Control systems and methods for vehicles
The control system architecture addresses the challenge of authenticating sensor data messages by periodically authenticating selected messages, preventing battery failure due to tampering, and optimizing computational resources.
Patent Information
- Application Number
- PCT/EP2024/081050
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-03
- Filing Date
- 2024-11-04
- Publication Date
- 2025-05-08
AI Technical Summary
Existing vehicle control systems lack effective methods to authenticate sensor data messages between control systems, which can lead to battery failure due to tampering or malicious interference.
A control system architecture that periodically applies an authentication process to selected messages between the first and second control systems, allowing the second control system to verify the authenticity of the messages on a timescale that prevents battery failure, while minimizing computational overhead by not encrypting every message.
This solution effectively prevents battery failure due to tampering by ensuring timely authentication and intervention, while reducing processing power consumption by not encrypting all messages, thus maintaining system performance and safety.
Smart Images

Figure EP2024081050_08052025_PF_FP_ABST
Abstract
Description
[0001] Control Systems and Methods for Vehicles
[0002] TECHNICAL FIELD
[0003] The present disclosure relates to control systems for vehicles. Aspects of the invention relate to first and second control systems for a vehicle, first and second methods performed by first and second control systems for a vehicle, a vehicle, computer readable instructions and a computer-readable data carrier. Particularly but non-exclusively, the disclosure relates to authenticating sensor data for use in battery management systems.
[0004] BACKGROUND
[0005] Battery-powered vehicles (cars, vans lorries, etc) are rapidly increasing in number. Car batteries tend to have a plurality of battery cells. The battery functions are managed by onboard vehicle controllers that gather and process sensor data to monitor and maintain the health of the battery. Such monitoring and maintenance can relate to processes such as determining when to engage and disengage the battery e.g. through one or more contactors, monitoring battery charging and discharge cycles, and monitoring cell efficiency. In hybrid vehicles that use a battery in combination with a petrol or diesel engine, the sensor data can also be used to manage the interplay between the battery and the hybrid engine.
[0006] SUMMARY OF THE INVENTION
[0007] Aspects and embodiments of the invention provide a first control system for a vehicle, a second control system for a vehicle, a method performed by a first control system in a vehicle, a method performed by a second control system in a vehicle, a vehicle, computer readable instructions and a computer readable data carrier, as claimed in the appended claims.
[0008] Aspects of the invention herein relate generally to authentication of messages from a first control system to a second control system in a vehicle, in order to prevent failure conditions of the battery in the vehicle, due to e.g. tampering.
[0009] According to an aspect of the present invention there is provided a first control system for a vehicle, the first control system comprises one or more processors. The one or more processors are collectively configured to: send a sequence of messages to a second control system in the vehicle, for use by the second control system in controlling a battery of the vehicle, and periodically apply an authentication process to selected messages in the sequence of messages that allows the second control system to authenticate that the selected messages in the sequence originate from the first control system. A first time period between each selected message is less than a second time period associated with a failure condition of the battery.
[0010] Because the messages sent from the first control system to the second control system are used to control the battery, it is necessary to verify that the information contained in such messages (e.g. sensor readings and the like) is genuine and that the messages haven’t been tampered with or otherwise maliciously intercepted. Messages can be protected using encryption, however encrypting every message in the sequence uses considerable processing power and can slow the feedback process down between the battery, sensors and the battery control system. The disclosure herein recognises that the effects of malicious tampering such as battery failure are not instantaneous, and that there is a delay between receipt of a malicious message and any negative effects arising therefrom. Thus, by only applying an authentication process periodically and on a time scale less than the time on which failure of the battery can occur (instead of to every message in the sequence), computer processing time and power associated with the encryption process can be reduced, while ensuring that the effects of any malicious tampering can be mitigated if the authentication process fails. This solution is further advantageous as the sensor data itself is not considered sensitive or confidential, and thus the intervening messages can be safely sent unencrypted.
