ECU Module Authentication by CAL-Based Secure Boot Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles are vulnerable to cyber-attacks through malicious applications or firmware updates, necessitating effective detection and response mechanisms to secure Electronic Control Units (ECUs).

Innovation Solution

Implementing a method that calculates cryptographic values for ECU modules, classifies them based on Cybersecurity Assurance Levels (CAL), and performs actions such as shutting down or providing control based on cryptographic value matches, using a Hardware Security Module (HSM) to generate and verify Message Authentication Codes (MAC) and employing Public Key Infrastructure (PKI) for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic verification is implemented for all ECU modules, then cybersecurity reliability is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvecybersecurity assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments ECUs into different Cybersecurity Assurance Levels (CAL 1-4) based on their criticality. This segmentation allows the system to apply different verification strictness to different modules, reducing overall system complexity while maintaining security for critical components. Non-critical modules (CAL 1-2) allow continued operation after verification failure, while critical modules (CAL 3-4) require immediate shutdown.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security verification qualities to different parts of the system based on their CAL classification. Critical ECUs (CAL 3-4) receive stringent verification with immediate shutdown on failure, while non-critical ECUs (CAL 1-2) receive less stringent verification allowing continued operation. This local differentiation optimizes the balance between security and system functionality.

Inventive Principle:
Principle #3Local quality

2Reliability

If cryptographic verification is performed on all modules, then detection of cyber-attacks is improved, but processing time and boot cycle duration increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidboot cycle time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the verification process into segments based on CAL levels. Critical modules (CAL 3-4) undergo thorough verification with immediate shutdown on failure, while non-critical modules (CAL 1-2) undergo verification but allow continued operation even on failure. This segmentation reduces overall boot time by not requiring complete system shutdown for all verification failures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial verification action based on criticality. For non-critical modules, the system performs verification but accepts partial failure (continued operation despite mismatch). For critical modules, full verification action is taken with immediate shutdown. This partial action approach reduces total processing time while maintaining adequate security.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If immediate shutdown is implemented upon cryptographic mismatch, then cybersecurity protection is improved, but system availability and operational continuity deteriorate

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the shutdown response based on CAL levels. Critical ECUs (CAL 3-4) trigger immediate shutdown to protect the vehicle from potential cyber-attacks. Non-critical ECUs (CAL 1-2) allow continued operation even when cryptographic verification fails, maintaining system availability for non-safety-critical functions. This segmentation balances security protection with operational continuity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality of shutdown response to different system parts. Critical systems receive high-quality protection with immediate shutdown, while non-critical systems receive lower-quality protection allowing continued operation. This local differentiation maintains overall system availability while protecting critical functions.

Inventive Principle:
Principle #3Local quality

4Reliability

If Public Key Infrastructure (PKI) is implemented for secure access, then authentication security is improved, but device complexity and computational overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring PKI credentials (root certificates, public keys) in ECUs during manufacturing. This preliminary setup enables secure authentication without requiring complex real-time key exchange protocols. The pre-configured credentials simplify the access control process while maintaining high security standards for firmware updates and remote access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12505221B2Secure automotive system
Publication Date: 2025.12.23 CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
  • US12505221B2 patent drawing
  • US12505221B2 patent drawing
  • US12505221B2 patent drawing

AI summary

An Electronic Control Unit (ECU) provides security for an automotive system. The ECU is classified according to a Cybersecurity Assurance Level (CAL) and calculates a cryptographic value for one or more or all modules of the ECU. The calculated cryptographic value is compared with a stored cryptographic value. Based on the CAL classification of the ECU, either control to one or more modules of the ECU is provided or the ECU is shut down as follows: when the calculated cryptographic value matches the stored cryptographic value, control to the one or more or all modules of the ECU is provided; and, when the calculated cryptographic value does not match the stored cryptographic value, the ECU is shut down in one of a current boot cycle or a subsequent boot cycle.