Method and device for establishing a communication protocol for a vehicle diagnosis, and vehicle
By reading and overwriting initial memory values with secure authorization, the method secures vehicle diagnostic communication protocols against illicit changes, enhancing their integrity.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- VOLKSWAGEN AG
- Filing Date
- 2025-11-07
- Publication Date
- 2026-05-21
AI Technical Summary
Existing vehicle diagnostic communication protocols are vulnerable to illicit modification, necessitating a secure method to define and ensure the integrity of the communication protocol.
A method involving reading an initial memory value, overwriting it with a defined second memory value to establish a communication protocol, and ensuring authorization through internal and external verification processes to prevent unauthorized changes.
This approach enhances the security of vehicle diagnostic communication protocols by linking authorization to the initial value overwrite, preventing unauthorized modifications and ensuring the defined protocol is tamper-proof.
Smart Images

Figure EP2025082251_21052026_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Method and device for defining a communication protocol for vehicle diagnostics as well as vehicle
[0003] The invention relates to a method and a device for defining a communication protocol for vehicle diagnostics, as well as a vehicle with a corresponding device.
[0004] During vehicle operation, for example, error messages from the vehicle's control units are stored in a fault memory. These stored error messages can be read out as part of vehicle diagnostics. Such vehicle diagnostics may be legally required to comply with exhaust emission limits. Various communication protocols are suitable for vehicle diagnostics, such as On-Board Diagnostics 2 (OBD-2) or Unified Diagnostic Services (UDS).
[0005] The communication protocol used may be prescribed by country-specific regulations, for example. Therefore, it must be ensured that the prescribed communication protocol cannot be illicitly modified.
[0006] From DE 197 48 181 A1, a method is known for testing a function and / or feature of a vehicle using a test device separate from the vehicle, wherein the function and / or feature is checked using a test routine transmitted from the test device to the vehicle before the test. It is further provided that a vehicle-specific function and / or feature is tested, wherein a test routine for this function and / or feature is transmitted before the test. A test communication protocol can be transmitted beforehand.
[0007] German patent application DE 10 2017 008 673 A1 discloses a method for charging a vehicle's battery via an authorized charging infrastructure point. This method involves establishing a data connection between the vehicle and the charging infrastructure point, and implementing a number of communication protocols and / or variants of communication protocols based on the same physical communication medium in the vehicle. Furthermore, after connecting the vehicle to the charging infrastructure point, communication between the vehicle and the charging infrastructure point is initiated according to a predefined communication protocol, and data exchange begins after a successful data connection is established.
[0008] The technical problem is to create a method and a device for defining a communication protocol for vehicle diagnostics, as well as a vehicle with a corresponding device, which improves safety in defining the communication protocol.
[0009] The solution to the technical problem is provided by the articles with the features of the independent claims. Further advantageous embodiments of the invention are described in the dependent claims.
[0010] A procedure for defining a communication protocol for vehicle diagnostics is proposed, comprising the following steps:
[0011] Reading at least one first memory value from a data storage device, enabling the storage of at least one second memory value, if the read at least one first memory value is an initial value of the data storage device,
[0012] Storing at least one second memory value on the data storage device, wherein the at least one second memory value defines the communication protocol for vehicle diagnostics, and wherein storing the at least one second memory value overwrites the at least one first memory value.
[0013] A further proposal is a device for defining a communication protocol for vehicle diagnostics, wherein the device is configured to execute a method according to an embodiment described in this disclosure. The device can, for example, be configured as or comprise a microprocessor.
[0014] A further proposal is for a vehicle comprising at least one device according to an embodiment described in this disclosure. The vehicle can, for example, be designed as a passenger car or a truck.
[0015] The technical effects and advantages described in this disclosure for the method naturally also apply to the device and the vehicle, and vice versa. The method has the technical effect that the authorization to store data is linked to the fact that the first read value is the initial value of the data storage. Since the initial value is overwritten by the second value after authorization, no further authorization is possible. This improves the security of the communication protocol.
[0016] The data storage device can be flash memory. The device can include the data storage device. The data storage device is, in particular, non-volatile. The data storage device can have one or more areas. One area can be used to define the communication protocol. The initial memory value can be stored in the area used to define the communication protocol. The data storage device can be factory-new, so that the initial value is stored in each area of the data storage device.