[0011] In some embodiments, the first control system comprises one or more controllers collectively comprising at least one electronic processor having an electrical input for receiving an input signal; and at least one memory device electrically coupled to the at least one electronic processor and having instructions stored therein; and wherein the at least one electronic processor is configured to access the at least one memory device and execute the instructions thereon so as to (e.g. so as to cause the first controller to): send a sequence of messages to a second control system in the vehicle, for use by the second control system in controlling a battery of the vehicle, and periodically apply an authentication process to selected messages in the sequence of messages that allows the second control system to authenticate that the selected messages in the sequence originate from the first control system. A first time period between each selected message is less than a second time period associated with a failure condition of the battery.
[0012] The second time period can be less than or equal to a minimum time to cause failure of the battery. In this way, the first controller sends messages to the second controller that can be authenticated by the second controller on a timescale less than the time that it would take for the battery to fail due to e.g. tampering of the sequence of messages. Thus, in the event that an encrypted message cannot be verified, the second control system has time to intervene, e.g. by shutting down the battery or stopping the vehicle. In some embodiments, the time period is between 5 seconds and 8 seconds, which is an average time interval in which battery failure can occur.
[0013] In some embodiments, the first control system can be further collectively configured to receive a response message from the second control system, the response message having the authentication process applied to it, and authenticate that the response message originates from the second control system, using the authentication process. Thus, the first control system may perform mutual authentication with the second control system, to ensure that the messages received from the second control system are also genuine, and to prevent e.g. downstream tampering initiated from the second control system.
[0014] In some embodiments, the authentication process adds a unique identifier to the selected messages, the unique identifier being derived from the content of the respective message. As an example, the authentication process may use a checksum. This has the advantage of being a light-weight, computationally efficient method of authenticating the message, which is advantageous in embodiments herein, where the purpose is to reliably verify the sender (e.g. without necessarily needing to protect the underlying data itself). In other embodiments, the authentication process is a mutual authentication protocol based on an asymmetric key process. Examples of asymmetric key processes include but are not limited to: Elliptic-Curve Diffie- Hellman processes and Cyclic Redundancy Checking processes. These are more secure encryption methods that are more difficult to tamper with, building in increased security to the verification process.
[0015] According to another aspect of the present invention there is provided a second control system for a vehicle. The second control system comprises one or more processors collectively configured to receive a sequence of messages from a first control system, the sequence of messages being for use by the second control system in controlling a battery of the vehicle. Periodic selected messages in the sequence of messages have an authentication process applied to them that allows the second control system to authenticate that the respective selected messages originate from the first control system. A first time period between each selected message is less than a second time period associated with a failure condition of the battery.
[0016] Thus, the second control system is able to verify or authenticate that the messages are genuine and haven’t been tampered with, with enough time to intercept and prevent the failure condition of the battery, yet without having to encrypt / decrypt every message in the sequence which would take up large amounts of processing power. This is possible because, as recognised by the Inventors herein, the messages themselves do not contain confidential information, and thus some of the messages can be left unencrypted, while the periodic encryption is still sufficient to verify the source of the sequence of messages as a whole, and prevent battery failure due to tampering.
[0017] In some embodiments, the second control system comprises one or more controllers collectively comprising at least one electronic processor having an electrical input for receiving an input signal; and at least one memory device electrically coupled to the at least one electronic processor and having instructions stored therein; and wherein the at least one electronic processor is configured to access the at least one memory device and execute the instructions thereon so as to (e.g. cause the second controller to): receive a sequence of messages from a first control system, the sequence of messages being for use by the second control system in controlling a battery of the vehicle. Periodic selected messages in the sequence of messages have an authentication process applied to them that allows the second control system to authenticate that the respective selected messages originate from the first control system. A first time period between each selected message is less than a second time period associated with a failure condition of the battery. The second control system receives the messages and is able to authenticate that they originate from the first control system. The fact that the selected messages are sent at intervals corresponding to the first time period mean that if an authentication fails, the second control system still has sufficient time to shut the battery down before any battery failure could occur.
[0018] The one or more processors can be further controlled to: verify that each selected message in the sequence of messages originated from the first control system, using the authentication process. In response to being unable to verify that a respective selected message originated from the first control system, the one or more processors can be configured to perform one or more of the following operations: output that data corruption and / or data tampering has occurred; initiate an immobilisation procedure for the vehicle; and open contactors on the vehicle to disengage the battery from the vehicle. Thus, in this way, a battery can be shut down or the vehicle immobilised before any battery failure can occur. Thus, in the event that the first control system is compromised (e.g. due to tampering), the second control system can intervene and immobilise the vehicle without the malicious agent being able to cause battery failure.
