Communication systems and vehicles

The communication system with a management unit and firewall function addresses the challenge of enhancing vehicle cybersecurity by filtering messages based on operating modes and encryption, ensuring efficient and secure communication without extensive adaptation.

JP2026517226APending Publication Date: 2026-05-28MERCEDES BENZ GROUP AG
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
MERCEDES BENZ GROUP AG
Filing Date
2024-05-08
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

Existing vehicle communication systems face challenges in adapting to evolving security threats, particularly in older vehicles lacking suitable update interfaces, necessitating a cost-effective and efficient method to enhance cybersecurity without extensive adaptation of computing units.

Method used

A communication system with a management unit providing a firewall function, having at least two operating modes, allows or blocks message exchange based on operating mode selection information, integrated into the vehicle's communication network, using protocols like UDS, and employing encryption for enhanced security.

Benefits of technology

This system effectively manages and filters communications, reducing computational load and latency, improving cybersecurity by allowing only authorized messages, thus protecting control units from unauthorized access and attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026517226000001_ABST
    Figure 2026517226000001_ABST
Patent Text Reader

Abstract

The present invention relates to a communication system comprising an external response unit (1) of a vehicle, at least one internal control unit (2) of a vehicle, and an internal management unit (4) interposed in a communication line (3) between the response unit (1) and the at least one control unit (2), wherein the management unit (4) provides a firewall function (5) that selectively allows or blocks exchangeable messages (6) between the response unit and the at least one control unit. The communication system according to the present invention is characterized in that the management unit (4) has at least two operating modes, in each operating mode different sets of messages (6) to be allowed to pass and messages (6) to be blocked, and the management unit (4) is configured to activate one of the operating modes in accordance with operating mode selection information (7) attached to the messages (6) by the response unit (1) or at least one control unit (2).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a type of communication system and a vehicle, which are more specifically defined by the first part of claim 1.

Background Art

[0002] Modern vehicles have various computing units such as control devices, central in-vehicle computers, telecommunication units, etc. These computing units not only communicate with each other but also with systems outside the vehicle. The communication may be carried out using wires or wirelessly. In particular, connecting the computing units inside the vehicle to a system outside the vehicle provides an entry point for attackers to manipulate vehicle components illegally. In order to prevent malicious code from being sent into the computing units in the vehicle, corresponding security measures need to be taken.

[0003] As a well-established and highly reliable method for controlling the information exchanged between two computing units, a so-called firewall is used. A firewall is a security system that includes a set of rules that serve as a basis for determining which information packet exchanges are permitted and which are not between computing units. Thereby, unauthorized access can be blocked. A firewall can also be implemented as a software component executed in a hardware component.

[0004] Technology is constantly evolving, and along with it, attacker strategies and malicious code are also evolving, so the IT security technologies used must also be adapted to these changes. When new vehicles are produced, it is possible to meet the latest security requirements at the time of production. Software updates for vehicles in use can be done wirelessly, or, for example, via wired connections when visiting the factory. However, adapting relatively older vehicles to the latest security requirements is relatively difficult, especially if those vehicles do not have a suitable update interface. In particular, the adaptation of computing units within vehicles must be kept within reasonable limits. That is, it is desirable to limit the adaptation of computing units within vehicles to as few units as possible. Nevertheless, in this case, it must be guaranteed that all computing units are reliably protected from attacks.

[0005] Patent Document 1 discloses a device for protecting diagnostic commands to a vehicle's control device and a corresponding vehicle. This document discloses the use of a firewall for filtering information exchanged between a control device and a diagnostic tester. The filtering of the information to be exchanged is performed according to the state of the hardware installed in the vehicle and the state of the software running on that hardware. In other words, for example, diagnostic commands can be forwarded only to a specific control device, or only a selection of specific diagnostic commands that prevent writing to a specific memory address of the control device can be forwarded, or if a diagnostic command is output more frequently than specified, it can be suppressed, or diagnostic commands can be executed only when the vehicle is in a specific state, for example, only when the vehicle is stopped.

[0006] Furthermore, Patent Document 2 discloses a method and a computing unit for managing diagnostic requests in a network. In this method, a computing unit with firewall functionality is incorporated into an internal vehicle communication network between a control device mounted in the vehicle and an external communication interface. A diagnostic tester can be connected to the communication network via the external communication interface. The computing unit includes a configuration file that specifies which diagnostic messages are permitted to be exchanged between the diagnostic tester and the control device, and which are not, depending on the diagnostic query received by the computing unit and the active operating mode of the control device connected to the computing unit.

