Starting up a means of transportation during production
The method generates a signed installation list for control units during production, enabling secure and independent commissioning in vehicles, reducing production line dependencies and ensuring cybersecurity.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- VOLKSWAGEN AG
- Filing Date
- 2025-10-08
- Publication Date
- 2026-04-23
AI Technical Summary
Current methods for commissioning electronic control units (ECUs) in vehicles require an online connection to a backend system, leading to production line stoppages if the connection is unavailable, and do not allow for secure commissioning without external influence.
A method and computer program that generate an installation list for control units during production, which is stored in the vehicle and signed to ensure authenticity, allowing control units to verify their own identities and communicate securely without needing an online connection, enabling independent commissioning and authentication.
Enables secure and independent commissioning of control units in vehicles, reducing production line dependencies and ensuring cybersecurity without external manipulation, allowing for efficient assembly and function authorization.
Smart Images

Figure EP2025079042_23042026_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Commissioning of a means of transport in production
[0003] The present invention relates to a method and a computer program with instructions for supporting the commissioning of a means of locomotion in production. The invention further relates to a method and a computer program with instructions for commissioning a means of locomotion in production. The invention also relates to a control unit for a means of locomotion designed for these applications, as well as a means of locomotion with such a control unit.
[0004] In vehicles, the increasing degree of automation allows for greater relief for the driver. With highly automated driving, safety-relevant vehicle functions can be controlled by the vehicles themselves, but therefore must also be protected as effectively as possible against malfunctions and failures. For example, the control units of actuator systems for steering, accelerator pedal, and brakes, as well as the environmental sensors, represent critical system components that must be protected accordingly. For this reason, redundant systems are provided in the vehicle for such system components. These systems can take over the safety-relevant functions sufficiently well in the event of problems, ensuring that the vehicle can continue to be controlled safely even without human intervention and that the occupants are not endangered.
[0005] This is of great importance due to the increasing connectivity of vehicles. While wireless communication enables real-time information exchange between vehicles and between infrastructure and vehicles, as well as wireless updates and internet access for in-vehicle entertainment systems, it also creates a potential entry point for cyberattacks. The interfaces used for this purpose can have security vulnerabilities. This creates the risk that these vulnerabilities could be exploited to manipulate individual vehicles or even entire fleets remotely, potentially controlling them against the will of the driver. For this reason, the cybersecurity of software and hardware used in the automotive sector is becoming increasingly important.In this context, the vehicle control units (ECUs), of which a large number are installed in modern vehicles, represent a potential vulnerability, as they each contain their own software and are networked together, but do not necessarily possess sufficient computing power for comprehensive encryption. Therefore, authentication can be implemented for communication between multiple ECUs, enabling a receiving ECU to verify whether the sender of a signed message is indeed the ECU it claims to be.
[0006] Against this background, DE 102020 004 832 A1 describes a method for securely equipping a vehicle with an individual certificate, wherein the vehicle has at least one electronic control unit (ECU) and a communication unit configured to establish a connection between the ECU and an external server when required. The method establishes a vehicle certification authority and an ECU certification authority, each with its own public key infrastructure based on an asymmetric key pair, whereby the respective private key remains with the respective certification authority and the respective public key is distributed to the participants who require it.The control unit is equipped with initial cryptographic material by generating a control unit-specific key pair and transmitting the control unit's identity and its public key to the control unit certification authority. There, a control unit-specific certificate is generated for the transmitted data using the control unit certification authority's private key and transmitted back to the control unit. Furthermore, the vehicle certification authority's public key is stored securely within the control unit to prevent tampering. The vehicle identity associated with the control unit's identity is determined and stored securely to prevent tampering.
[0007] US 2023 / 0327886A1 describes a method for installing a certificate based on the encryption and decryption of a contract certificate's private key for an electric vehicle's communications control unit (CCU). The method involves the CCU sending a certificate installation request message to a secondary actor. The request message is signed with a private key associated with a manufacturer's provisioning certificate. The method also involves receiving a certificate installation response message from the secondary actor. The response message is signed with a private key associated with a leaf certificate of a certificate provisioning service (CPS).