[0019] According to another aspect there is a vehicle comprising a first control system and / or a second control system as described in the aspects above. The vehicle further comprises a battery and one or more sensors. Sensor data from the sensors can be sent in the sequence of messages sent from the first control system to the second control system for use in controlling the battery. The control systems herein can thus be installed directly in a vehicle, to efficiently protect the battery of the vehicle against tampering.
[0020] In some embodiments, the first control system is comprised in a Wireless Gateway Module and the second control system is comprised in a Battery Management Controller Module. These modules control the battery in many vehicles and are often connected by a wired connection. Embodiments herein allow for efficient authentication of signals sent by the Wireless Gateway Module to the Battery Management Control Module, on timescales on which the Battery Management Control Module can shut the battery down if the authentication fails, but without applying the authentication process to every message sent from the Wireless Gateway Module to the Battery Management Control Module, thus reducing computational overheads associated with the authentication.
[0021] According to another aspect there is a method performed by a first control system for a vehicle. The method comprises sending a sequence of messages to a second control system in the vehicle, for use by the second control system in controlling a battery of the vehicle; and periodically applying an authentication process to selected messages in the sequence of messages that allows the second control system to authenticate that the selected messages in the sequence originate from the first control system; wherein a first time period between each selected message is less than a second time period associated with a failure condition of the battery.
[0022] The methods herein have the advantage of allowing messages sent from the first control system to be authenticated by the second control system, on a timescale on which the second control system can intervene and prevent battery failure, but without incurring the computational overhead of applying the authentication process to every message in the sequence. As described above, this is possible because the data in the messages is generally not sensitive or confidential, and thus the messages between the selected messages can safely be sent in plain text.
[0023] According to another aspect there is a method performed by a second control system for a vehicle, the method comprising receiving a sequence of messages from a first control system, the sequence of messages being for use by the second control system in controlling a battery of the vehicle. Periodic selected messages in the sequence of messages have an authentication process applied to them that allows the second control system to authenticate that the respective selected messages originate from the first control system. A first time period between each selected message is less than a second time period associated with a failure condition of the battery.
[0024] The methods herein have the advantages of allowing messages received from the first control system to be authenticated by the second control system, on a timescale on which the second control system can intervene and prevent battery failure, but without incurring the computational overhead of having to perform the authentication process on every message in the sequence. As described above, this is possible because the data in the messages is generally not sensitive or confidential, and thus the messages between the selected messages can safely be sent in plain text.
[0025] According to another aspect of the invention there are computer readable instructions which, when executed by a computer, are arranged to perform a method according to the preceding aspects above. Thus, the invention herein can advantageously be embodied in a computer code for use on a wide variety of vehicles.
[0026] According to another aspect there is a computer-readable data carrier having stored thereon the computer readable instructions according to the preceding aspect. Thus, the invention herein can advantageously be embodied in a computer-readable data carrier for us in a wide variety of vehicles.
[0027] Within the scope of this application it is expressly intended that the various aspects, embodiments, examples and alternatives set out in the preceding paragraphs, in the claims and / or in the following description and drawings, and in particular the individual features thereof, may be taken independently or in any combination. That is, all embodiments and / or features of any embodiment can be combined in any way and / or combination, unless such features are incompatible. The applicant reserves the right to change any originally filed claim or file any new claim accordingly, including the right to amend any originally filed claim to depend from and / or incorporate any feature of any other claim although not originally claimed in that manner.
