Method for preventing the execution of malicious code on a control device
The method interrupts and checks the authorization of programs on a microcontroller within control units, effectively preventing malicious code execution using existing hardware, thus enhancing security without additional hardware modules.
Patent Information
- Application Number
- PCT/EP2024/083119
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-22
- Filing Date
- 2024-11-21
- Publication Date
- 2025-05-30
AI Technical Summary
Existing control units lack effective methods to detect and prevent the execution of malicious code without relying on additional hardware security modules.
A method that interrupts the current program on a microcontroller with a high-speed interrupt, checks if the program is authorized using a whitelist, and prevents further execution if it is not registered as authorized.
This method reliably detects and prevents the execution of malicious code using existing hardware, ensuring the security of control units without the need for additional hardware security modules.
Smart Images

Figure EP2024083119_30052025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] title
[0003] Method for preventing the execution of malicious code on a control unit
[0004] The invention relates to a method for detecting malicious code and preventing the execution of the malicious code on a control unit. The invention also relates to a control unit for implementing the method, to a vehicle with a corresponding control unit, and to a computer program product with program code for executing the method.
[0005] State of the art
[0006] DE 102007 004 794 A1 describes a microcontroller with watchdog monitoring. The microcontroller comprises a computing unit and an addressable port module, each connected to an internal controller address and data bus. Computational tasks are performed in the microcontroller, the results of which are used to verify the correct functioning of the computing unit.
[0007] DE 102009 045 000 A1 describes a method for ensuring error-free data output from a data processing unit to a data bus. If faulty operation of the
[0008] If a data processing unit is detected by a monitoring unit independent of the data processing unit, the output of data from the data processing unit to a data bus is blocked.
[0009] Disclosure of the invention The invention describes a method for detecting malicious or foreign code in the form of an unauthorized program or software and preventing the malicious code from being executed on a control unit, for example a control unit in a vehicle, for example an airbag control unit. In the method, a program that is currently running on a microcontroller of the control unit is interrupted by means of an interrupt (interruption request), wherein the interruption is limited to a maximum duration. A check is carried out to determine whether the interrupted program is registered as an authorized program. If this is the case, i.e. the program is registered as an authorized program, the program is resumed or continued. If, on the other hand, the program is not registered as an authorized program, further execution of the interrupted program is prevented.
[0010] This method has the advantage of reliably detecting malicious code on the control unit and preventing its execution. This can be done without a hardware security module. Rather, it is sufficient to use the existing hardware to detect and deactivate the malicious code. The method can be implemented in the form of a computer program product with program code, i.e., in the form of software on the control unit.
[0011] The method preferably sets a high-speed interrupt that is fast enough to prevent permanent manipulation of the software on the control unit. For example, it can prevent malicious code from being written to a read-only memory (ROM) of the control unit and thus becoming permanently embedded in the control unit. Furthermore, the method can either prevent unauthorized transmission via a data line, or the faulty transmission is too short to lead to an undesired response in a receiving device. The maximum duration of the interrupt is, in particular, 1 msec, or 0.5 msec.
[0012] The interrupt is used to check which program was interrupted. This is usually sufficient for detecting the malicious code and generally leads to sufficiently reliable detection of the malicious code. In systems without program execution in RAM (electronic internal memory), this can be easily performed with a software query, particularly using a list of permitted programs (whitelist). The whitelist can be used to allow defined RAM areas to be accepted for execution. The whitelist can be limited to ROM areas if RAM program execution is not intended.
[0013] Additionally or alternatively, a stack is considered, which indicates the state of the currently called subroutines during runtime of the program under consideration. The stack can be examined via a return address or, if necessary, via a more complex analysis.
[0014] If an unauthorized program is detected during the interrupt, a restart or reset of the microcontroller can be performed to prevent further execution. The detection of an unauthorized program can optionally lead to a configurable error response, for example, an error entry that can be displayed and / or saved and read out as needed. The unauthorized program can be transferred to a secure state. To counter a systematic attack, it may be useful to suspend the diagnostics for detecting malicious code for several execution cycles after detecting an unauthorized program and / or to deactivate communication channels in the control unit.
[0015] According to yet another advantageous embodiment, the request to interrupt the program is generated via a hardware interrupt request (HW IRQ). Accordingly, the interrupt is generated via hardware configured for this purpose. Alternatively, it is also possible to generate the request to interrupt the program via an external, independent interrupt.
[0016] Furthermore, it is possible for a hardware memory protection unit (MPU) to generate the interrupt to interrupt the program. This can be implemented redundantly if no other interrupt request can be provided. RAM program execution can be excluded in the MPU.
[0017] To implement a watchdog function, a safety microcontroller can reset the control unit's microcontroller if the interrupt cannot be executed.
[0018] Furthermore, it may be useful to monitor the interrupt via a hardware security module acting as a watchdog. This ensures the interrupt's functionality and ensures that the interrupt's interrupt function is running.
[0019] According to yet another advantageous embodiment, the interrupt is executed each time a program is started on the control unit's microcontroller. This allows each executed program to be monitored for validity.
[0020] The invention also relates to a control unit that contains means designed to carry out the method described above. The means comprise at least one memory unit, at least one microcontroller as a computing unit, a control unit input, and a control unit output.
[0021] The control unit can be used to control adjustable components of a system in a vehicle, for example an airbag system or a driver assistance system.
[0022] The invention further relates to a computer program product with a program code designed to execute the method steps described above. The computer program product runs in the control unit described above.
[0023] Further advantages and expedient embodiments can be found in the further claims, the description of the figures and the drawing, in which a control unit is schematically shown in which a method for detecting malicious code and preventing the execution of the malicious code runs.