[0007] Furthermore, Patent Document 3 discloses a security device and security system for monitoring traffic in a data bus. The security device is connected to the data bus between the terminals for the tool calculation unit and the control device. The security device controls the data traffic between the tool calculation unit and the control device. In this case, the security device can insert the address of the control device into the response message to the tool calculation unit. [Prior art documents] [Patent Documents]

[0008] [Patent Document 1] U.S. Patent Application Publication No. 2020 / 0272735 [Patent Document 2] German Patent Application Publication No. 102021207870 Specification [Patent Document 3] U.S. Patent Application Publication No. 2013 / 0081106 [Overview of the project] [Problems that the invention aims to solve]

[0009] The problem that this invention addresses is to provide an improved communication system. [Means for solving the problem]

[0010] According to the present invention, this problem is solved by a communication system having the features of claim 1. Advantageous configurations and developments, as well as vehicles including part of the communication system, become apparent from claims dependent on claim 1.

[0011] A communication system as described above, comprising an external response unit, at least one internal control unit, and an internal management unit intervening in the communication line between the response unit and the at least one control unit and providing a firewall function for selectively allowing or blocking exchangeable messages between the response unit and the at least one control unit, is configured such that the management unit has at least two operating modes, in each operating mode different sets of messages to be allowed and messages to be blocked, and the management unit is configured to activate one of the operating modes in accordance with operating mode selection information attached to a message by the response unit or the at least one control unit.

[0012] Depending on the situation, it may be necessary to allow or block communication between the response unit and the control unit. The response unit is any computing unit outside the vehicle. For example, the response unit may be a laptop, tablet computer, desktop computer, etc. The response unit allows, for example, developers, workers during vehicle manufacturing, or mechanics during vehicle maintenance to access the vehicle's control unit. Access to the control unit is granted accordingly. However, the response unit can also be used by attackers such as hackers, potentially leading to unauthorized manipulation of the vehicle's control unit. In this case, it is necessary to restrict communication between the response unit and the control unit.

[0013] A method for blocking or allowing the flow of information between a response unit and a control device inside a vehicle, which is fast and computationally intensive, is guaranteed using the communication system according to the present invention. The management unit has at least two operating modes, each operating mode defining a different total number of messages to be passed or blocked in the corresponding operating mode. Messages exchangeable over the communication line can be assigned to different message types. Different message types are characterized by specific content and / or a specific destination address. For example, a message type may be an instruction to the control device to perform or provide a service. In this case, the control device may, for example, supply information as a response. Messages may also include software updates, i.e., code components of software executable by the control device that can be newly introduced or modified. Each operating mode of the management unit defines which types of messages are passed or blocked. This eliminates the need to exchange state information between individual control devices and the management unit, thereby reducing the computational load and shortening latency. It also improves cybersecurity because the number of accesses to the control device is reduced. That is, the computing unit is vulnerable to attacks such as voltage glitch attacks while processing tasks.

[0014] The operating mode selection information is transmitted together with the message itself. This further simplifies the process of determining which messages should be allowed and which should be blocked. In other words, the response unit does not need to establish separate communication with the management unit, nor does the management unit need to be configured separately. The operating mode selection information may form the entire message or only a part of it. In particular, the message includes a header section and a payload section, also referred to as the header and payload section, where the header section includes information related to the processing of the message, such as the destination address, message type, task type, etc., and the payload section includes the part related to the data to be transmitted.

[0015] The control unit can also issue operating mode selection information, which allows the vehicle's control unit to switch the operating mode of the management unit.

[0016] The management unit intervenes in the communication line between the response unit and the in-vehicle control unit. Therefore, it is not necessary to adapt all of the vehicle's control units to improve IT security. Such centralized management of communication traffic can be implemented in the vehicle relatively easily and inexpensively.

[0017] The management unit may be dedicated hardware, such as a separate computing unit. The firewall functionality may be comprised of software running on the management unit. However, the management unit itself may be comprised of software, and therefore the management unit may be integrated into a computer system, for example, as a virtual machine.

[0018] In a favorable configuration of the communication system, communication conducted over the communication line is based on the UDS protocol as defined by ISO 14229. UDS stands for Unified Diagnostic Services, also known as general vehicle diagnostics. In this context, the response unit is often referred to as a tester or diagnostic tester. Communication between the response unit and the control unit is based on the so-called question-and-answer principle, also known as the request-and-response principle. Therefore, the communication system according to the present invention enables efficient and secure protection of protocols that are very widely used for vehicle diagnostics.