[0017] The initial value can be a data byte, where, for example, all 8 bits of the initial value have the state "1". The bit sequence of the initial value can be called OxFF. Of course, the initial value can also be structured or designated differently.
[0018] The first memory value can also be a data byte and comprise 8 bits. The first memory value can be configured as an initial value. If the first memory value is configured as an initial value, then no communication protocol is currently defined. However, the first memory value can also be a value other than the initial value, for example, if a communication protocol has already been defined.
[0019] The device can be used to read the first memory value. The device can be configured to generate a read command. For example, a microcontroller within the device can read the data memory using this command. The read command can be addressed to the area that defines the communication protocol of the data memory. The address of this communication protocol area can be pre-defined. The read first memory value can then be temporarily stored, for example, in main memory. The device can encompass the main memory.
[0020] The device can enable the storage process. This enable can include comparing the read first memory value with the initial value. The device can be configured to perform this comparison. For example, it can check whether the bit sequence of the read first memory value matches the bit sequence of the initial value. The bit sequence of the initial value can be pre-defined. This ensures that no other communication protocol is already in use or that the wrong memory value has been read from the data storage. The enable can also include allowing a write operation to store the second memory value and / or other memory values. This can be achieved, for example, by the device generating an enable signal that initiates the storage process.
[0021] The second memory value can also be a data byte and comprise 8 bits. For example, at least one bit of the second memory value can be in the state "0" and the remaining bits in the state "1". The second memory value can be provided by a control unit, such as an engine control unit or a brake control unit.
[0022] The communication protocol for vehicle diagnostics, which is determined by storing the second memory value, can be, for example, OBD-2, OBDonllDS, or ZEVonllDS. The specific communication protocol used may depend, for example, on the vehicle's target country. In particular, the bit sequence of the second memory value can be assigned to the communication protocol intended for the vehicle. This assignment may be known in advance.
[0023] The device can be used for storage. The second value can be stored, for example, after receiving the release signal. The device can be configured to generate a storage command. This command allows the second value to be stored on the data memory, particularly in the area for defining the communication protocol. The storage command can be addressed to store the second value in the area where the first value is stored, overwriting it.
[0024] After saving, the communication protocol is defined by the second stored value. This is because the initial value cannot be overwritten, preventing the second stored value from being enabled. During vehicle diagnostics, for example, a diagnostic tool can read the stored second value from the data memory. This allows the diagnostic tool to be informed of the defined communication protocol, which will be used for communication between the diagnostic tool and the vehicle.
[0025] The procedure, or at least one or more steps of the procedure, can be performed during a vehicle assembly step. In this way, the communication protocol can be defined during the assembly step, thus utilizing vehicle assembly time for its establishment. The assembly step can be, for example, a final or near-final assembly step to ensure that the vehicle is substantially complete and that the proposed device is installed in the vehicle. For instance, the installation of a brake system or a brake system control unit is a final or near-final assembly step, as this step is performed at one end of the manufacturing process.
[0026] In this system, at least one second memory value is provided by an internal signal. This eliminates the need for an external device to provide the second memory value, thus preventing manipulation attempts via the external device. The internal signal is generated and provided by an already installed control unit in the vehicle, such as the engine control unit or the brake control unit. The internal signal can be transmitted via an internal communication bus of the vehicle, such as a CAN bus. The internal signal can contain an encoding to indicate the second memory value. This encoding can be implemented, for example, as a high and / or low level on the internal communication bus. The device can include an interface for communication with the internal communication bus. The device can be configured to decode the internal signal as the second memory value, for example, by...by decoding the encoding of the internal signal as a data byte.
[0027] In one embodiment, the at least one second memory value is checked by repeatedly providing it via the internal signal. This safeguards the provision of the second memory value against transmission errors. The check can include a comparison, where a first transmitted internal signal is compared against at least one subsequently transmitted internal signal. For example, the encoding of the first transmitted internal signal can be compared with the encoding of the subsequently transmitted internal signal. Furthermore, for example, a counter can be incremented by the counter value "1" if the transmitted signals match. If, however, the transmitted signals do not match, the counter can be reset to the counter value "= 0", decremented by the counter value "1", or at least not incremented, i.e., "+0".If a threshold value of the check is exceeded, the check can be considered successful. In this case, saving with the checked second memory value can occur. Otherwise, the check can continue until the threshold value is exceeded. The threshold value may be known in advance.