[0028] BRIEF DESCRIPTION OF THE DRAWINGS
[0029] One or more embodiments of the invention will now be described, by way of example only, with reference to the accompanying drawings, in which:
[0030] Figure 1 shows a vehicle in accordance with an embodiment of the invention;
[0031] Figure 2 shows a schematic representation of first and second control systems for a vehicle;
[0032] Figure 3 shows an example flow chart illustrating a method in a first control system in accordance with an embodiment of the invention;
[0033] Figure 4 illustrates timing of the sequence of messages and the authentication processes applied thereto;
[0034] Figure 5 shows an example flow chart illustrating a method in a second control system in accordance with an embodiment of the invention; and
[0035] Figure 6 shows another example flow chart illustrating a method in a second control system in accordance with an embodiment of the invention. DETAILED DESCRIPTION
[0036] Figure 1 illustrates a vehicle 100 according to an embodiment of the present invention. The vehicle 100 comprises a first control system 200, a second control system 250, sensors 212 and a battery 264. The battery 264 comprises a plurality of battery cells, and contactors that can be controlled by the second control system, to insert (e.g. connect) the battery 264 into the electrical circuit of the car. In the embodiment in Figure 1 , the vehicle is a passenger car, however it will be appreciated that this is merely an example, and that the vehicle could be any type of battery-powered vehicle, including but not limited to a car, lorry, van, drone, motorbike, or bicycle.
[0037] The first control system and the second control system can be connected via a wired connection 110. The second control system receives messages from the first control system for use in controlling the battery. It is an object of embodiments herein to enable the second control system to reliably verify that messages from the first control system are genuine and do actually originate from the first module. This is needed to ensure that malicious interception and re-routing of messages can be detected so that malicious actors can be prevented from providing false data to the second module that could result in battery failure. The verification is also necessary to detect tampering of the vehicle for warranty purposes.
[0038] Figure 2 shows a first control system 200 and a second control system 250 for a vehicle, such as the vehicle 100 above. As an example, the first control system may comprise a Wireless Gateway Module (WGM) in the vehicle, and the second control system may comprise the Battery Management Controller Module (BMCM). It will be appreciated however that these are merely example modules and that the functionality described herein may equally be performed by other control systems in a vehicle.
[0039] The first control system 200 comprises processing means 202 and memory means 204. The processing means can comprise one or more electronic processing devices 202 (otherwise referred to herein as processors) which operably execute computer-readable instructions 206. The memory means 204 may comprise one or more memory devices. The memory means 204 is electrically coupled to the processing means 202. The memory means 204 is configured to store instructions 206, and the processing means 202 is configured to access the memory means 204 and execute the instructions 206 stored thereon.
[0040] The processing means 202 may be any type of processing circuitry or logic, such as, for example, a central processing unit (CPU), a Graphics Processing Unit (GPU), a Neural Processing Unit (NPU), or any other type of processing unit. Processing means 202 may comprise one or more sub-processors, processing units, multicore processors or modules that are configured to work together in a distributed manner to control the node in the manner described herein.
[0041] The memory means 204 of the first control system 200, is configured to store any data or information referred to herein, such as for example, sensor data, requests, resources, information, data, signals, or similar that are described herein. The processing means of the first control system 200 can be configured to control the memory means 204 of the control system to store such information. In some embodiments, the first control system can be a virtual node, e.g. such as a virtual machine or any other containerised computer node. In such embodiments, the processing means 202 and / or the memory means 204 may be portions of larger processing and memory resources respectively.
[0042] The first control system 200 further comprises an input means 208 and an output means 210. The input means 208 may comprise an electrical input of the first control system 200. The output means 210 may comprise an electrical output of the first control system 200. The input 208 is arranged to receive signals 214 from one or more sensors 212. The signals 214 are electrical signals which are indicative of readings from the sensors 212. The output 210 is arranged to output a sequence of messages 216 to the second control system 250 for use by the second control system in controlling the battery of the vehicle.
[0043] The sensors 212 are for measuring quantities related to the battery of the vehicle and / or other parameters of the vehicle related to battery management, e.g. battery control data. The sensors 212 may be temperature sensors to measure the temperature of the battery, voltage or current sensors to measure the voltage or current of the battery, or of individual cells therein, or any other sensor suitable for collecting data that can be used in battery management.
[0044] As noted above, the first control system 200 sends a sequence of messages 216 to a second control system 250. The first and second control systems may be connected via a wired link 110, and may use isolated serial peripheral interface communication (isoSPI comm) to communicate.
[0045] The second control system 250 likewise has processing means 252, and memory means 254. The memory means 254 is configured to store the computer readable instructions 256, and the processing means 252 is configured to access the memory means 254 and to execute the instructions stored thereon. Processing means and memory means were described above with respect to the first control system 200 and the detail therein will be appreciated to apply equally to the second control system 250.
