Method for vehicle diagnosis, device for vehicle diagnosis, and vehicle
A counter system and protocol verification method secure vehicle diagnostics by limiting write operations and detecting unauthorized changes, enhancing safety and compliance.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2026-04-09
AI Technical Summary
Existing vehicle diagnostic procedures lack sufficient safety measures to prevent malicious use of write operations in fault memory and control units, potentially compromising vehicle integrity.
Implement a counter system to track write operations, generating an error message when the permissible number of writes is exceeded, and verify communication protocols using internal and external signals to ensure compliance with predefined communication standards.
Enhances the security and reliability of vehicle diagnostics by preventing unauthorized changes to fault memory and control units, ensuring compliance with regulatory protocols.
Smart Images

Figure EP2025076962_09042026_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Vehicle diagnostic procedure, vehicle diagnostic device and vehicle
[0003] The invention relates to a method for vehicle diagnostics and a device for vehicle diagnostics as well as a vehicle with at least one corresponding device.
[0004] During vehicle operation, error messages from the vehicle's control units are stored in a fault memory. These stored error messages can be read out as part of a vehicle diagnostic procedure. Such a vehicle diagnostic procedure may be legally required to comply with exhaust emission limits. For vehicle diagnostics, a communication protocol such as On-Board Diagnostics 2 (OBD-2) can be used.
[0005] In addition to reading the fault memory mentioned earlier, vehicle diagnostics may also involve writing data, for example, to clear the fault memory or to program a replaced control unit. In the worst-case scenario, these writing operations could be used for malicious purposes.
[0006] The technical problem is to create a procedure for vehicle diagnostics, a device for vehicle diagnostics, and a vehicle with at least one such device, which will increase the safety of the vehicle diagnostics.
[0007] The solution to the technical problem is provided by the articles with the features of the independent claims. Further advantageous embodiments of the invention are described in the dependent claims.
[0008] A procedure for vehicle diagnostics is proposed, comprising the following steps:
[0009] Providing at least one internal signal, wherein the at least one internal signal signals an actual communication protocol for vehicle diagnostics; receiving at least one external signal, wherein the at least one external signal signals a target communication protocol for vehicle diagnostics; outputting vehicle diagnostics when the actual communication protocol matches the target communication protocol; adjusting a counter when the received at least one external signal signals at least one write operation.
[0010] Generate at least one error message when the counter passes a threshold for a permissible number of write operations.
[0011] A further proposed device for vehicle diagnostics is presented, wherein the device is configured to perform a method according to an embodiment described in this disclosure. The device may, for example, be configured as or comprise a microprocessor.
[0012] A further proposal is for a vehicle comprising at least one device according to an embodiment described in this disclosure. The vehicle can be, for example, a passenger car or a truck.
[0013] The technical effects and advantages described in this disclosure for the process naturally also apply to the device and the vehicle, and vice versa.
[0014] The procedure has the technical effect of allowing an exceedance of the permissible number of write operations to be registered by means of at least one error message. This is achieved technically by counting each write operation triggered by an external signal using a counter and comparing the current counter value with the threshold. This improves the reliability of vehicle diagnostics.
[0015] The internal signal can be generated and provided by a control unit, such as the engine control unit. The provision of the internal signal can occur via an internal communication bus of the vehicle, such as a CAN bus. The internal signal can contain an encoding to indicate the current communication protocol. This encoding can be implemented, for example, by a high and / or low level on the internal communication bus. The device can include an interface for communication with the internal communication bus.
[0016] The default communication protocol can be, for example, OBD-2 or UDS. However, other communication protocols are also possible. The default communication protocol can be set at the factory, for example, by storing it in the ECU's memory. Which communication protocol is set as the default may be dictated by country-specific regulations. The default communication protocol can also be set at a vehicle manufacturer's plant at the end of the assembly line, i.e., shortly before the vehicle is completed.
[0017] It should be noted that a communication protocol other than the standard communication protocol can also be used for vehicle diagnostics. This alternative communication protocol can be used, for example, when the target communication protocol signals its use. By receiving the target communication protocol, the system can switch between a standard communication protocol, such as OBD-2, and the target communication protocol, such as OBD-on-UDS. This switch can be registered by adjusting the counter. This will be explained in more detail below.