[0028] In one embodiment, at least one step of the method is enabled by an external device. This allows the method to be initiated externally, for example, to define the communication protocol. The enabling action can, for instance, allow and initiate the reading of the first stored value. Other steps of the method can also be enabled by the external device. The external device can, for example, be a diagnostic tool. The external device can be configured to send at least one external signal to the device to enable the process. For this purpose, the external device can be connected to the device, for example, via another communication bus of the vehicle. The external device can, for example, be connected to the vehicle via a vehicle diagnostics interface.
[0029] In one embodiment, the activation of the at least one step only occurs once the at least one external device has been verified. This further enhances security when defining the communication protocol. Without verification, the process cannot be initiated, as, for example, reading the first stored value cannot be enabled. For verification purposes, the at least one external signal can, for example, signal a verification key. The external signal can be encoded with the verification key. Conversely, the device or vehicle can be configured to generate at least one signal that signals a lock for the verification key. The generated signal can also be encoded with the key. The external device can be verified when the verification key opens the lock. The lock and the verification key can, for example, be...The data is generated by the vehicle manufacturer and made available to an authorized diagnostic service provider. For example, the vehicle and the external device can communicate with an external server of the manufacturer. This ensures that only verified diagnostic service providers can perform the activation. Possible verification methods include SFD-Basic or SFD Level 2.
[0030] In one embodiment, at least one error message is issued if the data storage authorization has not been granted. This allows attempts to modify the defined communication protocol to be detected, as the authorization is only granted if the first stored value is the initial value. The error message can be generated by the device itself. It can also be stored in the vehicle's fault memory. Furthermore, the error message can trigger the illumination of the engine warning light.
[0031] In one embodiment, at least one further error message is deleted when the first memory value is overwritten. This further error message can indicate that no communication protocol is currently defined. For example, the further error message can initially be generated by reading the first memory value and storing it in the vehicle's fault memory. The further error message can trigger the illumination of the engine warning light. Deleting the further error message can, for example, stop the engine warning light from illuminating. In this way, the successful definition of the communication protocol can be communicated. In another embodiment, the second memory value is overwritten when at least a third memory value is provided that has been verified. This allows the defined communication protocol to be changed subsequently and in a tamper-proof manner.For example, a software update or a change in legal regulations may necessitate modifying the communication protocol defined by the second memory value using the third memory value. The third memory value could, for instance, define a new communication protocol or specify a modified version of the current communication protocol. This third memory value could be generated and provided by a newly installed or updated control unit. To verify the third memory value, it could be encoded with a verification key. Conversely, the device or vehicle could be configured to generate at least one verification signal, which would indicate a lock for the verification key. This verification signal could also be encoded with the lock.The third storage value can be verified if the verification key opens the lock. It should be noted that the terms "first storage value," "second storage value," and "third storage value" do not necessarily imply any temporal or spatial relationship between the storage values, but serve only for the sake of clarity within the context of this disclosure.
[0032] In one embodiment, the at least one third storage value is provided by an external device. In this way, the third storage value can be provided via the external device, for example, during a service appointment. The third storage value can be verified, in particular, if the external device is verified. The verification of the external device has already been explained previously, mutatis mutandis.
[0033] The invention is explained in more detail using exemplary embodiments. The figures show:
[0034] Fig. 1 shows a schematic representation of an embodiment of a vehicle with a device and
[0035] Fig. 2 shows a schematic representation of another embodiment of a vehicle with a device.
[0036] In the following, identical reference symbols denote elements with the same technical characteristics.
[0037] Fig. 1 shows a schematic representation of an embodiment of a vehicle 200 designed as a passenger car with a device 100. The device 100 comprises a microcontroller (not shown) and a data memory 10 designed as flash memory. The device 100 is configured to execute a method for defining a communication protocol for vehicle diagnostics. The method comprises the steps described below. In step S1, a first memory value 1 is read from the data memory 10. The first memory value 1 can be a data byte and have a bit sequence of 8 bits. The readout is enabled by an external device 300 designed as a diagnostic device. The external device 300 is configured to signal an external signal 311 to the device 100 to enable step S1.For this purpose, the external device 300 is connected to the device 100 via a communication bus 240 of the vehicle 200. The communication bus 240, designed as a K-bus, enables communication between an interface 230 of the vehicle 200 and an interface 13 of the device 100. The interface 230 of the vehicle 200 can, for example, be an OBD-2 socket for vehicle diagnostics, to which the external device 300 is connected.
