Anti-intrusion device for an on-board system, in particular integrated in a motor vehicle

The anti-intrusion device for on-board systems uses ultrasonic waves and signal comparison to detect physical breaches, enhancing the protection of vehicle electronic control units against physical attacks and ensuring system integrity.

WO2025132674A1PCT designated stage expired Publication Date: 2025-06-26AMPERE SAS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/087244
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-22
Filing Date
2024-12-18
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing anti-intrusion methods for on-board systems in vehicles, such as electronic control units, are inadequate in protecting against physical attacks that can compromise the integrity of the system and access confidential information.

Method used

An anti-intrusion device that emits ultrasonic waves and uses a control unit to compare the emitted signals with reference signals, detecting any breaches in the system's integrity through changes in the wave patterns caused by physical modifications.

Benefits of technology

The device effectively prevents physical intrusions into vehicle computers by detecting any mechanical modifications, such as drilling, and ensuring the integrity of the entire electronic card and interfaces between semiconductors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024087244_26062025_PF_FP_ABST
    Figure EP2024087244_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to an anti-intrusion device intended to be integrated in an on-board system, in particular in an electronic control unit, the on-board system being in particular integrated in a motor vehicle, the device including an element for emitting ultrasonic waves, the device including or being connected to a control unit configured to receive a signal resulting from the emission of the ultrasonic waves by the element and to compare this signal with a reference signal in order to detect a possible break in the integrity of the on-board system.
Need to check novelty before this filing date? Find Prior Art

Description

Description Title of the invention: Anti-intrusion device for an on-board system, in particular integrated into a motor vehicle Technical field

[0001] The present invention relates to an anti-intrusion device intended to be integrated into an on-board system, in particular into an electronic control unit, the on-board system being in particular integrated into a motorized vehicle. Prior art

[0002] Modern vehicles include electronic control units (ECUs) containing increasingly complex and powerful computing processors, and memories storing increasingly confidential “DATA” information, such as user data under GDPR, advanced driver assistance algorithms and systems under intellectual property, security keys for diagnostics or remote updates.

[0003] Such an electronic control unit "A" is shown in [Fig.1]. It consists of printed circuit boards "CI", printed circuit board connectors "CO", electronic components "B", internal buses "C", a housing "D" and an external interface "E". An attacker with physical access to the system, placed in the vehicle or extracted from the vehicle, can attack it in several ways. He can remove or cut the mechanical housing. He can gain access to confidential information stored on the electronic chip by using an invasive attack on the silicon. The attacker can eavesdrop on and / or tamper with the internal signals and buses. He can replace the genuine chip with a bad chip to trigger malicious behavior.

[0004] Vehicles already incorporate mechanisms to protect them against attacks originating from the internal network, or from external elements, known as "offboard", for example gateway mechanisms, proxy, or a "VLAN" type system, for virtual local area network. However, attackers with significant financial resources can carry out physical attacks on electronic boards and their semiconductors, and succeed in recovering various data.

[0005] These attackers can directly recover confidential information, for example stored in memories containing a one-time password, the English acronym of which is "OTP" of the semiconductor, i.e. fuses, allowing the decryption of normally secure data (user data, firmware), or to amplify their attacks to an entire fleet of vehicles (recovery of a non-diversified MAC key used for updating, unlocking functions, etc.). debugging and tamper-evident capabilities). They can also retrieve information that is not directly confidential, but which allows them to understand how the system works and improve the attacker's knowledge, then allow them to generalize their attack to all vehicles after dismantling a single ECU.

[0006] These attack methods are now partially resolved by semiconductors made more robust with complementary systems such as Secure Storage, RPMB, or integrated HSMs, but the problem is not completely resolved, as attackers can generally reread OTP memories through physical attacks.

[0007] It is still possible for the attacker to remove or cut the mechanical box "D" to gain physical access "AP", so that he can access confidential information:

[0008] - using invasive “AI” attacks on the silicon stored on the chip of the electronic component “B”, and / or

[0009] - by intercepting or falsifying “IF” signals or internal buses “C”, and / or

[0010] - replacing the genuine chip with a parasitic “PP” chip to trigger malicious behavior.