[0018] The external signal can be generated and provided, for example, by an external diagnostic device. Receiving the external signal can occur, for example, via another communication bus, such as CAN, a K-bus, and / or an L-bus. Receiving the external signal can, for example, be done as part of vehicle diagnostics. The external signal can include an encoding to signal the target communication protocol. The external signal can also include a further encoding to signal the write operation. The encoding and / or further encoding of the external signal can be implemented, for example, by a high and / or low level on the other communication bus. The device can include an interface for communication with the other communication bus.
[0019] The target communication protocol can be set by the external diagnostic device or selected by the user of the diagnostic device from several possible communication protocols. The target communication protocol could be, for example, OBD-2 or UDS. However, other communication protocols are also possible. Which communication protocol is set or selected as the target communication protocol may be specified, for example, by country-specific regulations.
[0020] The vehicle diagnostic output can include a comparison of the external signal with the internal signal. For example, it can be checked whether the encoding of the internal signal matches the encoding of the external signal. The output can also include the authorization of at least one write and / or read operation. This can be achieved, for example, by generating an output signal.
[0021] In a write operation, for example, a fault memory or the memory of a control unit can be erased and rewritten. The write operation can include, for example, setting the target communication protocol as the actual communication protocol. This setting of the target communication protocol as the actual communication protocol can also be referred to as switching the communication protocol. The target communication protocol can be stored, for example, in the memory of the device and / or the vehicle. To store the target communication protocol as the actual communication protocol, the external signal can indicate at least one memory value. The write operation can, for example, be used to calibrate a newly installed or replaced control unit. The device or the vehicle can include the fault memory, the control unit, and / or the memory of the control unit.
[0022] Alternatively or cumulatively, the external signal can indicate a read operation, e.g., to read the error memory. The external signal can contain additional encoding that signals the read operation.
[0023] The counter can be updated by receiving an external signal or by a write operation. Updating the counter can be done, for example, by adding or subtracting at least one counter value from the current counter reading. This process can therefore be described as incrementing or decrementing. The counter value can be an integer, such as "1". The counter can be implemented on a microcontroller within the device.
[0024] By adjusting the counter, it is particularly possible to register every switch between multiple available communication protocols.
[0025] The error message can be generated by the device, for example. The error message can be stored in the vehicle's fault memory, for example. The error message can trigger the engine warning light to illuminate. For example, the engine warning light can remain illuminated if the counter exceeds the threshold for the permissible number of write operations. The threshold can be a maximum value. Exceeding the maximum value can be described as exceeding it. The maximum value can be an integer, for example, "5". The maximum value can be known in advance. In particular, no further vehicle diagnostics output can be generated if the counter exceeds the maximum value for the permissible number of write operations. Furthermore, a write operation can no longer be permitted if the counter exceeds the maximum value for the permissible number of write operations. Alternatively, the threshold can also be a minimum value.Passing the minimum value can be described as falling below it.
[0026] It should be noted that providing the internal signal and / or outputting the vehicle diagnostics can be optional features of the proposed procedure. The essential point is that the write operations are counted by receiving the external signal and the error message is generated depending on the counter value.
[0027] In another embodiment, the actual communication protocol and / or target communication protocol is OBDonUDS or ZEVonUDS. These communication protocols require a particularly high level of security for vehicle diagnostics, which is provided by the present invention. This is because, compared to conventional communication protocols, OBDonUDS or ZEVonUDS allow write operations that can result in particularly profound changes to the vehicle's fault memory and control units.
[0028] In another embodiment, the at least one external signal is received via at least one vehicle diagnostics interface. This allows the external signal to be received, for example, as part of a vehicle diagnostics check. This simplifies the output of the vehicle diagnostics, as no additional interface is required to receive the external signal. The device can include the at least one vehicle diagnostics interface. This interface can, for example, be an OBD-II port.
[0029] In one embodiment, the at least one write operation only occurs if the external signal has been verified beforehand. This further increases the security of vehicle diagnostics, as no write and / or read operations can be permitted without verification. The at least one external signal can, for example, signal a verification key. For this purpose, the external signal can have an additional encoding. Conversely, the internal signal can signal a lock for the verification key. For this purpose, the internal signal can also have an additional encoding. It is also possible that another external signal signals the verification key and / or another internal signal signals the lock. The at least one additional external signal can, for example, be provided by the diagnostic device. The at least one additional internal signal can, for example,The external signal can be provided by the device or the vehicle. The external signal can be verified when the verification key opens the lock. The device can be configured to verify the received external signal. The verification key corresponding to the lock can, for example, be generated by a vehicle manufacturer and provided to an authorized diagnostic service provider. For this purpose, the vehicle and the external diagnostic device can communicate with an external server of the manufacturer. This ensures that only authorized diagnostic service providers receive write access. A possible verification method is, for example, SFD-Basic or SFD Level 2.