[0046] The second control system 250 further comprises an input means 258 and an output means 260. The input means 258 may comprise an electrical input of the second control system 250. The output means 260 may comprise an electrical output of the second control system 250. The input 258 is arranged to receive the sequence of messages 216 from the first control system 200. The output 262 is arranged to send a battery control signal 262 to the battery 264 to control the battery as described herein. The output 262 can also be arranged to send messages back to the first control system, for example, in the manner of mutual authentication as described below.
[0047] The first control system 200 sends a sequence of messages to second control system 250 for use by the second control system in controlling the battery of the vehicle 208. The first controller sends the sensor data and / or data derived from the sensor data, in each message. The second controller receives the sequence of messages and uses the information therein to control the battery. The second controller may output one or more control signals 262 to the battery 264 to control the battery 264. Figure 3 illustrates a method 300 according to an embodiment of the invention. The method 300 is a method performed by a first control system for a vehicle, such as the vehicle 100 illustrated in Figure 1 . The method 300 may be performed by the first control system 200 illustrated in Figure 2. In particular, the memory means 204 may comprise computer-readable instructions which, when executed by the processing means 202, cause the processing means to perform the method 300 according to an embodiment of the invention.
[0048] The method 300 is for use in an authentication process, performed by the second control system 250, for verifying that a sequence of messages sent by the first control system 200 to the second control system 250 are genuine messages from said first control system 200.
[0049] In brief, in a first step, the method comprises sending 302 a sequence of (electronic) messages to the second control system in the vehicle, for use by the second control system in controlling a battery of the vehicle. In a second step 304, the method comprises periodically applying 304 an authentication process to selected messages in the sequence of messages that allows the second control system to authenticate that the respective selected messages in the sequence originate from the first control system. A first time period, ti, between each selected message is less than a second time period, t2, associated with a failure condition of the battery.
[0050] As described above, the sequence of messages from the first control system 200 are for use by the second control system in controlling the battery of the vehicle. As such, the sequence of messages can comprise sensor readings from sensors 212, and / or any other data that can be used by the second control system 250 in controlling or otherwise monitoring the battery 264.
[0051] In step 304, periodically, a message in the sequence will have an authentication process applied to it. For example, every nth message in the sequence of messages can have the authentication process applied to it (where n is an integer). Or messages at intervals of ti seconds will have the authentication process applied to them. Generally, only the nth message (or messages every ti seconds) will have the authentication process applied to it and the other messages will not have the authentication process applied to them. Messages that do not have the authentication process applied to them can, for example, be sent unencrypted, or in plain text.
[0052] This is illustrated in Figure 4 whereby a sequence of messages, shown as upward arrows, are sent in sequence. Messages 402 and 404 are sent with an authentication process applied to them, and the other messages are sent without any authentication. As such, messages 402 and 404 can be verified by the second controller as having originated from the first control system, while there is no guarantee for any of the other messages in the sequence of messages.
[0053] The first time period ti on which the messages in the sequence have the authentication process applied to them is generally less than or equal to a minimum time to cause failure of the battery. Failure in this sense may be associated with artificial or malicious draining of the battery, over-heating of the battery, or any other battery failure condition that can be caused by incorrect messages due to e.g. malicious or tampered messages being sent to the second control system, instead of the genuine messages from the first control system. In some embodiments, ti may be less than a time period in which a battery can go from normal operating conditions, to an overheated condition. In some embodiments, the time period is between 5 and 8 seconds (e.g. between about 5 seconds and about 8 seconds), which is an average timescale on which an average battery can overheat.
[0054] In some embodiments, the authentication process adds a unique identifier to each selected message (e.g. to each nth message), the unique identifier being derived from the content of the respective message. As an example, a check sum may be added to the selected messages. The skilled person will be familiar with checksums, whereby the contents of the message itself is used to generate a unique code or number, using a process only known to the sender and receiver. In this way, if the receiver generates the same checksum as found in the message, then the message can be verified as being genuine. The use of checksums is a computationally light-weight and efficient way to enable the second control system to verify the source of a message.