[0011] Known methods still focus on countermeasures at the semiconductor level, particularly on metallization layers, with voltage or capacitive measurements, micro-mesh, but do not allow the protection of a complete electronic card, nor the interfaces between several semiconductors.

[0012] Other known methods implement techniques such as "anti-tamper switches" (anti-tamper switches, infrared, pressure sensors, capacitive sensors), or use infrared illumination when a housing is light-tight. These devices are less robust, and an attacker can easily bypass them after X-raying the protected system.

[0013] Techniques have also been developed in the field of radio frequencies, but they consume a lot of electrical energy and require significant volumes and modifications to the systems, in particular the addition of a Faraday cage, thus not allowing operation suitable for a system on board a vehicle. Statement of the invention

[0014] There is therefore a need to further improve the means of ensuring the integrity of on-board systems, in particular electronic control units integrated into a motor vehicle. Summary of the invention Anti-intrusion device

[0015] The present invention meets this need thanks to, according to one of its aspects, an anti-intrusion device intended to be integrated into an on-board system, in particular into an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the device comprising an element for emitting ultrasonic waves,

[0016] the device comprising or being connected to a control unit configured to receive a signal resulting from the emission of ultrasonic waves by said element and to compare it to a reference signal in order to detect a possible breach of the integrity of the on-board system.

[0017] Thanks to the invention, physical intrusions into the vehicle's computers can be prevented. The invention makes it possible to protect an entire electronic card, as well as the interfaces between several semiconductors.

[0018] When the attacker performs a drilling or any other mechanical modification, the transmitted waves are modified compared to their reference state, due to destructive or constructive interference, or reflection. The received signal is modified; cross-correlation or artificial intelligence techniques can detect this integrity breach.

[0019] The invention allows the protection of a complete embedded system, i.e. an electronic card in its casing, with its semiconductors, against physical reverse engineering attacks, by an active mechanism capable of destroying confidential information if an intrusion is detected in the casing, or at least of being able to determine at a given moment whether the system has all its integrity or whether it could have been rendered non-integral in its life cycle, in particular by an attempt at dismantling.

[0020] Unlike known "anti-tampering" methods, which can be easily circumvented once the attacker has knowledge of the mechanism, the invention cannot be circumvented by an attacker, because the mechanical properties of the materials and the non-deterministic nature of the signal do not allow the attacker to reproduce it. The invention leaves very little room for maneuver to the attacker, even if he has prior knowledge of an identical system. Emitting element

[0021] In a preferred embodiment, the ultrasonic wave emitting element is a transducer configured to emit ultrasonic waves, being in particular a piezoelectric transducer, in particular of the PZT ceramic type.

[0022] In a first embodiment, said transducer is configured to emit ultrasonic waves into at least a portion of the material that constitutes the housing of the device. The waves advantageously propagate in the form of surface waves, called "Lamb waves", in the material.

[0023] This embodiment is based on mechanical transmission in the material of the device housing, for example ABS plastic or aluminum. It offers a more robust but more expensive solution, with more difficult coupling with the ultrasonic wave emitting element.

[0024] The device may be configured such that the frequency of reception of the ultrasonic waves is determined as a function of at least said material and / or a predefined temperature range.

[0025] In this embodiment, said transducer is advantageously further configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit. In a variant, the device may further comprise a receiving element configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit, said receiving element being in particular a transducer

[0026] In a second embodiment, said transducer is configured to emit ultrasonic waves inside the space defined by the housing of the on-board system, the waves being emitted in particular into the air or gas present in said space.

[0027] In this embodiment, the device is configured so that the ultrasonic waves propagate at a frequency between 30 kHz and 50 kHz, being in particular equal to 40 kHz.

[0028] Said transducer is advantageously further configured to receive the ultrasonic waves after their propagation within the space defined by the housing of the on-board system and to emit said resulting signal received by the control unit.

[0029] This embodiment uses wave propagation by acoustic transmission in the air or gas enclosed in the system housing, which contains the electronic card. This constitutes a lower cost solution, but not suitable for all mechanics, in particular due to the difficulty of integration in very compact and less robust housings.