[0038] Step S1 is only activated by the external signal 311 if the external device 300 is verified. The external device 300 can be verified, for example, by the manufacturer of the vehicle 200. For this purpose, a verification key 420 can be provided to the external device 300, for example, via an external server 400 of the manufacturer. Simultaneously, a lock 410 for verification can be provided to a control unit 210 of the vehicle 200, configured as an engine control unit, via the external server 400. The verification of the external device 300 can be carried out, for example, with the help of the control unit 210 by checking whether the verification key 420 opens the lock 410. If the external device 300 is verified, it can communicate the external signal 311 to the device 100.
[0039] In step S2, a second memory value 2 is enabled for storage if the first memory value 1 read is an initial value of data memory 10. The initial value can, for example, be an 8-bit sequence known as OxFF, which exclusively contains the states "1". In step S2, the bit sequence of the first memory value 1 read can be compared with the known bit sequence of the initial value.
[0040] If the bit sequences do not match (this is indicated in step S2 by "N" for "No"), the release is not granted and an error message 50 is output via a vehicle-internal communication bus 220, configured as a CAN bus, to a fault memory 250 of the vehicle 200. In this way, failed attempts to obtain a release to modify the data memory 10 can be stored in the fault memory 250.
[0041] If, however, the bit sequences match (this is indicated in step S2 by "Y" for "Yes"), the system is enabled to store the second memory value 2 on data storage 10. The second memory value 2 can, for example, be a data byte comprising 8 bits, whereby the bit sequence of the second memory value 2 differs from the bit sequence of the initial value in at least one state. The second memory value 2 defines a communication protocol intended for the vehicle 200. The communication protocol can, for example, be OBDonllDS. The second memory value 2 is provided by the control unit 210 and transmitted as an internal signal 211 via the vehicle's internal communication bus 220 to an interface 12 of the device 100.
[0042] In step S3, the second memory value 2 is stored on data memory 10. Storing the second memory value 2 overwrites the first memory value 1 to replace the initial value with the second memory value 2. For security reasons, step S3 comprises several sub-steps S31, S32, and S33. This is because storing the second memory value 2 prevents the release performed in step S2 from being possible in the future, thus preventing any further modification of the communication protocol.
[0043] In sub-step S31, it is checked whether the transmitted internal signal 211, which signals the second memory value 2, has been transmitted correctly. For this purpose, the transmitted signal 211 can, for example, be stored in a working memory (not shown) of the device 100, and then the system waits for the internal signal 211 to be transmitted again. The transmitted internal signals 211 can then be compared with each other, for example, by comparing the encodings of the successively transmitted signals 211. If the encodings match, the internal signal 211 has been transmitted correctly. This result is indicated by a "Y" in sub-step S31. If, however, the encodings do not match, the internal signal 211 has probably been transmitted incorrectly. This result is indicated by an "N" in sub-step S31.
[0044] In sub-step S32, depending on the result of sub-step S31, a computer-implemented counter 30 is incremented by one value if the internal signal 211 has been transmitted correctly. This is indicated by a "+1" in Fig. 1. Otherwise, the counter 30 can be reset to a starting value. This is indicated by a "=0" in Fig. 1. In the embodiment shown in sub-step S32 in Fig. 1, the counter 30 jumps from a value "4" to a value "5"—that is, the internal signal 211 has already been transmitted correctly several times, so the second memory value 2 has thus been provided multiple times.
[0045] In sub-step S33, it is checked whether the current reading of counter 30 already exceeds a known threshold value 35, e.g., "4". In the embodiment shown in sub-step S33 in Fig. 1, this is the case, since the current reading of counter 30 is "5". The internal signal 211 has thus been transmitted correctly multiple times, i.e., five times in succession. This rules out a transmission error with near certainty. Exceeding the threshold value 35 is indicated by "Y" in Fig. 1. The second memory value 2 can then be stored in the data memory 10 to define the communication protocol.
[0046] If, however, the reading of meter 30 does not exceed the threshold value 35, the check is continued according to sub-steps S31, S32, S33.
[0047] When the first memory value 1 is overwritten with the second memory value 2, an additional erase signal 51 is generated to delete at least one further error message in the error memory 250. This further error message might, for example, indicate that the initial value is stored in data memory 10 and therefore no communication protocol has yet been defined. Since this is no longer the case, the further error message can be eliminated in this way.