[0030] In one embodiment, the counter is stored on at least one memory, wherein the at least one memory is not writable by the at least one external signal. This ensures that the counter is not reset by the external signal. The device can include the memory. The memory is, in particular, non-volatile memory, so that the counter cannot be reset, for example, by switching off the device or the vehicle. The memory can, for example, be flash memory.
[0031] In one embodiment, the counter is reset when at least one memory chip is flashed. This allows the counter to be reset safely while simultaneously flashing new software or firmware. The counter can, for example, be reset to a predefined reset value. This reset value could be, for example, "0" or "1" or any other counter value. Resetting the counter can, in particular, clear the error message generated when the threshold is exceeded.
[0032] In one embodiment, the counter is reset when at least one verified reset signal is received. This allows the counter to be reliably reset as needed. The reset signal can be provided, received, and verified analogously to the external signal, mutatis mutandis. Alternatively, the reset signal can be provided, received, and verified by the device itself.
[0033] In one embodiment, at least one additional error message is generated if the target communication protocol does not match the actual communication protocol. This allows the system to detect that the received target protocol does not correspond to the actual protocol. The additional error message can, for example, be stored in the vehicle's fault memory.
[0034] The invention is explained in more detail using exemplary embodiments. The figures show:
[0035] Fig. 1 shows a schematic representation of an embodiment of a vehicle with a device for vehicle diagnostics and
[0036] Fig. 2 shows a schematic representation of another embodiment of a vehicle with a vehicle diagnostic device.
[0037] In the following, identical reference symbols denote elements with the same technical characteristics.
[0038] Fig. 1 shows a schematic representation of an embodiment of a vehicle 200 designed as a passenger car with a device 100 for vehicle diagnostics. The device 100 has a microcontroller (not shown) and is configured to perform a method for vehicle diagnostics. The method comprises the steps described below.
[0039] In step S1, an internal signal 10 is provided. This internal signal 10 is generated, for example, by a control unit 210 of the vehicle 200. The control unit 210 could, for example, be the engine control unit of the vehicle 200. The internal signal 10 is communicated via an internal communication bus 220 of the vehicle 200, configured as a CAN bus, to an interface 11 of the device 100. The internal signal 10 indicates a current communication protocol for vehicle diagnostics, for example, OBDonllDS. The current communication protocol may have been factory-defined for the vehicle 200 and may be permanently stored, for example, in a memory (not shown) of the control unit 210. However, at least one other communication protocol besides the current communication protocol may be stored in the memory of the control unit 210 and / or in another memory (not shown).The other communication protocol only replaces the current communication protocol when this is specified by a target communication protocol.
[0040] For vehicle diagnostics, an external diagnostic device 300 is connected to a diagnostic interface 230 of the vehicle 200, which is configured as an OBD-2 port. The external diagnostic device 300 can also be referred to as a tester. Vehicle diagnostics can be performed, in particular, by a government authority—such as the police—of the country in which the vehicle 200 is registered, or by a customer service center. The external diagnostic device 300 can be verified, for example, by the manufacturer of the vehicle 200. For this purpose, a verification key 420 can be provided to the external diagnostic device 300 via an external server 400 of the manufacturer. Simultaneously, a lock symbol 410 can be provided to the control unit 210 of the vehicle 200 via the external server 400 for verification purposes.
[0041] An external signal 20 can be generated by the external diagnostic device 300 and provided via a further communication bus 240 of the vehicle 200, configured as a K-bus. The external signal 20 indicates a target communication protocol for vehicle diagnostics, e.g., OBDonllDS. For verification purposes, the external signal 20 can be encoded with the verification key 420. The internal signal 10, on the other hand, can be encoded by the control unit 210 with the lock 410 for this purpose.
[0042] Additionally, the external signal 20 can also signal a write operation. This write operation can, for example, result in the deletion of a fault memory 250 of the vehicle and / or switch the actual communication protocol to the target communication protocol. Alternatively or cumulatively, the external signal 20 can, of course, also signal a read operation. This read operation can, for example, result in the reading of the fault memory 250 of the vehicle.
[0043] In step S2, the external signal 20 is received via an interface 21 of the device 100.