[0055] The authentication process can be an encryption process. For example, the authentication process can be a mutual authentication protocol based on an asymmetric key process. Examples of such methods include, but are not limited to Elliptic-Curve Diffie-Hellman (ECDH), Cyclic Redundancy Checking (CRC) and Message Integrity Code authentication processes. The skilled person will be familiar with such methods, which are described in the following papers: Haakegaard & Lang (2015): “The Elliptic Curve Diffie Hellman (ECDH)" and A. K. Singh, "Comprehensive study of error detection by cyclic redundancy check," 2017 2nd International Conference for Convergence in Technology (I2CT), Mumbai, India, 2017, pp. 556-558, doi: 10.1 109 / I2CT.2017.8226191.
[0056] Thus, in this way, the first control system sends a sequence of messages to the second control system, periodically applying an authentication process to individual messages in the sequence, while the remaining messages are sent without the authentication process applied to them. The messages that have the authentication process applied to them are sent at intervals of ti; in other words, every ti seconds, a message is selected and sent with the authentication applied to it. ti is set to be less than a time interval t2 on which a failure of the battery can occur. In this way, if any messages in the sequence of messages are maliciously intercepted, or interfered with, and the authentication fails, the second control system has sufficient time to intervene and e.g. disable the battery, however without incurring the computational load associated with encrypting and / or verifying the source of every message in the sequence. This also draws on the fact that the messages in the sequence of messages contain sensor data and the like, which isn’t confidential, and thus the other messages in the sequence can be sent unencrypted. Thus, the disclosure herein balances the computational overhead associated with encryption and source verification, with the time period associated with battery failure, to maintain good performance of the vehicle.
[0057] It will be appreciated that other steps can be performed in addition to those illustrated in Figure 3. For example, in some embodiments, mutual authentication may be performed. For example, the method 300 can further comprise receiving a response message from the second control system, the response message having the authentication process applied to it, and authenticating that the response message originates from the second control system, using the authentication process. In this way mutual authentication between the first and second control systems can be performed.
[0058] Dual authentication in this manner allows the first control system to verify the authenticity of the second control system. For example, it allows a Wireless Gateway Module to verify the authenticity of the Battery Management Control Module. This can prevent a malicious party (e.g. an attacker or hacker) from manipulating or changing configurations downstream from the first module. For example, it prevents an attacker from sending messages from a Battery Management Control Module to the Wireless Gateway Module to perform processes such as enabling the balancing circuits at the CSC level (the units that measure voltages, temperatures). Uncontrolled balancing enablement can damage the battery or limit its operation. The skilled person will appreciate that this is merely an example, however, and that there could also be other routes to attack if a Wireless Gateway Module cannot check the authenticity of a Battery Management Control Module.
[0059] As such, in response to being unable to authenticate that a response message originates from the second control system, the first control system can block a request or instruction received from the second control system in the response message. As above, this may involve preventing a process instructed in the response message (e.g. preventing the enablement of the balancing circuits).
[0060] Turning now to Figure 5, which shows a method 500 performed by the second control system 250. The method 500 comprises complementary steps to the method 300. Briefly, in a first step, the method 500 comprises receiving 502 a sequence of messages from a first control system, the sequence of messages being for use by the second control system in controlling a battery of the vehicle, wherein periodic selected messages in the sequence of messages have an authentication process applied to them that allows the second control system to verify that the respective selected messages originate from the first control system. The first time period between each selected message is less than a second time period associated with a failure condition of the battery.
[0061] In step 502, the second control system receives the sequence of messages that were sent by the first control system in the method 300. The sequence of messages, the authentication process, and the first and second time periods were described above with respect to the method 300 and the detail therein will be understood to apply equally to the method 500.
[0062] The second control system may perform further steps of verifying 504 that each of the messages with the authentication process applied thereto originate from the first control system, according to the authentication process.
[0063] If the second control system is able to authenticate a message then it is used in the normal way (e.g. according to the usual battery control and / or management processes performed by the second control system). However, if the authentication fails and the second control system is unable to verify that a respective message originated from the first control system, then the second control system may perform 506 steps such as: outputting that data corruption and / or data tampering has occurred, initiating an immobilisation procedure for the vehicle; and / or opening contactors on the vehicle to disengage the battery from the vehicle. Thus, if a message cannot be verified, then an immobilisation procedure is initiated to safeguard the battery.