[0048] Fig. 2 shows a schematic representation of another embodiment of a vehicle 200 designed as a passenger car with a device 100. The device 100 comprises a microcontroller (not shown) and a data storage device 10 designed as flash memory. The device 100 is configured to execute a method for defining a communication protocol for vehicle diagnostics.
[0049] A second memory value 2 (see Fig. 1) is stored on data storage device 10. This second memory value 2 can, for example, define the communication protocol of the vehicle 200 during a service appointment. However, this communication protocol is now to be adapted by the procedure, for example, due to changed legal regulations or standards.
[0050] In step S4 of the procedure, the second storage value 2 is therefore overwritten by a third storage value 3. However, this can only occur if the third storage value 3 is verified. The third storage value 3 is provided by an external device 300 connected to the vehicle 200 in the form of an adaptation signal 312. The adaptation signal 312 can be encoded with a verification key 420.
[0051] The external device 300 can be verified, for example, by the manufacturer. This was shown in Fig.
[0052] As already explained in Figure 1, Figure 2 further shows that a control unit 210 of the vehicle 200 can provide another internal signal 212 via a vehicle-internal communication bus 220, which signals a lock 410. When the verification key 420 opens the lock 410, the external device 300 is verified by the manufacturer. The third memory value 3 is then also verified because the external device 300 is verified. This is indicated by "Y" in Figure 2 in step S4. Subsequently, the second memory value 2 (see Figure 1) is overwritten by the third memory value 3.
[0053] If, however, the external device 300 is not verified (this is indicated by "N" in step S4 in Fig. 2), a verification error message 52 is issued and stored in a fault memory 250 of the vehicle 200. In this case, the second memory value 2 (see Fig. 1) is not overwritten by the third memory value 3. Reference numeral list
[0054] 1 first memory value
[0055] second memory value
[0056] third memory value
[0057] 10 Data storage
[0058] 11 to 13 Interface of the device
[0059] 0 counters
[0060] 5 Threshold
[0061] 0 error messages
[0062] 1 Extinguishing signal
[0063] 2 Verification error message
[0064] 100 Device
[0065] 00 Vehicle
[0066] 10 Control unit
[0067] 11 internal signal
[0068] 12 further internal signal
[0069] 220 vehicle-internal communication bus
[0070] 230 Interface for vehicle diagnostics 240 Additional communication bus
[0071] 250 fault memory
[0072] 300 external facilities
[0073] 311 external signal
[0074] 312 Adaptation signal
[0075] 400 external servers
[0076] 410 Lock for verification
[0077] 420 verification keys
[0078] S1 step
[0079] S2 step
[0080] S3 step
[0081] S31 Substep
[0082] S32 Substep
[0083] S33 Substep
[0084] S4 step
Claims
Patent claims 1. Procedure for defining a communication protocol for vehicle diagnostics, comprising the steps: Reading (S1) at least one first memory value (1) from a data storage device (10), enabling (S2) to store at least one second memory value (2) if the read-out at least one first memory value (1) is an initial value of the data storage device (10), storing (S3) the at least one second memory value (2) on the data storage device (10), wherein the at least one second memory value (2) defines the communication protocol for vehicle diagnostics, wherein storing the at least one second memory value (2) overwrites the at least one first memory value (1), wherein the at least one second memory value (2) is provided by an internal signal (211) of a control unit of the vehicle.
2. Method according to claim 1, characterized in that the at least one second storage value (2) is checked by providing the at least one second storage value (2) multiple times by the internal signal (211).
3. Method according to one of the preceding claims, characterized in that at least one step (S1, S2, S3) of the method is enabled by an external device (300).
4. Method according to claim 3, characterized in that the activation of the at least one step (S1, S2, S3) occurs only when the at least one external device (300) is verified.
5. Method according to one of the preceding claims, characterized in that at least one error message (50) is output if the release (S2) for saving has not occurred and / or that at least one further error message is deleted if the at least one first storage value (1) has been overwritten.
6. Method according to one of the preceding claims, characterized in that the at least one second storage value (2) is overwritten when at least one third storage value (3) is provided which is verified.
7. Method according to claim 6, characterized in that the at least one third storage value (3) is provided by an external device (300).
8. Device (100) for defining a communication protocol for vehicle diagnostics, wherein the device (100) is configured to perform a method according to any one of claims 1 to 7.
9. Vehicle (200) comprising at least one device (100) according to claim 8.