[0008] Currently, the requirement for cryptographic keys in the vehicle's electronic control units (ECUs) is determined via configurations in the vehicle manufacturer's backend systems, and the respective cryptographic keys are also calculated there. Vehicle data is then entered, for example, via an online diagnostic connection directly to such a backend. This results in a synchronous dependency on the backend responsible for cybersecurity for ECU data entry during production, sales, and development. Vehicles can only be assembled on the production line with an online connection. A prolonged outage or unavailability of the backend can therefore lead to a worldwide production halt. Due to the necessary online connection to the backend, commissioning the ECUs in the production process, during which cryptographic information is to be exchanged, is only possible at a late stage.Since cryptographic keys are typically provided in packages from the backend, a production line stoppage can occur if a required package is not available in time. Commissioning of subassemblies, such as sub-assemblies, is also currently not possible.
[0009] One object of the invention is to provide suitable solutions for the commissioning of a means of transport in production.
[0010] This problem is solved by a method having the features of claim 1, by a method having the features of claim 6, by a computer program with instructions according to claim 13, by a control unit according to claim 14, and by a means of propulsion according to claim 15. Preferred embodiments of the invention are the subject of the dependent claims.
[0011] According to a first aspect of the invention, a method for supporting the commissioning of a means of transport in production comprises the following steps:
[0012] - Determining an installation list for the means of transport, which lists the types of control units to be installed in the means of transport; and
[0013] - Storing the installation list in at least one control unit of the means of transport.
[0014] According to another aspect of the invention, a computer program contains instructions which, when executed by a computer, cause the computer to perform the following steps to support the commissioning of a means of transportation in production:
[0015] - Determining an installation list for the means of transport, which lists the types of control units to be installed in the means of transport; and
[0016] - Storing the installation list in at least one control unit of the means of transport.
[0017] The term "computer" is to be understood broadly. In particular, it also includes workstations, distributed systems, and other processor-based data processing devices. Furthermore, the individual steps are not necessarily performed directly by the computer. It is equally possible that the computer controls or relies on external components to carry out individual steps.
[0018] The computer program can, for example, be made available for electronic retrieval or be stored on a computer-readable storage medium.
[0019] In the solution according to the invention, a component list is generated for each means of transport during or prior to production. This list contains the types of control units that are combined into a system within the means of transport. The component list enables the control units to check during subsequent commissioning whether the type of a connected control unit is listed in the component list. In this way, commissioning is possible without requiring an online connection to a backend system.
[0020] According to one aspect of the invention, the parts list for the means of transport includes an identifier for the means of transport. This ensures that the parts list is uniquely linked to the respective means of transport. The identifier can be, for example, the vehicle identification number, a provisional identification number, a production identifier, etc.
[0021] According to one aspect of the invention, the parts list is signed before it is stored in at least one control unit of the means of transport. Signing the parts list ensures that the safety of the means of transport cannot be compromised by a manipulated parts list.
[0022] According to one aspect of the invention, the component list is divided into confidence intervals. This division into confidence intervals makes it easy to represent the distribution of control units into sub-units. In practice, not all installed control units often communicate with each other. Furthermore, the control units can generally be assigned to specific functional areas, making a division into sub-units advantageous.
[0023] According to one aspect of the invention, the installation list includes information on approved functions. This allows control over which functions of the control units or the means of transport can be used in production. For example, the information may include access approval or driving approval for production.
[0024] According to another aspect of the invention, a method for commissioning a means of transport in production comprises the following steps:
[0025] - Check whether the vehicle's control units, which are grouped together, are listed in an installation list that is stored in at least one of the vehicle's control units;
[0026] - in the event of a positive test result, authentication of the control units; and
[0027] - upon successful authentication, commissioning of the control units.
[0028] According to another aspect of the invention, a computer program contains instructions which, when executed by a computer, cause the computer to perform the following steps for commissioning a means of transportation in production:
[0029] - Check whether the vehicle's control units, which are grouped together, are listed in an installation list that is stored in at least one of the vehicle's control units;
[0030] - in the event of a positive test result, authentication of the control units; and
[0031] - upon successful authentication, commissioning of the control units.