[0064] As noted above, in embodiments herein the time period between each message that has the authentication process applied to it is short enough such that there is always time for the second control system to immobilise the vehicle and / or disengage the battery before a battery failure condition occurs, ti is set to be less than t2 where te is the time horizon on which battery failure due to tampering or other malicious interference e.g. maliciously triggered overheating or draining, can occur.
[0065] Turning now to Figure 6 which illustrates a process 600 according to an embodiment in which the vehicle is an electric car, the first control system is a Wireless Gateway Module and the second control system is a Battery Management Control Module. In this example, the Wireless Gateway Module and Battery Management Control Module are connected via a wired connection 110, using an isolated serial peripheral interface communication (isoSPI comm) method. The Wireless Gateway Module performs the method 300 and the Battery Management Control Module performs the method 500 described above. In step 602 the Wireless Gateway Module and the Battery Management Control Module power up. The Wireless Gateway Module sends 302 the Battery Management Control Module a sequence of messages for use by the Battery Management Control Module in controlling a battery of the vehicle. The Wireless Gateway Module initialises 604 and runs 605 a timer. When the timer expires 606, the next message in the sequence has an authentication process applied to it, as described above. The timer is set to expire on a time period ti that is less than a timescale t2 on which the battery can fail, so that the second control system has sufficient time to disconnect the battery from the vehicle in the event that a message cannot be authenticated. Upon expiry of the time, the timer is then re-initialised by the Wireless Gateway Module and the processes repeats in a loop. Note that the timer is generally re-initialised by the Wireless Gateway Module straight after the previous timer has expired.
[0066] The Battery Management Control Module receives the messages according to step 504 and at step 608 (Check WGM credentials), the Battery Management Control Module performs step 504 of the method 500, and verifies 504 that a selected message (e.g. one having had the authentication process applied to it) in the sequence of messages originated from the first control system, using the authentication process. If in step 610 the message passes the verification, and the Wireless Gateway Module credentials are correct, then the message and the data therein can be used in subsequent processes. For example, to validate cell data 612, monitor the isoSPI comm 614, check the transceiver 616 and perform a Message Integrity Code calculation of the data (MIC / MAC) in step 618. Message Integrity Code (MIC) or Message Authentication Code (MAC) is similarto a CRC process, except the MIC / MAC can only be calculated and re-calculated correctly if the system has an encryption key.
[0067] If the Wireless Gateway Module credentials of the selected message cannot be verified in step 610, then in step 620, the second control system flags 620 the data as being corrupted and may further flag that there has been a potential malicious attack or other tampering of the system. In step 622, the second control system causes the battery contactors to open, so as to disengage the battery from the circuitry of the vehicle and immobilise the vehicle. There is thus provided a method of verifying the provenance of a sequence of messages that can be performed on an appropriate timescale to prevent tampering and prevent a battery failure condition, without performing computationally expensive processes that e.g. encrypt every message in the sequence.
[0068] Turning now to other embodiments, it will be appreciated that the methods 300 and 500 may be embodied in one or more computer programs. For example, computer readable instructions can be arranged such that, when executed by a computer, the computer is caused to perform the methods herein, such as the method 300 or the method 500. Computer readable instructions (e.g. a computer program) may take different forms, for example, source code, compiled code, executable code, or any other type of code. It will be appreciated that the source code of computer programs may be written in a wide variety of different programming languages, and may take different architectural designs. For example, the functionality described herein may be split across various different sub-routines. Furthermore, the skilled person will appreciate that many different ways of splitting the functionality between the different sub-routines will be possible. The sub-routines may be stored together in one executable file to form a self-contained program. Furthermore, computer programs may call external and / or standard libraries of computer code for performing certain sub-tasks associated with the functionality described herein.
[0069] In another embodiment, there is a computer-readable data carrier having stored thereon the computer readable instructions as above. A computer-readable data carrier may comprise non-transitory computer readable media, having stored thereon computer readable instructions as described above. Examples of computer readable media include, but are not limited to: ROM, such as a CD ROM, a semi-conductor ROM or a magnetic recording medium such as a hard disk. Examples of computer readable data carriers include but are not limited to an electronic signal, optical signal, radio signal, computer storage medium, or similar. The carrier of a computer program may be any entity or device (e.g. hardware) capable of carrying the program. As an example, a carrier may be a computer readable media as described above. In other examples a carrier may be a transmissible carrier such as an electronic or optical signal, which may be conveyed via electrical or optical cable or by radio or other means.