[0044] In step S3, vehicle diagnostics are output if the actual communication protocol matches the target communication protocol. For example, the encoding of the internal signal 10 is compared with the encoding of the external signal 20. The external signal 20 can be further verified in step S3 (not shown) by checking whether the verification key 420 opens the lock 410. If the communication protocols match and the external signal 30 is verified, the result of step S3 is "Yes". In this case, the device 100 can generate an output signal 30 and communicate with the diagnostic interface 230 via the further communication bus 240. Alternatively, in step S3, vehicle diagnostics can be output using the actual communication protocol if the actual communication protocol does not match the target communication protocol.
[0045] If, however, the target communication protocol does not match the actual communication protocol, the result of step S3 is "No". In this case, device 100 can generate an error message 55 and output it via interface 12. The error message 55 is then communicated, for example, via the internal communication bus 220 to the error memory 250 and stored there. In this way, attempts to communicate with vehicle 200 using a different communication protocol than the actual communication protocol can be registered.
[0046] In step S4, a computer-implemented counter 40 can be incremented. This includes a sub-step S41, in which it is checked whether the external signal 20 indicates a write operation. This is represented in Fig. 1 by a pen and a piece of paper. For verification, for example, another encoding of the external signal 20 can be compared with an encoding known for permissible write operations. If the external signal 20 indicates a write operation, the result of sub-step S41 is "Yes". In a further sub-step S42, the counter 40 is then incremented by the integer "+1". For example, the counter value of counter 40 increases from the counter value "4" to the counter value "5", since four permissible write operations have already been counted during previous vehicle diagnostics.If the external signal 20 does not indicate a write operation, the result of sub-step S42 is "No", and the counter 40 is not incremented in the subsequent sub-step S42. This is indicated by a "+0" in Fig. 1. In this way, the signaled write operations can be recorded.
[0047] Alternatively, in step S4 the counter can be decremented by 40 (not shown) and, for example, counted down from a starting value to a minimum value until the minimum value is undershot.
[0048] The counter value of counter 40 can be permanently stored in a flash memory 60. Flash memory 60 is not writable by the external signal 20. This means that flash memory 60 cannot be erased or modified by the external signal 20. Therefore, counter 40 cannot be manipulated by the external signal 20. In step S5, an error message 50 is generated if counter 40 exceeds a maximum value 45 for a permissible number of write operations. For this purpose, the current counter value of counter 40 is provided from flash memory 60. Alternatively or cumulatively, the current counter value can be provided from a working memory of the device 100 (not shown). The maximum value 45 can, for example, be "4". Of course, step S5 can alternatively include checking whether counter 40 is greater than or equal to the maximum value 45 for a permissible number of write operations.In such a case, the maximum value 45 would correspond to "5". In the embodiment shown in Fig. 1, the counter 40 exceeds the maximum value 45, so the result of step S5 is "Yes" and the error message 50 is generated. If, however, the counter 40 does not exceed the maximum value 45, the result of step S5 is "No" and the process can end at this point.
[0049] The generated error message 50 can be output via an interface 13 of the device 100. The error message 50 is then communicated, for example, via the internal communication bus 220 to the fault memory 250 and stored there. In this way, an exceedance of the permissible number of write operations is registered. The error message 50 can, for example, cause the engine control light of the vehicle 200 to illuminate and display the error message 50. This is indicated in Fig. 1 by a symbol of the engine control light.
[0050] Since counter 40 is stored in memory 60 in a tamper-proof manner, error message 50 is still generated even if error memory 250 has been cleared, for example, as part of a tampering process. This makes vehicle diagnostics particularly secure.
[0051] Fig. 2 shows a schematic representation of another embodiment of a vehicle 200 designed as a passenger car with a device 100 for vehicle diagnostics. In contrast to Fig. 1, Fig. 2 shows how a counter 40 can be reset.
[0052] The current reading of meter 40 is stored on a memory 60 designed as flash memory.
[0053] A reset signal 80 can be generated, for example, by means of a diagnostic device 300 connected to the vehicle 200. The generated reset signal 80 can signal a flashing of the memory 60. The diagnostic device 300 can be verified, for example, via an external server 400 of the manufacturer. This allows the external diagnostic device 300 to encode the verified reset signal 80 with a verification key 420. The device 100 can receive the reset signal 80 via an interface 21.