[0019] The messages exchanged between the response unit and the control unit are, in this case, diagnostic notifications or diagnostic commands based on the corresponding diagnostic protocol. The management unit may be a central gateway within the vehicle, connected to the vehicle's control unit via individual bus systems, particularly one or more CAN buses. The communication path of the communication line connecting the response unit to the management unit is also referred to as the diagnostic bus. The message type may be described by the UDS service. Distinction is possible using the so-called SID.

[0020] According to another advantageous configuration of the communication system according to the present invention, the operating mode selection information is protected by encryption and attached to each message. This includes all common encryption methods, such as performing signature procedures, verifying certificates, and performing so-called challenge-response authentication. Such encryption security methods often rely on the exchange of public and private keys and the computation of secret information using hash functions. This further improves the security of communication between components of the communication system. In particular, an exclusively authorized computing unit can generate a corresponding message that can actually switch the operating mode. The management unit uses the aforementioned encryption methods to verify the authenticity of the corresponding message or operating mode selection information, and switches the operating mode only if it is confirmed that the message originates from an authorized source.

[0021] Messages containing unencrypted or unencrypted operating mode selection information may also be permitted in order to activate certain operating modes that are not related to security. This is the case, for example, when only a single piece of information should be read by the control unit.

[0022] Furthermore, in another advantageous configuration of the communication system according to the invention, the management unit automatically activates the first operating mode, activates the operating mode specified by the operating mode selection information after receiving a message containing the operating mode selection information, and is configured to automatically reactivate the first operating mode after at least processing the message. In other words, the first operating mode corresponds to a kind of standard operating mode and thus is activated for most of the time. Accordingly, messages of the rules underlying the first operating mode are either passed or blocked. Only when certain messages, for example, messages related to security, are to pass, this message switches the management unit based on the added operating mode selection information, thereby enabling different operating modes to be temporarily activated to pass each respective message. Thereafter, the management unit returns to the first operating mode. The corresponding message can also instruct the management unit such that not only the message itself but also, for example, the subsequent x messages are passed. In this context, "processing of the message" is understood as transfer or blocking by the management unit.

[0023] Preferably, in the first operating mode, the transfer of all messages is blocked. This can further improve the cyber security of the communication system according to the invention. Thus, usually, the management unit blocks the exchange of messages between the response unit and the control device inside the vehicle. Thereby, only authorized messages, i.e., messages containing appropriate operating mode selection information, preferably operating mode selection information protected by encryption, can be transferred.

[0024] Furthermore, in another advantageous configuration of the communication system according to the invention, the management unit has a monitoring interface and is configured to provide operation information describing the operation behavior of the management unit via the monitoring interface. Thereby, the user can understand the behavior of the management unit or each firewall function. Thus, for example, a developer can understand why a message was not transferred even though it should have been transferred originally. Particularly advantageously, the operation information is read out by a so-called watchdog. A watchdog is a function for identifying a failure of a digital system. Thereby, the watchdog can take appropriate measures to maintain the operation of the communication system when a malfunction occurs. For example, individual components of the communication system can be reset or restarted.

[0025] According to another advantageous configuration of the communication system according to the invention, decision logic for determining which messages should be blocked and which messages should be passed, which is inherent in the management unit according to each operation mode, is defined in the form of a decision tree. Thereby, the decision behavior of the management unit can be understood quickly and easily. Various levels of the decision tree are subdivided according to the message type. In this case, at the top layer of the decision tree, for example, it is checked which SID has the corresponding message, and based on this, messages with a specific SID are passed, messages with another SID are blocked, and messages with yet another SID are checked in a lower layer of the decision tree. In a lower layer of the decision tree, a plurality of SIDs can be grouped together, so that, for example, messages addressed to a specific destination address are blocked or passed.

[0026] Furthermore, in a more advantageous configuration of the communication system according to the present invention, if the management unit blocks the forwarding of a message generated by the response unit to the target control unit, the management unit is configured to respond on behalf of the target control unit. In this case, the management unit generates a unique response message addressed to the response unit, using the address of the target control unit as the source address. This allows the operational sequence in communication between the response unit and the control unit to be maintained in a very efficient manner. Depending on the message type, it may be necessary for the response unit to wait for a response from the target control unit. However, if the management unit blocks the forwarding of the corresponding message to the target control unit, the corresponding response message will not be received, and the response unit will wait for an excessively long time. However, to prevent this, the management unit itself can generate the response message and send it to the response unit on behalf of the target control unit.