[0070] Variations to the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed invention, from a study of the drawings, the disclosure and the appended claims. In the claims, the word “comprising” does not exclude other elements or steps, and the indefinite article “a” or “an” does not exclude a plurality. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these claims cannot be used to advantage. Any reference signs in the claims should not be construed as limiting the scope. It will be appreciated that various changes and modifications can be made to the present invention without departing from the scope of the present application.
Claims
CLAIMS1. A first control system for a vehicle, the first control system comprising one or more processors collectively configured to: send a sequence of messages to a second control system in the vehicle, for use by the second control system in controlling a battery of the vehicle; and periodically apply an authentication process to selected messages in the sequence of messages that allows the second control system to authenticate that the selected messages in the sequence originate from the first control system; wherein a first time period between each selected message is less than a second time period associated with a failure condition of the battery.
2. A first control system as in claim 1 , wherein the second time period is less than or equal to a minimum time to cause failure of the battery.
3. A first control system as in claim 1 or 2 wherein the first time period is between 5 seconds and 8 seconds.
4. A first control system as in claim 1 , 2 or 3, wherein the one or more processors are further collectively configured to: receive a response message from the second control system, the response message having the authentication process applied to it; and authenticate that the response message originates from the second control system, using the authentication process; and in response to being unable to authenticate that the response message originates from the second control system, block a request made by the second control system in the response message from being performed.
5. A first control system as in any one of the preceding claims wherein the authentication process: adds a unique identifier to a selected message, the unique identifier being derived from the content of the respective selected message.
6. A first control system as in any one of claims 1 to 4 wherein the authentication process is a mutual authentication protocol based on an asymmetric key process.
7. A first control system as in claim 6 wherein the asymmetric key process is an Elliptic-Curve Diffie- Hellman process, or a Cyclic Redundancy Checking process.
8. A second control system for a vehicle, the second control system comprising one or more processors collectively configured to: receive a sequence of messages from a first control system, the sequence of messages being for use by the second control system in controlling a battery of the vehicle; wherein periodic selected messages in the sequence of messages have an authentication process applied to them that allows the second control system to authenticate that the respective selected messages originate from the first control system; and wherein a first time period between each selected message is less than a second time period associated with a failure condition of the battery.
9. A second control system as in claim 8 wherein the one or more processors are further controlled to: verify that each selected message in the sequence of messages originated from the first control system, using the authentication process; and in response to being unable to authenticate that a respective selected message originated from the first control system, perform one or more of the following operations: output that data corruption and / or data tampering has occurred; initiate an immobilisation procedure for the vehicle; and open contactors on the vehicle to disengage the battery from the vehicle.
10. A vehicle comprising a first control system as in any one of claims 1 to 7 and / or a second control system as in claim 8 or 9.11 . A vehicle as in claim 10 wherein the first control system is comprised in a Wireless Gateway Module and the second control system is comprised in a Battery Management Controller Module.
12. A method performed by a first control system for a vehicle, the method comprising: sending a sequence of messages to a second control system in the vehicle, for use by the second control system in controlling a battery of the vehicle; and periodically applying an authentication process to selected messages in the sequence of messages that allows the second control system to authenticate that the selected messages in the sequence originate from the first control system; wherein a first time period between each selected message is less than a second time period associated with a failure condition of the battery.
13. A method performed by a second control system for a vehicle, the method comprising: receiving a sequence of messages from a first control system, the sequence of messages being for use by the second control system in controlling a battery of the vehicle; wherein periodic selected messages in the sequence of messages have an authentication process applied to them that allows the second control system to authenticate that the respective selected messages originate from the first control system; andwherein a first time period between each selected message is less than a second time period associated with a failure condition of the battery.
14. Computer readable instructions which, when executed by a computer, are arranged to perform a method according to claim 12 or 13.
15. A computer-readable data carrier having stored thereon the computer readable instructions of claim14.
Citation Information
Patent Citations
Selective real-time cryptography in a vehicle communication network
US20200244442A1