[0032] In the solution according to the invention, the control units are delivered with a certificate issued by the manufacturer of the respective control unit or by the manufacturer of the means of transport. The authenticity of the control units can be verified using these certificates. The control units, which are connected to form a network, check whether the types of the respective connected control units are listed in the vehicle's installation list. In addition, the control units mutually validate the certificates. If both checks are successful, commissioning can take place. In this state, control units can be replaced with identical control units as needed, e.g., in the event of a defect, without any additional external influence. By utilizing the digital identities and the vehicle's installation list, smart control units can independently activate safety-related functions.
[0033] According to one aspect of the invention, commissioning the control units includes exchanging session keys. The session keys enable encrypted communication between the respective control units, if required. However, exchanging session keys is not strictly necessary, for example, with very inexpensive components that have limited processing power and memory.
[0034] According to one aspect of the invention, the authenticity of the parts list is verified. For example, this can be done by verifying a signature on the parts list generated by the vehicle manufacturer. This ensures that the safety of the vehicle cannot be compromised by a manipulated parts list.
[0035] According to one aspect of the invention, the component list is divided into confidence intervals. This division into confidence intervals allows for the partitioning of the control units into sub-units. For example, the sub-units can comprise those control units that are each assigned to a specific functional area.
[0036] According to one aspect of the invention, after commissioning the control units, their identities are documented in the installation list or in a new installation list. Once the assembly is complete, the identity of each individual control unit is documented in the installation list at the end of the production process. After the identities have been entered, control units with a different identity, e.g., due to a hardware replacement, are no longer accepted. A change or update of the installation list in the event of a desired control unit replacement can then only be made by an authorized body.
[0037] Preferably, the control unit identities are transmitted to a backend system, which, based on certain criteria such as completeness, generates a complete parts list and makes it available to the vehicle. The data can be collected using the same parts list that was initially provided to the vehicle via the production systems. Alternatively, a new parts list can be generated.
[0038] According to one aspect of the invention, after the control units have been commissioned, information on released functions contained in the installation list is changed, or information on released functions is entered in a new installation list. In this way, it can be determined, for example, which functions of the control units or the means of transport can be used after completion of production. For example, the information could be access authorization, driving authorization for transport, or full authorization for the customer.
[0039] The entry or modification of approvals is preferably done via a backend, which transmits the resulting equipment list to the vehicle. Here, too, it is possible either to update the existing equipment list or to generate a new one.
[0040] According to one aspect of the invention, a final parts list is signed. Signing the final parts list protects it from manipulation.
[0041] Preferably, a control unit for a means of transportation is configured for use in a method according to the invention. Advantageously, a means of transportation uses such a control unit. The means of transportation can be, in particular, a motor vehicle, but also a ship, an aircraft, e.g., a Volocopter, etc.
[0042] Further features of the present invention will become apparent from the following description and the attached claims in conjunction with the figures.
[0043] Fig. 1 schematically shows a method for supporting the commissioning of a means of transport in production;
[0044] Fig. 2 schematically shows a method for commissioning a means of transport in production;
[0045] Fig. 3 schematically shows a control unit for a means of transport, designed for use in a method according to the invention;
[0046] Fig. 4 schematically represents a means of transport in which a solution according to the invention is implemented;
[0047] Fig. 5 shows a first example of a parts list for a means of transport; Fig. 6 illustrates the commissioning process in production;
[0048] Fig. 7 illustrates a final result of the commissioning; and
[0049] Fig. 8 shows a second example of a parts list for a means of transport.
[0050] To better understand the principles of the present invention, embodiments of the invention are explained in more detail below with reference to the figures. It is understood that the invention is not limited to these embodiments and that the described features can also be combined or modified without leaving the scope of protection of the invention as defined in the appended claims.
[0051] Fig. 1 schematically shows a method for supporting the commissioning of a means of transportation in production. In a first step, an installation list for the means of transportation is determined 10. The installation list contains types of control units that are to be installed in the means of transportation. The installation list can be divided into trust domains. In addition, the installation list can contain information on released functions. The installation list is then stored in at least one control unit of the means of transportation 12. Optionally, the installation list can be signed beforehand 11. Preferably, an identifier of the means of transportation is also specified in the installation list.