[0030] Ultrasonic waves are advantageously reflected on the walls of the housing, printed circuits, connectors, fasteners, interact with each other in the form of constructive or destructive interference, then return to their starting point at the transducer. The signal received at the transducer thus depends on the geometry of the elements inside the housing, and on the geometry of the housing itself. As soon as an intrusion is carried out, for example by drilling the housing, removing a cover, inserting a probe, this geometry is modified, and a break in the mechanical integrity is therefore detected by processing the signal which returns to the transducer. Command and control units

[0031] The ultrasonic wave emitting element may comprise or be connected to a unit control system configured to send a train of waves, including Gaussian pulses, including pulses of a predefined duration, including at predefined or randomly defined intervals. This significantly reduces the amount of energy required by the device. The pulses can be modulated by random information. This increases the robustness of the anti-intrusion device.

[0032] Said control unit may be self-powered by an autonomous energy source internal to the device, in particular a battery. In a variant, the device is configured to erase any confidential information if the external power source is removed.

[0033] The control unit is advantageously configured to compare the signal resulting from the emission of the ultrasonic waves to a reference signal by implementing signal processing techniques, including cross-correlation, time correlation techniques, robust statistics or artificial intelligence. This makes it possible to detect differences in the signal, which mean that there has been a breach of integrity of the control medium, i.e. the housing that surrounds the embedded system in the first embodiment, or the air or gas that surrounds the electronic boards in the second embodiment. This means that an attacker has opened the housing, or inserted a probe through a small hole, or has significantly deformed the housing to access the electronics.

[0034] The control unit may include a field programmable gate array (FPGA), a complex programmable logic device (CPLD), a semiconductor, including an application-specific integrated circuit (ASIC), a microcontroller, or a DSP or signal processing microcontroller.

[0035] The control unit may be configured to transmit to at least one external system connected to the device the detection information of the possible breach of the integrity of the embedded system. These external systems may trigger actions, such as in particular sending a notification, recording an error code, deleting security keys or confidential information.

[0036] The control unit may be configured to receive reference signals resulting from the emission of ultrasonic waves by said emission element in order to carry out the calibration of the device, said reference signals being in particular stored in a non-volatile memory of the device. The device advantageously requires calibration at its start-up, as well as regular recalibration, for example if the material behaves very differently when the temperatures go towards extremes.

[0037] Calibration can be done in a controlled environment, such as a factory, or at predefined intervals during the device's life cycle, including every 24 hours.

[0038] When a breach of integrity is detected, various actions can be taken. If the system is powered externally, confidential information can be erased as soon as the power supply is lost, or if a breach of integrity is detected by the anti-intrusion device.

[0039] If the system is powered autonomously, in particular by battery or battery, the integrity breach can trigger various actions: switching to a specific system mode, in particular locking, erasing confidential information, replacing confidential information with a honeypot, self-protection of the system's inputs / outputs, in particular the deactivation of all electronic chip interfaces. The system can also record information to later report an incident, in particular an attempt to dismantle the embedded system to a security operations center, called "Security Operations Center" in English.

[0040] The device's control unit that performs signal processing can be the "root of trust" for integrity in the entire system, for example by having the control unit itself store confidential information rather than storing it in other processors in the system. If the control unit includes a so-called "secure element," such as a microcontroller with additional security guarantees, such as CC EAL7 certification, the robustness of the device is thus improved. Detection method

[0041] According to another of its aspects, the invention relates to a method for detecting the breakdown of the integrity of an on-board system, in particular an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the method using an anti-intrusion device according to any one of the preceding claims and comprising at least the following steps: - receive a signal resulting from the emission of ultrasonic waves by the emitting element of the device, and - compare said signal to a reference signal in order to detect a possible breakdown in the integrity of the on-board system.

[0042] The characteristics stated in relation to the device apply to the method and vice versa. Motor vehicle

[0043] According to another of its aspects, the invention relates to a motor vehicle comprising a powertrain and at least one electronic control unit comprising an anti-intrusion device according to the invention.