[0027] Preferably, the management unit is configured to add error information to the response message, which includes at least one instruction relating to at least one operating mode of the management unit. This allows the operating behavior of the response unit to be adapted to the situation. For example, if the response unit is authorized to communicate with a control unit but uses an incorrect operating mode, thereby blocking the relevant message by the management unit, the response unit can activate the appropriate operating mode of the management unit, thereby forwarding the message to the corresponding control unit. This applies to cases where the response unit is used to communicate with a general-purpose management unit that does not have firewall functionality, and also to communication with the management unit according to the present invention. In other words, the response unit can query the implementation of the management unit, and the response unit is notified of which operating modes are available. Depending on the implementation of the management unit, various combinations of operating modes can also be provided. That is, a first management unit may have a first number of operating modes, and a second management unit may have a different number of operating modes. Accordingly, the response unit can activate the appropriate operating mode for each management unit to allow each message to pass through.

[0028] The vehicle according to the present invention includes at least one control device included in the communication system described above, and a management unit included in such communication system. The vehicle may be any vehicle such as a passenger car, truck, transporter, or bus. By including the corresponding components of the communication system according to the present invention, the cybersecurity of the vehicle according to the present invention is improved in a very simple, efficient, and reliable manner.

[0029] Another advantageous configuration of the communication system and vehicle according to the present invention will become apparent from the embodiments described below in more detail with reference to the figures. [Brief explanation of the drawing]

[0030] [Figure 1] This is a schematic diagram of a vehicle and a communication system according to the present invention. [Figure 2] These are two decision trees configured according to different operating modes of the communication system's management unit. [Modes for carrying out the invention]

[0031] Figure 1 shows a vehicle 9 according to the present invention. The vehicle 9 includes a plurality of control devices 2, such as an engine control device, a transmission control device, an ABS control device, an instrument cluster, a navigation system, an infotainment system, etc. The control devices 2 can be connected to a management unit 4 via one or more bus lines 10, such as a high-speed bus and a low-speed bus. The management unit 4 may be a dedicated computing unit or a software component executed on another computing unit. The management unit 4 is also referred to as a gateway.

[0032] The control unit 2 is communicable via the management unit 4 in order to read information, activate the control unit 2 for the provision of services, and / or to change or introduce new software components of the control unit 2. For this purpose, an external response unit 1 is connected to the corresponding control unit 2 via a communication line 3. The portion of the communication line 3 between the response unit 1 and the management unit 4 is also referred to as the diagnostic bus 3.1, and the portion between the management unit 4 and the control unit 2 is also referred to as the type bus 3.2. Here, "type" represents the category of control unit 2 connected to the type bus 3.2, i.e., an infotainment bus. Furthermore, sensors 11 may be connected to each control unit 2 via a subbus 3.3.

[0033] To enhance cybersecurity, the management unit 4 includes or provides a firewall function 5. The firewall function 5 may be provided by a software component running in the management unit 4. The response unit 1 is used to communicate with each control unit 2. Here, the management unit 4 manages the communication that takes place via the communication line 3. This communication is based on the Unified Diagnostic Services protocol as defined by ISO 14229, according to an advantageous embodiment of the communication system of the invention. Corresponding diagnostic notifications are exchanged as messages 6, illustrated in Figure 2. The management unit 4 determines which of those messages 6 should be allowed to pass to each control unit 2, or which of those messages 6 should be blocked. Similarly, the management unit 4 can allow or block messages 6 output from the control unit 2 to the response unit 1.

[0034] According to the present invention, the management unit 4 has at least two operating modes, in which different sets of various messages 6 are passed through or blocked. Activation of each operating mode is performed via operating mode selection information 7 attached to each message 6 (see Figure 2). Both the response unit 1 and the control device 2 can attach the operating mode selection information 7 to the corresponding message 6, thereby allowing the response unit 1 and the control device 2 to change the operating mode of the management unit 4.

[0035] In Figure 2, the decision logic underlying each operating mode is shown in the form of a decision tree 8 for two operating modes with different configurations. Figure 2a) shows the configuration for the first operating mode, and Figure 2b) shows the configuration for the second operating mode. Here, a circled checkmark corresponds to the passage of message 6, and a circled × mark corresponds to the blocking of message 6 forwarding.

[0036] In the first step 201, the management unit 4 analyzes the received message 6. The message 6 consists of a header 6.1 and a payload 6.2. The operation mode selection information 7 is a component of the payload 6.2, preferably protected by encryption. The management unit 4 activates the operation mode set by the operation mode selection information 7. Thereafter, various messages 6 are forwarded or blocked according to the active operation mode. For this purpose, messages 6 can be grouped according to the address unit 12 and the service unit 13, for example, as suggested in steps 202 and 203. The service unit 13 describes, for example, a specific message type, that is, for example, which service should be provided or utilized by each control device 2 using each message 6. If the communication system according to the present invention is based on the UDS protocol as defined by ISO 14229, the service unit 13 may be, for example, a so-called SID. Thus, various SIDs can be set to pass through the management unit 4. Corresponding filtering can be performed based on the address unit 12, which corresponds to the source address or destination address of the corresponding hardware component of the communication system. In the embodiment shown in Figure 2, the service unit 13 is positioned before the address unit 12 in message 6. Generally, the positions of the service unit 13 and the address unit 12 may be reversed.