[0052] Fig. 2 schematically shows a procedure for commissioning a means of transportation in production. The procedure checks 21 whether the control units of the means of transportation, which are grouped together, are listed in an installation list that is stored in at least one control unit of the means of transportation. The installation list can be divided into trust areas. Optionally, the authenticity of the installation list can be verified beforehand 20. If the control units are listed in the installation list, the respective control units are authenticated 22. If authentication is successful, the control units are then commissioned 23. Session keys can be exchanged between the participating control units during this process. After commissioning 23 the control units, the identities of the control units can be documented in the installation list or in a new installation list 24.Furthermore, information on enabled functions contained in the installation list can be changed, or information on enabled functions can be entered in a new installation list. 25. A resulting final installation list is preferably signed. 26. Fig. 3 shows a simplified schematic representation of a control unit SG for a means of transportation, which is designed for use in a method according to the invention. The control unit SG has a processor 31 and a memory 30. Instructions are stored in the memory 30 which, when executed by the processor 31, cause the control unit SG to perform the steps according to one of the described methods. The instructions stored in the memory 30 thus embody a program executable by the processor 31, which implements the method according to the invention. The control unit SG has an input 32 for receiving data. Data generated by the processor 31 is provided via an output 33.Furthermore, data can be stored in memory 30. Input 32 and output 33 can be combined into a bidirectional interface.
[0053] Fig. 4 schematically depicts a means of transport 40 in which a solution according to the invention is implemented. In the illustrated example, the means of transport 40 is a motor vehicle. The motor vehicle has sensors 41 for acquiring environmental information, such as cameras, radar sensors, lidar sensors, or ultrasonic sensors. An assistance system 42 supports the driver during operation or provides a (partially) automated driving function. A data transmission unit 43 can establish a connection to a backend, for example, for transmitting data or retrieving updated software for components of the motor vehicle. A memory 44 serves to store data. Data exchange between the various components of the motor vehicle takes place via a network 45.Control units (CEUs) according to the invention are responsible for at least some of the vehicle components; these CEUs can be designed as independent components or integrated into the respective component. Communication between the CEUs is carried out, at least partially, using cryptographic functionalities. At least one of the CEUs contains an installation list (V) which is used during the commissioning of the vehicle in production.
[0054] A preferred embodiment of the invention will now be explained with reference to Figures 5 to 8. In this embodiment, the means of transport is a motor vehicle.
[0055] Fig. 5 shows a first example of a parts list V for a means of transport. During production preparation, a target configuration is defined that describes the vehicle to be built. The target configuration is documented in a parts list V, which is preferably digitally signed. For this purpose, for example, a production-related public key infrastructure of the vehicle manufacturer can be used.
[0056] The parts list V contains an identifier IF, a control unit list LS, which lists the types of control units to be installed, and a function list FL, which lists the activated functions Fj(P) for production. The functions Fj(P) can be represented, for example, by defined activation numbers.
[0057] In the example shown, the control unit list LS includes types TN 123.A, TN 456.B, and TN 789.C. As can be seen from the sub-entry TN 789.CA for type TN 789.C, the control unit list LS can also include types of partial functionalities of a control unit type. The function list FL lists two functions Fj(P) as examples, such as an access release and a drive release for production.
[0058] Fig. 6 illustrates the commissioning process in production. No online connection to the backend is required for commissioning. When a control unit SG; is powered on, it queries the target installation state documented in the installation list V on a carrier control unit SGT. It then checks both its own compliance with the target installation state and the compliance of the communication partners K. After this check, the control unit SG; searches for its communication partners K and performs authentication with them. Upon successful authentication, the communication partners K can, for example, exchange session keys, thus establishing secure communication between them. If a control unit SG; is replaced during production, the described process is repeated. This can be triggered manually or automatically, e.g.,triggered by the newly installed control unit SG;.
[0059] Figure 7 illustrates a final result of the commissioning process. Typically, counting points are defined in the production process. At a designated counting point with an online connection to the backend, e.g., when the vehicle is ready for sale, the actual installation is checked. The target installation state is then converted into the actual installation state, including the IDs of the control units SGj. This actual installation state is then signed using the vehicle manufacturer's public key infrastructure. Additionally, the vehicle activation is changed; that is, the functions released for production Fj(P) are changed to functions released for transport Fj(T) or, if applicable, directly to functions released for the customer Fj(K). The resulting installation list V, or new installation list V, is stored in the carrier control unit SGT.