[0054] The device 100 can be configured to verify the received reset signal 80 in step S6. For verification purposes, a further signal 70, encoded with a lock 410, can be generated by a control unit 210 of the vehicle 200 and provided to the device 100 via an interface 11. In step S6, it can be checked, for example, whether the encoding of the received reset signal 80 matches the encoding of the further signal 70. If this is the case, the result of step S6 is "Yes". In this case, the memory 60 can be flashed using the reset signal 80, and, for example, new firmware can be uploaded to the device 100.
[0055] By flashing memory 60, counter 40 is reset to a value of 0.
[0056] If, however, the result of step S6 is "No"—i.e., the encoding of the received reset signal 80 does not match the encoding of the subsequent signal 70—the device 100 can generate a further error message 56 and output it via an interface 12. This further error message 56 is then communicated, for example, via an internal communication bus 220 to a fault memory 250 of the vehicle 200 and stored there. In this way, unverified reset attempts can be registered.
[0057] Furthermore, the reset signal 80 can also be used to change the permissible number of write operations. For example, a maximum value of 45 stored in memory 60 can be adjusted from "4" to "2". This can be useful if, for example, stricter legal regulations restrict the number of write operations to two instead of four. Other internal or external signals (not shown) can also be used to adjust the maximum value.
[0058] Reference symbol list
[0059] 10 internal signal
[0060] 11 to 13 Interface for communication with an internal communication bus
[0061] 20 external signal
[0062] 21 the interface for communication with another communication bus
[0063] 30 Output signal
[0064] 40 counters
[0065] 45 maximum value
[0066] 50 error messages
[0067] 55 more error messages
[0068] 56 more error messages
[0069] 60 storage
[0070] 70 more signals
[0071] 80 Reset signal
[0072] 100 Device
[0073] 200 vehicles
[0074] 210 Control unit
[0075] 220 internal communication bus
[0076] 230 Interface for vehicle diagnostics
[0077] 240 additional communication buses
[0078] 250 fault memory
[0079] 300 diagnostic device
[0080] 400 external servers
[0081] 410 Lock for verification
[0082] 420 verification keys
[0083] S1 step
[0084] S2 step
[0085] S3 step
[0086] S4 step
[0087] S41 Substep
[0088] S42 Substep
[0089] S5 step
[0090] S6 step
Claims
Patent claims 1. Vehicle diagnostic procedure, comprising the following steps: Providing (S1) at least one internal signal (10), wherein the at least one internal signal (10) signals an actual communication protocol for vehicle diagnostics, Receiving (S2) at least one external signal (20), wherein the at least one external signal (20) signals a target communication protocol for vehicle diagnostics, - Output (S3) of the vehicle diagnostics when the actual communication protocol matches the target communication protocol, - Adjusting (S4) a counter (40) if the received at least one external signal (20) signals at least one write operation, Generate (S5) at least one error message (50) when the counter (40) passes a threshold (45) for a permissible number of write operations.
2. Method according to claim 1, characterized in that the actual- The communication protocol and / or the target communication protocol is OBDonllDS or ZEVonUDS.
3. Method according to one of the preceding claims, characterized in that the reception (S2) of the at least one external signal (20) is carried out via at least one interface (230) for vehicle diagnostics.
4. Method according to one of the preceding claims, characterized in that the at least one writing operation only takes place if the external signal (20) is verified.
5. Method according to one of the preceding claims, characterized in that the counter (40) is stored on at least one memory (60), wherein the at least one memory (60) is not writable by the at least one external signal (20).
6. Method according to claim 5, characterized in that the counter (40) is reset when the at least one memory (60) is flashed.
7. Method according to one of the preceding claims, characterized in that the counter (40) is reset when at least one verified reset signal (80) is received.
8. Method according to one of the preceding claims, characterized in that at least one further error message (55) is generated if the target communication protocol does not match the actual communication protocol.
9. Device (100) for vehicle diagnostics, wherein the device (100) is configured to perform a method according to any one of claims 1 to 8.
10. Vehicle (200) comprising at least one device (100) according to claim 9.
Citation Information
Patent Citations
Vehicle diagnostic tool with copy protection and automatic identification of vehicle ECUS and fault display
CA2692530A1
vehicle diagnostic device and system
DE102016201674A1
Electronic control unit and control method for storing a rewrite count of a non-volatile memory
DE19934191B4
Predictive Management of Failing Portions in a Data Storage Device
US20210073063A1
Method for configuring a control device for a vehicle
WO2025146349A1