[0037] The filtering of message 6 can be performed based on any number of subsequent steps. Message 6 that is not simply passed through in step 203 can be further examined in a subsequent step, for example, step 204. A first subset of these messages 6 can be blocked, and another subset, here denoted as TYP1, is further examined in step 205. This subset includes, for example, messages that provide highly specialized services to a particular destination address. In steps 206 and 207, another subset, TYP1.1 and TYP1.2, can be formed from subset TYP1. In step 208, yet another subset, here denoted as TYP1.1.1, can be formed from such subsets.

[0038] According to Figure 2b), another operating mode of the management unit 4 is active, resulting in different messages 6 being passed through or blocked.

[0039] The communication system according to the present invention is extremely simple and can be cost-effectively integrated into existing vehicles. Only one component, namely the aforementioned management unit 4, needs to be adjusted. Therefore, this communication system allows for the reuse of existing technologies. Cybersecurity is improved by managing or filtering communications conducted via the communication line 3. Reliable access to the control unit 2 by authorized users is guaranteed in a simple manner. Users with appropriate authorization can quickly and easily configure the management unit 4 to gain the necessary access to the control unit 2 by sending a corresponding message 6 containing corresponding operating mode selection information 7.

Claims

1. A communication system comprising: an external response unit (1) of the vehicle; at least one internal control device (2) of the vehicle; and an internal management unit (4) interposed in a communication line (3) between the response unit (1) and the at least one internal control device (2), In a communication system, the management unit (4) provides a firewall function (5) that selectively allows or blocks exchangeable messages (6) between the response unit and the at least one control device, A communication system characterized in that the management unit (4) has at least two operating modes, in each operating mode a different set of messages (6) to be allowed to pass and messages (6) to be blocked, and the management unit (4) is configured to activate one of the operating modes in accordance with operating mode selection information (7) attached to a message (6) from the response unit (1) or the at least one control unit (2).

2. The communication system according to claim 1, characterized in that the communication conducted via the communication line (3) is based on the UDS protocol as defined by ISO 14229.

3. The communication system according to claim 1 or 2, characterized in that the operation mode selection information (7) is protected by encryption and attached to each message (6).

4. The communication system according to any one of claims 1 to 3, characterized in that the management unit (4) is configured to automatically activate a first operating mode, activate an operating mode specified by the operating mode selection information (7) after receiving a message (6) containing operating mode selection information (7), and automatically reactivate the first operating mode after at least processing the message (6).

5. The communication system according to claim 4, characterized in that, in the first operating mode, the transmission of all messages (6) is blocked.

6. The communication system according to any one of claims 1 to 5, wherein the management unit (4) has a monitoring interface and is configured to provide operational information via the monitoring interface, and the operational information describes the operational behavior of the management unit (4).

7. The communication system according to any one of claims 1 to 6, characterized in that the decision logic for determining which messages (6) should be blocked and which messages (6) should be allowed, which is inherent in the management unit (4) according to each operating mode, is defined in the form of a decision tree (8).

8. The communication system according to any one of claims 1 to 7, wherein the management unit (4) is configured to respond on behalf of the target control device when the management unit (4) blocks the forwarding of the message (6) generated by the response unit (1) to the target control device, and the management unit (4) generates a unique response message addressed to the response unit (1) and uses the address of the target control device as the source address.

9. The communication system according to claim 8, wherein the management unit (4) is configured to add error information to the response message, and the error information includes at least one instruction relating to at least one operating mode of the management unit (4).

10. In vehicle (9), A vehicle (9) comprising at least one control device (2) included in the communication system according to any one of claims 1 to 9, and a management unit (4) included in the communication system.

Citation Information

Patent Citations

  • Method and corresponding device for protecting vehicle from cyber attack

    JP2020109953A

  • Vehicle control system, vehicle control method and vehicle control device

    JP2021197595A

  • Method and computing unit for managing diagnostic requests in a network

    DE102021207870A1

  • Bus monitoring security device and bus monitoring security system

    US20130081106A1

  • Device for securing diagnostic commands to a control unit, and corresponding motor vehicle

    US20200272735A1