the control module 110.
[0052] Before the transmission of image data 130, an authentication element F1 is appended to the light-emitting setpoint data. Preferably, the concatenated data is transmitted via the video bus 140. Alternatively, without departing from the scope of the present invention, it may be assumed that element F1 is encrypted within the image data 130 itself using a steganographic method. Thus, the authentication element F1 is transmitted, preferably as a matter of the value of an additional pixel or line that forms part of the image data. After being received by the lighting module 120, the arithmetic unit 126 is enabled to verify the signature of hash F1 and to verify whether the local hash of the received image data 130 corresponds to the received value F1. If the signature is not verified or the received hash does not match the calculated hash, authentication fails and the corresponding image is not projected by the pixelated light source. Hash functions known in the art allow different results to be produced for any different computation input presented therein. Thus, different hashes allow it to be concluded that the input data presented to the hash function (here, the transmitted image data and the received image data) are different. If the signature cannot be verified, it means, for example, that the control module has been modified without proper pairing procedures (and therefore it contains a new private key or does not contain an encryption key). Authentication failure means that it is no longer possible to guarantee that the received data 130 is suitable for projection by the matrix array 122.
[0053] If the two modules include synchronized clocks and / or counters, they may verify the data corresponding to authentication element F1 by comparing them with the values of their own clocks or their own corresponding counters.
[0054] If authentication of the controller and microcontroller fails, the lighting function may be switched to communication failure mode. Advantageously, failure mode is activated only after repeated authentication failures, which avoids activating failure mode if the link is interrupted, for example, by transient electromagnetic interference.
[0055] Communication failure modes may include the following procedures, performed individually or in combination: - Disable projection or lighting function by the default image lighting module. - Generation of a failure signal by the control module 110, which is sent to the vehicle's central management system.
[0056] The lighting module 120 preferably includes a matrix array light source 122 that groups together a plurality of basic light sources 123. In the example shown, it is a matrix array of LEDs, but the invention is not limited to this example. The matrix array light source may also be a micromirror device in which each mirror is configured to generate one basic light beam of the matrix. The module includes a unit 124 for receiving and transmitting data, which is an interface that can receive and decode messages sent via a video data bus in a powered vehicle, such as a GMSL bus (GMSL stands for gigabit multimedia serial link).
[0057] The data receiving unit 124 is intended to receive data from at least one control module 110 of the powered vehicle, and in particular it may perform the interactions of steps a) and b) of the authentication method described above, preferably together with the arithmetic unit 126 to which the data receiving unit 124 is connected.
[0058] Module 120 further comprises a memory element 128 such as flash memory, and the arithmetic unit 130 is functionally connected to the memory element 128 and has read access to it.
[0059] In all embodiments, this may be a matter of an optional secure memory element that allows for the storage of data necessary to verify the authentication element F1. This data may include, for example, the private key of the lighting module 120 and / or the public encryption key of the control module 110. Preferably, this memory element is incorporated into a casing that incorporates the pixelated light source or into the ASIC chip that forms the pixelated light source 122. Thus, it becomes impossible to access its secure memory without destroying the light source.
[0060] The memory element may also include calibration data specific to the matrix array source 122. For example, this data may include values indicating the difference in brightness of the matrix array source 122 relative to the average brightness, with respect to each basic light source 123 and possibly a range of load currents. Nevertheless, the calibration data may include more complex optical, thermal, or geometric calibration parameters without departing from the scope of the present invention.
[0061] In any embodiment of the invention, the lighting system 100 may further include a second channel 150 for transmitting data, which enables bidirectional data exchange between the control module and the lighting module 120. This may be a CAN bus issue or a low-throughput control channel issue that constitutes part of a video bus. This channel 150 may be used, for example, for exchanging encryption keys in encryption technology. Channel 150 may also be used by the lighting module 120 to authenticate the control module 110. The method for authenticating the module may be performed periodically or in response to a failure to verify the received image data 130. The method for authenticating modules 120, 110 may be a challenge-response type requiring bidirectional communication. Such a method may require the control module 110 to provide a response or password calculated by a predetermined algorithm after receiving a received random challenge, as is known. Authentication may be verified by the arithmetic unit 126 of the lighting module by comparing the received response with the expected response. If authentication fails, module 120 may preferably enter failure mode, as described above.
[0062] Needless to say, the embodiments described are not intended to limit the scope of protection of the invention. Other embodiments can be envisioned without departing from the scope of the invention, based solely on the description given.
[0063] The scope of protection is determined by the claims.
Claims
1. A method for authenticating image data (130) exchanged between a receiving illumination module (120) and a transmitting control module (110) for a powered vehicle, wherein the two modules (110, 120) each include units (114, 124) for transmitting and receiving image data, and are connected by a first channel (140) for transmitting image data, and the method is: a. The step of transmitting image data (130, F1) including at least one authentication element (F1) from the control module to the lighting module; b. After receiving the image data by the lighting module, the arithmetic unit (126) verifies the authentication element (F1); c. The lighting module interrupts communication with the control module if verification fails, and continues communication otherwise. A method characterized by including the following.
2. The method according to claim 1, characterized in that the receiving illumination module (120) comprises a pixelated light source.
3. The method according to 1 or 2, characterized in that the authentication element (F1) includes data encrypted by encryption technology, the lighting module includes a memory element (128), and the memory element (128) stores verification data that enables the encrypted data to be verified.
4. The method according to 3, characterized in that the data encrypted by the encryption technology includes a hash covering at least the image data (130) transmitted in step a).
5. The method according to 4, characterized in that the authentication element (F1) includes one that indicates a date or one that indicates a counter for data exchange between the two modules (110, 120).
6. The method according to any one of claims 1 to 5, comprising a preliminary step of exchanging a public encryption key between the two modules (110, 120), wherein the encryption key forms part of a public / private encryption pair associated with each of the two modules.
7. The method according to 6, characterized in that the authentication element (F1) includes data encrypted or signed using the private key of the control module.
8. The method according to any one of claims 1 to 7, characterized in that data describing the at least one authentication element (F1) is added to the image data (130) before transmission.
9. The method according to any one of claims 1 to 8, characterized in that a bidirectional second channel (150) for transmitting data connects the control module (110) and the lighting module (120), and the method includes the step of the lighting module authenticating the control module and / or the other way around through data exchange via the second channel for transmitting data.
10. A lighting system (100) for a powered vehicle, the system comprising a transmit control module (110) and a receive lighting module (120), the two modules each comprising units (114, 124) for transmitting and receiving image data, and connected by a first channel (140) for communicating image data, the control module and the lighting module being configured to carry out the steps of the method according to any one of claims 1 to 9.
11. The lighting system according to claim 10, wherein the lighting module (120) comprises a secure memory element (128) intended to store verification data that enables the received encrypted data to be verified.
12. The lighting system according to claim 11, characterized in that the lighting module comprises a pixelated light source (122) including a substrate on which the safety memory element (128) is integrated.
13. A computer program comprising a series of instructions, wherein, when executed by a processor, the series of instructions causes the processor to carry out the method according to any one of claims 1 to 10.