[0044] The characteristics stated in relation to the device apply to the vehicle and vice versa. Brief description of the drawings

[0045] The invention may be better understood by reading the detailed description which follows, a non-limiting example of its implementation, and by examining the attached drawing, in which

[0046] [Fig.l] [Fig.l], already described, represents an embedded system according to the prior art,

[0047] [Fig.2] [Fig.2], already described, represents an embedded system according to the prior art which is subject to attacks,

[0048] [Fig.3] [Fig.3] represents a first embodiment of the device according to the invention,

[0049] [Fig.4] [Fig.4] represents the device of [Fig.3] in the event of an attack,

[0050] [Fig.5] [Fig.5] represents a second embodiment of the device according to the invention, and

[0051] [Fig.6] [Fig.6] represents the device of [Fig.5] in the event of an attack. Detailed description

[0052] [Fig. 3] shows an anti-intrusion device according to a first embodiment of the invention, integrated in an electronic control unit, itself integrated in a motorized vehicle. The device 1 comprises an ultrasonic wave emission element 2, a transducer in the example considered, in particular a piezoelectric transducer, in particular of the PZT ceramic type. The device 1 comprises or is connected to a control unit 3 configured to receive a resulting signal “SRE” from the emission of ultrasonic waves by the transducer and to compare it to a reference signal “SRF” in order to detect a possible breach of the integrity of the on-board system.

[0053] In the example considered, the transducer 2 comprises or is connected to a control unit configured to send a wave train, in particular Gaussian pulses. The control unit is configured to compare the signal resulting from the emission of the ultrasonic waves to a reference signal by implementing signal processing techniques, in particular cross-correlation, time correlation techniques, robust statistics or artificial intelligence.

[0054] In this first embodiment, as visible in [Fig. 3], the transducer 2 is configured to emit ultrasonic waves in at least part of the material which constitutes the housing 4 of the device 1.

[0055] The device 1 according to the invention is configured so that the reception frequency of the ultrasonic waves is determined as a function of at least said material and / or a preset temperature range.

[0056] In the illustrated example, the transducer 2 is further configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit 3. In a variant not shown, the device 1 may further comprise a reception element configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit, said reception element being for example a transducer.

[0057] As visible in [Fig.4], as soon as an intrusion “INT” is carried out, for example by drilling the housing 4, removing a cover, inserting a probe, the geometry of the ultrasonic waves is modified, and a rupture “RUPT” of the mechanical integrity is therefore detected by processing the signal “SREm” which returns to the transducer 2.

[0058] The control unit 3 is advantageously configured to transmit to at least one external system connected to the device 1 the information detecting the possible breakdown of the integrity of the on-board system.

[0059] In the second embodiment illustrated in [Fig.5], the transducer 2 is configured to emit ultrasonic waves “WAVES” inside the space 5 defined by the housing 4 of the on-board system, the waves being emitted into the air or gas present in said space 5.

[0060] In this example, the device is configured so that the ultrasonic waves propagate at a frequency between 30 kHz and 50 kHz, being in particular equal to 40 kHz. The transducer 2 is further configured to receive the ultrasonic waves after their propagation inside the space 5 defined by the housing 4 of the on-board system and to emit said resulting signal received by the control unit 3.

[0061] The ultrasonic waves are reflected on the walls of the housing 4, the printed circuits, the connectors, the fasteners, interact with each other in the form of constructive or destructive interference, then return to their starting point at the level of the transducer 2. The signal received at the transducer 2 thus depends on the geometry of the elements inside the housing 4, and on the geometry of the housing itself. In the case of an attack, as shown in [Eig.6], as soon as an intrusion “INT” is carried out, for example by drilling the housing 4, removing a cover, inserting a probe, this geometry is modified, and a break in the mechanical integrity is therefore detected by processing the signal which returns to the transducer 2.

[0062] The invention is not limited to the examples which have just been described.

[0063] In particular, other ultrasonic wave emitting elements may be used.

[0064] The invention can be implemented in embedded systems not integrated into a motor vehicle, in so-called “offboard” solutions.