[0060] Fig. 8 shows a second example of a component list V for a means of transportation. The component list V again contains an identifier IF, a control unit list LS, which lists the types of control units to be installed, and a function list FL, which lists the functions Fj enabled for production. The functions Fj can be represented, for example, by defined activation numbers. However, in this embodiment, the control unit list LS is divided into trust domains VB, two of which are shown as examples. The first trust domain VB includes the types TN 123.A and TN 456.B, the second the type TN 789.C. In each trust domain, there is at least one master and a variable number of slaves, which are preferably authenticated by only one master. The division into trust domains VB allows the control units to be divided into sub-units.For example, the sub-units can include those control units that are each assigned to a specific functional area.
[0061] Reference symbol list
[0062] 10. Determining a parts list
[0063] 11. Signing the parts list
[0064] 12. Storing the installation list in a control unit
[0065] 20. Checking the authenticity of a parts list
[0066] 21 Check regarding inclusion in the parts list
[0067] 22 Authenticating the control units
[0068] 23 Commissioning the control units
[0069] 24 Documenting identities
[0070] 25. Changing or entering information about enabled functions
[0071] 26. Signing a final parts list
[0072] 30 storage
[0073] 31 processor
[0074] 32 Entrance
[0075] 33 Exit
[0076] 40 means of transport
[0077] 41 Sensors
[0078] 42 Assistance systems
[0079] 43 Data transmission unit
[0080] 44 storage
[0081] 45 Network
[0082] ID Identity
[0083] IF Identifier
[0084] Fi function
[0085] K Communication partner
[0086] LF Function List
[0087] LS control unit list
[0088] SGi control unit
[0089] V installation list
[0090] VB Trust Area
Claims
Patent claims 1. Method for supporting the commissioning of a means of transport (40) in production, comprising the steps: - Determine (10) an installation list (V) for the means of transport (40), which lists the types of control units (SGj) to be installed in the means of transport (40); and - Storing (12) the installation list (V) in at least one control unit (SGj) of the means of transport (40).
2. Method according to claim 1, wherein the assembly list (V) for the means of transport (40) specifies an identifier (IF) of the means of transport (40).
3. Method according to claim 1 or 2, wherein the installation list (V) is signed (11) before it is stored in at least one control unit (SGj) of the means of transport (40) (12).
4. Method according to one of the preceding claims, wherein the installation list (V) is subdivided into confidence intervals (VB).
5. Method according to one of the preceding claims, wherein the installation list (V) contains information on released functions (Fj).
6. Method for putting a means of transport (40) into operation in production, comprising the steps: - Check (21) whether control units (SGj) of the means of transport (40) connected to form a group are listed in an installation list (V) which is stored in at least one control unit (SGj) of the means of transport (40); - if the test result is positive, authentication (22) of the control units (SGj); and - upon successful authentication, commissioning (23) of the control units (SGj).
7. Method according to claim 6, wherein the commissioning (23) of the control units (SGj) comprises an exchange (23) of session keys.
8. Method according to claim 6 or 7, wherein the authenticity of the installation list (V) is verified (20).
9. Method according to one of claims 6 to 8, wherein the installation list (V) is subdivided into confidence intervals (VB).
10. Method according to one of claims 6 to 9, wherein after commissioning (23) the control units (SGj) the identities (ID) of the control units (SGj) are documented in the installation list (V) or in a new installation list (V) (24).
11. Method according to one of claims 6 to 10, wherein, after commissioning (23) the control units (SGj) are put into operation, information on released functions (Fi) contained in the installation list (V) is changed or information on released functions (Fi) is entered in a new installation list (V) (25).
12. Method according to one of claims 10 or 11, wherein a final installation list (V) is signed (26).
13. Computer program with instructions which, when executed by a computer, cause the computer to perform the steps of a method according to any one of claims 1 to 12.
14. Control unit (SGi) for a means of transport (40), wherein the control unit (SGi) is configured for use in a method according to any one of claims 1 to 12.
15. Means of transport (40) with a control unit (SGj) according to claim 14.
Citation Information
Patent Citations
Procedure for safely equipping a vehicle with an individual certificate
DE102020004832A1
Method and device for installing certificate on basis of encryption and decryption of contract certificate private key
US20230327886A1
Method and apparatus for in-vehicle device authentication and secure data delivery in a distributed vehicle network
US20030147534A1