[0024] The control unit 1 shown in the figure is, by way of example, the control unit of an airbag system in a vehicle, wherein the airbag deployment function is controlled via the control unit 1. The control unit 1 comprises a microcontroller 2 as a computing unit, in which various programs run. These are control programs for controlling the sequence of the control unit 1 and function programs for controlling the function of the airbag.
[0025] For security reasons, a method for detecting malicious code and preventing its execution is implemented in control unit 1. Malicious code refers to unauthorized programs or software that have entered control unit 1 without permission. This method makes it possible to identify malicious code and prevent its execution without additional hardware, in particular without a hardware security module. The existing hardware in control unit 1 can be used to detect and deactivate the malicious code. The method is implemented in the form of a computer program product with a program code on control unit 1.
[0026] In this method, a program currently running on microcontroller 2 of the control unit is interrupted using an interrupt, with the interruption being limited to a maximum duration. A check is performed to determine whether the interrupted program is registered as an authorized program. If this is the case, i.e., the program is registered as an authorized program, the program is resumed or continued. If, however, the program is not registered as an authorized program, further execution of the interrupted program is prevented.
[0027] This approach has the advantage of reliably detecting malicious code on the control unit and preventing its execution. This can be done without a hardware security module. Rather, it is sufficient to use the existing hardware to detect and deactivate the malicious code. The method can be implemented in the form of a computer program product with program code, i.e., in the form of software on control unit 1.
[0028] In this method, a program currently running on microcontroller 2 of control unit 1 is interrupted using a high-speed interrupt. The interrupt duration is a maximum of 0.5 ms. The interrupt is fast enough to prevent permanent manipulation of the software on control unit 1. In particular, it can prevent malicious code from being written to the read-only memory (ROM) 3 of control unit 1. Unauthorized transmission over a data line can also be prevented.
[0029] During the interrupt, the program being interrupted is checked. This check is performed using a software query based on a whitelist. The whitelist can be used to allow defined areas of RAM 4 to be accepted for program execution. The whitelist can be limited to areas of ROM 3 if RAM program execution is not permitted.
[0030] Additionally or alternatively, a stack memory called Stack 6 is considered, which indicates the state of the currently called subroutines during program runtime. Stack 6 can be examined via a return address or, if necessary, via a more complex analysis.
[0031] The request to interrupt the program can be generated via a hardware interrupt request. It is also possible to perform the request to interrupt the program via an external, independent interrupt.
[0032] If an unauthorized program is detected during the interrupt, a restart or reset can be performed in microcontroller 2 to prevent further execution. Furthermore, a hardware Memory Protection Unit (MPU) 5 can generate the interrupt to interrupt the program. This can be implemented redundantly if no other interrupt request can be provided. RAM program execution can be prevented in the MPU 5.
[0033] To implement a watchdog function, a safety microcontroller 7 can reset the microcontroller 2 of the control unit 1 if the interrupt cannot be executed.
[0034] The interrupt is preferably executed each time a program is started on the microcontroller 2 of the control unit 1. This allows each executed program to be monitored for validity.
Claims
Claims 1. A method for detecting malicious code and preventing the execution of the malicious code on a control unit (1), comprising the following steps: Interrupting a program currently running on a microcontroller (2) of the control unit (1) by means of an interrupt, the interruption being limited to a maximum duration, Check whether the interrupted program is registered as an authorized program, Prevent further execution of the interrupted program if the program is not registered as an authorized program, resume the program if the program is registered as an authorized program.
2. Method according to claim 1, characterized in that the maximum duration of the interruption is 1 msec, preferably 0.5 msec.
3. Method according to claim 1 or 2, characterized in that the check as to whether the interrupted program is registered as an authorized program is carried out using a stack (6).
4. Method according to one of claims 1 to 3, characterized in that the check as to whether the interrupted program is registered as an authorized program is carried out on the basis of a whitelist in the ROM (3) of the control unit (1).
5. Method according to one of claims 1 to 4, characterized in that the request to interrupt the program is generated via a hardware interrupt request.
6. Method according to one of claims 1 to 4, characterized in that the request to interrupt the program is generated via an external, independent interrupt.
7. Method according to one of claims 1 to 6, characterized in that a memory protection unit (5) generates the request to interrupt the program.
8. Method according to one of claims 1 to 7, characterized in that the method runs on a control unit (1) which allows no or only limited program execution on an internal data memory (4) of the control unit (1).
9. Method according to one of claims 1 to 8, characterized in that, in the event that the interrupt cannot be executed, a safety microcontroller (7) resets the microcontroller (2) of the control unit (1).
10. Method according to one of claims 1 to 9, characterized in that the interrupt is monitored via a hardware-side security module.
11. Method according to one of claims 1 to 10, characterized in that in the case of preventing further execution of the interrupted program, an error reaction takes place, for example an error entry.
12. Method according to one of claims 1 to 11, characterized in that the interrupt is executed each time a program is started on the microcontroller (2) of the control unit (1).
13. Control unit, in particular airbag control unit, containing means designed to carry out the method according to one or more of the preceding claims.
14. Vehicle having a control unit according to claim 13.
15. A computer program product comprising a program code designed to carry out steps of the method according to any one of claims 1 to 12, if the computer program product runs in a control device (1) according to claim 13.
Citation Information
Patent Citations
controller module with monitoring by a watchdog
DE102007004794A1
Method and data output monitoring unit for ensuring error-free data output from a data processing unit to a data bus
DE102009045000A1
Program check system
JP1998040177A
Storage device of game device, writing device and method therefor, and device and method for controlling game device
JP1999276704A
Memory management method and device in a multitasking capable data processing system
US20120042324A1