[0065] The invention can be used in the aeronautical or railway industry, for very different applications, in particular for non-destructive testing. ("Non-Destructive Testing") of structures, such as aircraft wings or railway tracks, in order to detect defects in materials, which can cause damage or accidents.

Claims

Claims

1. Anti-intrusion device (1) intended to be integrated into an on-board system, in particular into an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the device comprising an ultrasonic wave emission element (2), the device being characterized in that it comprises or is connected to a control unit (3) configured to receive a signal resulting from the emission of ultrasonic waves by said element (2) and to compare it with a reference signal in order to detect a possible breach of the integrity of the on-board system.

2. Device according to claim 1, in which the ultrasonic wave emitting element (2) is a transducer configured to emit ultrasonic waves, being in particular a piezoelectric transducer, in particular of the PZT ceramic type.

3. Device according to claim 2, wherein said transducer (2) is configured to emit ultrasonic waves into at least a portion of the material which constitutes the housing (4) of the device (1).

4. Device according to the preceding claim, configured so that the reception frequency of the ultrasonic waves is determined as a function of at least said material and / or a predefined temperature range.

5. Device according to any one of claims 3 or 4, wherein said transducer (2) is further configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit (3).

6. Device according to any one of claims 3 or 4, further comprising a receiving element configured to receive the ultrasonic waves after their propagation in the material and to emit said resulting signal received by the control unit (3), said receiving element being in particular a transducer.

7. Device according to claim 2, wherein said transducer (2) is configured to emit ultrasonic waves inside the space (5) defined by the housing (4) of the on-board system, the waves being emitted in particular into the air or gas present in said space (4).

8. Device according to the preceding claim, configured so that the ultrasonic waves propagate at a frequency between 30 kHz and 50 kHz, being in particular equal to 40 kHz.

9. Device according to any one of claims 7 or 8, wherein said transducer (2) is further configured to receive the ultrasonic waves after their propagation inside the space (5) defined by the housing (4) of the on-board system and to emit said resulting signal received by the control unit (3).

10. Device according to any one of the preceding claims, wherein the ultrasonic wave emitting element (2) comprises or is connected to a control unit configured to send a wave train, in particular Gaussian pulses, in particular pulses of a predefined duration, in particular at predefined or randomly defined intervals.

11. Device according to the preceding claim, in which said control unit is self-powered by an autonomous energy source internal to the device (1), in particular a battery.

12. Device according to any one of the preceding claims, wherein the control unit (3) is configured to compare the signal resulting from the emission of the ultrasonic waves to a reference signal by implementing signal processing techniques, in particular cross-correlation, temporal correlation techniques, robust statistics or artificial intelligence.

13. Device according to any one of the preceding claims, in which the control unit (3) comprises a programmable pre-broadcast circuit, a programmable complex circuit, a semiconductor, in particular an integrated circuit specific to an application, a microcontroller, or a signal processing microcontroller.

14. Device according to any one of the preceding claims, in which the control unit (3) is configured to transmit to at least one external system connected to the device (1), the information detecting the possible breakdown of the integrity of the on-board system.

15. Device according to any one of the preceding claims, wherein the control unit (3) is configured to receive reference signals resulting from the emission of ultrasonic waves by said emission element (2) in order to carry out the calibration of the device (1), said reference signals being in particular stored in a non-volatile memory of the device (1).

16. Method for detecting the breakdown of the integrity of an on-board system, in particular an electronic control unit, the on-board system being in particular integrated into a motorized vehicle, the method using an anti-intrusion device (1) according to any one of the preceding claims and being characterized in that it comprises at least the following steps: - receiving a signal resulting from the emission of ultrasonic waves by the emission element (2) of the device (1), and - compare said signal to a reference signal in order to detect a possible breakdown in the integrity of the on-board system.

17. Motor vehicle comprising a powertrain and at least one electronic control unit comprising an anti-intrusion device (1) according to any one of claims 1 to 15.

Citation Information

Patent Citations

  • Methodology and application of acoustic detection of optical integrity

    EP4102220A1

  • System and method for seal tamper detection for intelligent electronic devices

    US20050039040A1

  • Detection of a physical intrusion into a protective receptacle

    WO2015090714A1